Total
396528 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-54396 | 2026-09-09 | N/A | 6.5 MEDIUM | ||
| PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server. | |||||
| CVE-2023-54390 | 2026-09-09 | N/A | 7.5 HIGH | ||
| PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPacket to crash the server. | |||||
| CVE-2026-85392 | 2026-09-09 | N/A | 4.3 MEDIUM | ||
| Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying arbitrary user IDs. Attackers can forcibly log out any user including administrators by calling the logout handler with another user's ID, since the endpoint performs no authorization checks to verify the caller owns the target account. | |||||
| CVE-2026-53924 | 2026-09-09 | N/A | N/A | ||
| Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9, StreamingEscrow.claim() correctly rejects withdrawals while an escrow is disputed, but the permissionless syncOutflow() path performs the same excess-balance transfer without checking disputed. After a streaming proposal is challenged, anyone can call syncOutflow() to transfer escrowed SuperTokens to the proposal beneficiary while the dispute is pending. If the proposal is later rejected, those tokens cannot be recovered by drainToStrategy(). This issue has been patched in 0xc9d4e0dacd937364793278180551e59d93cd43f9. | |||||
| CVE-2026-49456 | 2026-09-09 | N/A | 3.1 LOW | ||
| Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchanged into the HTTP Location response header with no URL validation, scheme restriction, or path-only enforcement. Any application that passes user-controlled input to this helper — the natural pattern documented in the JSDoc and official fixtures — is vulnerable to open redirect attacks. An attacker who convinces a victim to click a crafted link can silently redirect the browser to an arbitrary external domain, enabling phishing, credential harvesting, and OAuth token theft. Additionally, scheme-relative URLs (//evil.example/) bypass naive https?://-only allow-list filters that developers might add as ad-hoc mitigations. This issue has been patched in version 1.0.0-beta.1. | |||||
| CVE-2026-70582 | 2026-09-09 | N/A | 6.4 MEDIUM | ||
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69819 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69531 | 2026-09-09 | N/A | 5.5 MEDIUM | ||
| Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally. | |||||
| CVE-2026-69429 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-69418 | 2026-09-09 | N/A | 8.0 HIGH | ||
| Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69412 | 1 Microsoft | 7 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 4 more | 2026-09-09 | N/A | 8.0 HIGH |
| Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. | |||||
| CVE-2026-69389 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69361 | 2026-09-09 | N/A | 6.5 MEDIUM | ||
| Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-69336 | 2026-09-09 | N/A | 7.1 HIGH | ||
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-62744 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-50894 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload. | |||||
| CVE-2026-39020 | 2026-09-09 | N/A | 5.5 MEDIUM | ||
| An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file | |||||
| CVE-2026-38961 | 2026-09-09 | N/A | 5.4 MEDIUM | ||
| Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget. | |||||
| CVE-2026-15140 | 2026-09-09 | N/A | N/A | ||
| A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster. | |||||
| CVE-2026-79636 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 7.0 HIGH |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. | |||||
