Total
396633 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-69338 | 2026-09-09 | N/A | 7.1 HIGH | ||
| Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69292 | 2026-09-09 | N/A | 7.0 HIGH | ||
| Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-67276 | 2026-09-09 | N/A | N/A | ||
| RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable) | |||||
| CVE-2026-66768 | 2026-09-09 | N/A | 9.0 CRITICAL | ||
| SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system. | |||||
| CVE-2026-66767 | 2026-09-09 | N/A | 7.7 HIGH | ||
| SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application. | |||||
| CVE-2026-58240 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system. | |||||
| CVE-2026-45200 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption. Scenario caused by fabricating a specific combination of flags on the allocation interface that would cause an incorrect double free event when freed. | |||||
| CVE-2026-21042 | 2026-09-09 | N/A | N/A | ||
| Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code. | |||||
| CVE-2026-19634 | 2026-09-09 | N/A | 6.4 MEDIUM | ||
| PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later | |||||
| CVE-2026-19633 | 2026-09-09 | N/A | 8.8 HIGH | ||
| PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions | |||||
| CVE-2026-77504 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69764 | 1 Microsoft | 6 365 Apps, Office 2016, Office 2019 and 3 more | 2026-09-09 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69530 | 2026-09-09 | N/A | 8.1 HIGH | ||
| Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69522 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69359 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-19398 | 2026-09-09 | N/A | N/A | ||
| An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' Security Update for ASUS FA507NV / FA507NU BIOS ' section on the ASUS Security Advisory for more information. | |||||
| CVE-2025-14733 | 1 Watchguard | 39 Firebox M270, Firebox M290, Firebox M295 and 36 more | 2026-09-09 | N/A | 9.8 CRITICAL |
| An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured. | |||||
| CVE-2026-11814 | 1 Netgear | 52 Be9300, Be9300 Firmware, Mr60 and 49 more | 2026-09-09 | N/A | 6.8 MEDIUM |
| A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. | |||||
| CVE-2026-11738 | 1 Netgear | 52 Be9300, Be9300 Firmware, Mr60 and 49 more | 2026-09-09 | N/A | 4.4 MEDIUM |
| Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | |||||
| CVE-2026-9214 | 1 Netgear | 2 R7000, R7000 Firmware | 2026-09-09 | N/A | 4.5 MEDIUM |
| Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | |||||
