Total
395079 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-25280 | 2026-09-17 | N/A | 7.8 HIGH | ||
| Memory corruption when processing escape handling flow with insufficient user buffer sizes. | |||||
| CVE-2026-25278 | 2026-09-17 | N/A | 7.8 HIGH | ||
| Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying. | |||||
| CVE-2026-25275 | 2026-09-17 | N/A | 7.5 HIGH | ||
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |||||
| CVE-2026-25261 | 2026-09-17 | N/A | 6.7 MEDIUM | ||
| Memory corruption while processing rear sensor IOCTL calls. | |||||
| CVE-2026-24081 | 2026-09-17 | N/A | 7.4 HIGH | ||
| Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | |||||
| CVE-2026-24075 | 2026-09-17 | N/A | 7.8 HIGH | ||
| Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. | |||||
| CVE-2026-20250 | 2026-09-17 | N/A | 8.6 HIGH | ||
| A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. | |||||
| CVE-2026-20222 | 2026-09-17 | N/A | 7.4 HIGH | ||
| A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate to an affected device. A successful exploit could allow the attacker to trigger a memory leak that will eventually cause the affected device to reload unexpectedly. | |||||
| CVE-2026-14805 | 2026-09-17 | N/A | 8.8 HIGH | ||
| The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an arbitrary transient key without capability checks or nonce validation, and (2) the developer access login mechanism in admin/classes/stm-theme-support.php authenticates users based on a transient value without proper cryptographic validation when in legacy string mode. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the stm_developer_access_token transient to a known value (1), then authenticate as any existing user including administrators by visiting a specially crafted URL, thereby achieving full privilege escalation to administrator. | |||||
| CVE-2026-12728 | 2026-09-17 | N/A | 8.8 HIGH | ||
| IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data. | |||||
| CVE-2023-54397 | 2026-09-17 | N/A | 7.5 HIGH | ||
| Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies. | |||||
| CVE-2026-65643 | 1 Cpanel | 1 Cpanel | 2026-09-17 | N/A | 8.8 HIGH |
| Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. | |||||
| CVE-2026-69443 | 1 Microsoft | 4 Windows 10 1809, Windows Server 2019, Windows Server 2022 and 1 more | 2026-09-17 | N/A | 7.5 HIGH |
| Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-69507 | 1 Microsoft | 6 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 3 more | 2026-09-17 | N/A | 5.7 MEDIUM |
| Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-69551 | 1 Microsoft | 7 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 4 more | 2026-09-17 | N/A | 8.8 HIGH |
| Use after free in Windows DNS allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-69552 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-17 | N/A | 5.7 MEDIUM |
| Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-69569 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-17 | N/A | 5.7 MEDIUM |
| Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network. | |||||
| CVE-2026-69572 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-17 | N/A | 5.7 MEDIUM |
| Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-76797 | 1 Mongodb | 1 Mongosql Transition Readiness Tool | 2026-09-17 | N/A | 6.3 MEDIUM |
| The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is later evaluated as a formula when an operator opens the generated report in a spreadsheet application, which may result in unintended disclosure of report contents or execution of external content on the operator's workstation. Generating a report for the affected namespace and opening it in a spreadsheet application is required. | |||||
| CVE-2026-76798 | 1 Mongodb | 1 Mongosql Transition Readiness Tool | 2026-09-17 | N/A | 6.3 MEDIUM |
| The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup supplied in a query is interpreted by the browser when an operator later generates and opens the report, which may disclose other users' logged query text and user names to an external party or present misleading content to the operator. Generating a report over logs containing the affected entries and opening that report in a browser is required. | |||||
