Total
396633 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-68876 | 2026-09-09 | N/A | 8.0 HIGH | ||
| Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-68850 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-68828 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-65669 | 2026-09-09 | N/A | 9.6 CRITICAL | ||
| Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-62813 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-62810 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-55007 | 2026-09-09 | N/A | 8.1 HIGH | ||
| Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-7861 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3. | |||||
| CVE-2026-86504 | 2026-09-09 | N/A | 7.8 HIGH | ||
| In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution | |||||
| CVE-2026-86502 | 2026-09-09 | N/A | 8.4 HIGH | ||
| In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts | |||||
| CVE-2026-86480 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | |||||
| CVE-2026-86479 | 2026-09-09 | N/A | 8.1 HIGH | ||
| In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | |||||
| CVE-2026-86478 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | |||||
| CVE-2026-86218 | 1 N-able | 1 N-central | 2026-09-09 | N/A | 9.8 CRITICAL |
| N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | |||||
| CVE-2026-85880 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 5 more | 2026-09-09 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-83534 | 2026-09-09 | N/A | 6.4 MEDIUM | ||
| PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions | |||||
| CVE-2026-83527 | 2026-09-09 | N/A | 8.1 HIGH | ||
| An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. | |||||
| CVE-2026-81963 | 1 Microsoft | 5 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 2 more | 2026-09-09 | N/A | 7.8 HIGH |
| Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-76967 | 2026-09-09 | N/A | 7.8 HIGH | ||
| SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application. | |||||
| CVE-2026-75650 | 1 Adobe | 3 Commerce, Commerce B2b, Magento | 2026-09-09 | N/A | 10.0 CRITICAL |
| Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | |||||
