Vulnerabilities (CVE)

Total 396665 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-19634 2026-09-09 N/A 6.4 MEDIUM
PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later
CVE-2026-19633 2026-09-09 N/A 8.8 HIGH
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions
CVE-2026-77504 2026-09-09 N/A 8.8 HIGH
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69764 1 Microsoft 6 365 Apps, Office 2016, Office 2019 and 3 more 2026-09-09 N/A 8.8 HIGH
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69530 2026-09-09 N/A 8.1 HIGH
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-69522 2026-09-09 N/A 8.8 HIGH
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-69359 2026-09-09 N/A 7.8 HIGH
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.
CVE-2026-19398 2026-09-09 N/A N/A
An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.
CVE-2025-14733 1 Watchguard 39 Firebox M270, Firebox M290, Firebox M295 and 36 more 2026-09-09 N/A 9.8 CRITICAL
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
CVE-2026-11814 1 Netgear 52 Be9300, Be9300 Firmware, Mr60 and 49 more 2026-09-09 N/A 6.8 MEDIUM
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
CVE-2026-11738 1 Netgear 52 Be9300, Be9300 Firmware, Mr60 and 49 more 2026-09-09 N/A 4.4 MEDIUM
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-9214 1 Netgear 2 R7000, R7000 Firmware 2026-09-09 N/A 4.5 MEDIUM
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-11739 1 Netgear 54 Mr60, Mr60 Firmware, Mr70 and 51 more 2026-09-09 N/A 6.4 MEDIUM
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
CVE-2026-11737 1 Netgear 26 Rax20, Rax20 Firmware, Rax41 and 23 more 2026-09-09 N/A 4.5 MEDIUM
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
CVE-2026-11733 1 Netgear 22 Rax41, Rax41 Firmware, Rax41v2 and 19 more 2026-09-09 N/A 4.9 MEDIUM
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
CVE-2026-11734 1 Netgear 30 Mr70, Mr70 Firmware, Mr90 and 27 more 2026-09-09 N/A 2.7 LOW
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
CVE-2026-11736 1 Netgear 38 Rax20, Rax20 Firmware, Rax35v2 and 35 more 2026-09-09 N/A 4.9 MEDIUM
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
CVE-2026-11735 1 Netgear 40 R7000, R7000 Firmware, Rax20 and 37 more 2026-09-09 N/A 4.9 MEDIUM
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
CVE-2026-15141 1 Tp-link 2 Tl-wr820n, Tl-wr820n Firmware 2026-09-09 N/A 5.7 MEDIUM
The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.
CVE-2026-20504 1 Mediatek 38 Mt2735, Mt2735 Firmware, Mt6833 and 35 more 2026-09-09 N/A 5.3 MEDIUM
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.