Vulnerabilities (CVE)

Total 396528 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-69690 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 4.6 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69576 2026-09-09 N/A 7.8 HIGH
Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.
CVE-2026-69549 2026-09-09 N/A 7.0 HIGH
Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69492 2026-09-09 N/A 7.0 HIGH
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69488 2026-09-09 N/A 7.0 HIGH
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69468 2026-09-09 N/A 7.0 HIGH
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69453 2026-09-09 N/A 5.5 MEDIUM
Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
CVE-2026-69451 2026-09-09 N/A 7.1 HIGH
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.
CVE-2026-69434 2026-09-09 N/A 8.8 HIGH
Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network.
CVE-2026-69424 2026-09-09 N/A 7.8 HIGH
Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-69377 2026-09-09 N/A 7.8 HIGH
Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
CVE-2026-69357 2026-09-09 N/A 7.1 HIGH
Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.
CVE-2026-69269 2026-09-09 N/A 7.8 HIGH
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
CVE-2026-68888 2026-09-09 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
CVE-2026-58600 2026-09-09 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
CVE-2026-56198 2026-09-09 N/A 7.8 HIGH
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
CVE-2026-52486 2026-09-09 N/A 6.6 MEDIUM
An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module
CVE-2026-47297 2026-09-09 N/A 8.1 HIGH
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2022-26961 2026-09-09 N/A 5.4 MEDIUM
Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
CVE-2026-87485 1 Google 1 Chrome 2026-09-09 N/A 3.1 LOW
Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)