Total
396665 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19634 | 2026-09-09 | N/A | 6.4 MEDIUM | ||
| PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later | |||||
| CVE-2026-19633 | 2026-09-09 | N/A | 8.8 HIGH | ||
| PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions | |||||
| CVE-2026-77504 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69764 | 1 Microsoft | 6 365 Apps, Office 2016, Office 2019 and 3 more | 2026-09-09 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69530 | 2026-09-09 | N/A | 8.1 HIGH | ||
| Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69522 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69359 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-19398 | 2026-09-09 | N/A | N/A | ||
| An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' Security Update for ASUS FA507NV / FA507NU BIOS ' section on the ASUS Security Advisory for more information. | |||||
| CVE-2025-14733 | 1 Watchguard | 39 Firebox M270, Firebox M290, Firebox M295 and 36 more | 2026-09-09 | N/A | 9.8 CRITICAL |
| An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured. | |||||
| CVE-2026-11814 | 1 Netgear | 52 Be9300, Be9300 Firmware, Mr60 and 49 more | 2026-09-09 | N/A | 6.8 MEDIUM |
| A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. | |||||
| CVE-2026-11738 | 1 Netgear | 52 Be9300, Be9300 Firmware, Mr60 and 49 more | 2026-09-09 | N/A | 4.4 MEDIUM |
| Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | |||||
| CVE-2026-9214 | 1 Netgear | 2 R7000, R7000 Firmware | 2026-09-09 | N/A | 4.5 MEDIUM |
| Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | |||||
| CVE-2026-11739 | 1 Netgear | 54 Mr60, Mr60 Firmware, Mr70 and 51 more | 2026-09-09 | N/A | 6.4 MEDIUM |
| A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. | |||||
| CVE-2026-11737 | 1 Netgear | 26 Rax20, Rax20 Firmware, Rax41 and 23 more | 2026-09-09 | N/A | 4.5 MEDIUM |
| Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality. | |||||
| CVE-2026-11733 | 1 Netgear | 22 Rax41, Rax41 Firmware, Rax41v2 and 19 more | 2026-09-09 | N/A | 4.9 MEDIUM |
| A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. | |||||
| CVE-2026-11734 | 1 Netgear | 30 Mr70, Mr70 Firmware, Mr90 and 27 more | 2026-09-09 | N/A | 2.7 LOW |
| A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. | |||||
| CVE-2026-11736 | 1 Netgear | 38 Rax20, Rax20 Firmware, Rax35v2 and 35 more | 2026-09-09 | N/A | 4.9 MEDIUM |
| A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. | |||||
| CVE-2026-11735 | 1 Netgear | 40 R7000, R7000 Firmware, Rax20 and 37 more | 2026-09-09 | N/A | 4.9 MEDIUM |
| A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. | |||||
| CVE-2026-15141 | 1 Tp-link | 2 Tl-wr820n, Tl-wr820n Firmware | 2026-09-09 | N/A | 5.7 MEDIUM |
| The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information. | |||||
| CVE-2026-20504 | 1 Mediatek | 38 Mt2735, Mt2735 Firmware, Mt6833 and 35 more | 2026-09-09 | N/A | 5.3 MEDIUM |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865. | |||||
