| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69829 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69824 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69819 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69769 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69768 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69730 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69715 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69641 | Cri | 0.59 | 9.1 | 0.01 | Sep 8, 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69595 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69590 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | ||
| CVE-2026-69586 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69579 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69525 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69496 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69493 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69491 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69463 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69431 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69408 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69356 | Cri | 0.61 | 9.3 | 0.01 | Sep 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-69276 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-68839 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-67643 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-67636 | Cri | 0.59 | 9.0 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-67631 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-67378 | Cri | 0.59 | 9.0 | 0.01 | Sep 8, 2026 | Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65669 | Cri | 0.62 | 9.6 | 0.01 | Sep 8, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-82533 | Cri | 0.55 | 9.6 | 0.01 | Sep 8, 2026 | DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the… | ||
| CVE-2026-79570 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||
| CVE-2026-79569 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||
| CVE-2026-78997 | Cri | 0.60 | 9.3 | 0.00 | Sep 8, 2026 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain… | ||
| CVE-2026-75156 | Cri | 0.52 | 9.1 | 0.00 | Sep 8, 2026 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are… | ||
| CVE-2026-26084 | Cri | 0.64 | 9.9 | 0.00 | Sep 8, 2026 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests. | ||
| CVE-2026-86840 | Cri | 0.59 | 9.1 | 0.00 | Sep 8, 2026 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on… | ||
| CVE-2026-79574 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. | ||
| CVE-2026-79577 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request. | ||
| CVE-2026-79576 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. | ||
| CVE-2026-79571 | Cri | 0.59 | 9.1 | 0.01 | Sep 8, 2026 | Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without… | ||
| CVE-2026-61516 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session.… | ||
| CVE-2026-12745 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12744 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12650 | Cri | 0.64 | 9.9 | 0.02 | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12647 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12646 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12645 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-77098 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. | ||
| CVE-2026-77092 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor. | ||
| CVE-2026-77089 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. | ||
| CVE-2026-78234 | Cri | 0.64 | 9.9 | 0.00 | Sep 8, 2026 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource.… | ||
| CVE-2026-71377 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from… |
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.
- risk 0.59cvss 9.1epss 0.01
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- risk 0.64cvss 9.8epss 0.01
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- risk 0.61cvss 9.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.64cvss 9.8epss 0.01
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.59cvss 9.0epss 0.01
Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.59cvss 9.0epss 0.01
Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.62cvss 9.6epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
- risk 0.55cvss 9.6epss 0.01
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the…
- risk 0.64cvss 9.8epss 0.00
mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
- risk 0.64cvss 9.8epss 0.00
Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
- risk 0.60cvss 9.3epss 0.00
UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain…
- risk 0.52cvss 9.1epss 0.00
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are…
- risk 0.64cvss 9.9epss 0.00
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
- risk 0.59cvss 9.1epss 0.00
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on…
- risk 0.64cvss 9.8epss 0.01
An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.
- risk 0.64cvss 9.8epss 0.00
An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.
- risk 0.64cvss 9.8epss 0.00
An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.
- risk 0.59cvss 9.1epss 0.01
Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without…
- risk 0.64cvss 9.8epss 0.01
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session.…
- risk 0.64cvss 9.8epss 0.02
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.8epss 0.02
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.9epss 0.02
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.9epss 0.01
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.9epss 0.01
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.9epss 0.01
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.8epss 0.00
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
- risk 0.64cvss 9.8epss 0.00
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
- risk 0.64cvss 9.8epss 0.01
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
- risk 0.64cvss 9.9epss 0.00
A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource.…
- risk 0.64cvss 9.8epss 0.01
Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from…