Total
396528 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-85124 | 1 Fastify | 1 Fastify\/http-proxy | 2026-09-09 | N/A | 7.5 HIGH |
| @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options. An unauthenticated network attacker can use this to reach upstream paths that were meant to stay hidden behind the proxy, resulting in disclosure of internal endpoints. This is a path traversal issue (CWE-22). Users should upgrade to @fastify/http-proxy 11.6.2 or later. | |||||
| CVE-2026-69629 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-09-09 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-85090 | 1 Freerdp | 1 Freerdp | 2026-09-09 | N/A | 5.4 MEDIUM |
| FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane. | |||||
| CVE-2026-87563 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87565 | 1 Google | 2 Android, Chrome | 2026-09-09 | N/A | 6.5 MEDIUM |
| Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87566 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 5.3 MEDIUM |
| Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87735 | 2026-09-09 | N/A | 4.3 MEDIUM | ||
| An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption. | |||||
| CVE-2026-87724 | 2026-09-09 | N/A | 6.5 MEDIUM | ||
| Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032. | |||||
| CVE-2026-83998 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-83986 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-09-09 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-83975 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-09-09 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-81355 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally. | |||||
| CVE-2026-79588 | 2026-09-09 | N/A | 4.3 MEDIUM | ||
| U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP. | |||||
| CVE-2026-79574 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. | |||||
| CVE-2026-79571 | 2026-09-09 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication. | |||||
| CVE-2026-79390 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same network segment can intercept MQTT traffic and obtain sensitive device information and operational data, including device identifiers, message metadata, and control-related information. | |||||
| CVE-2026-78997 | 2026-09-09 | N/A | 9.3 CRITICAL | ||
| UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed. | |||||
| CVE-2026-78837 | 2026-09-09 | N/A | 7.5 HIGH | ||
| A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement. | |||||
| CVE-2026-77908 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-70351 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network. | |||||
