CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2026-66305

    Last Modified: 9 Sept 2026

    Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-63523

    Last Modified: 8 Sept 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-66308

    Last Modified: 8 Sept 2026

    Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-66306

    Last Modified: 8 Sept 2026

    Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

    Published: 8 Sept 2026
    9.8
    Critical

    CVE-2026-66302

    Last Modified: 9 Sept 2026

    External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-66304

    Last Modified: 8 Sept 2026

    Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

    Published: 8 Sept 2026
    2.1
    Low

    CVE-2026-86675

    Last Modified: 10 Sept 2026

    A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

    Published: 8 Sept 2026
    7.7
    High

    CVE-2026-82537

    Last Modified: 8 Sept 2026

    Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash. Attackers can craft a command string with an allowlisted word immediately followed by a hash character, separator, and denied command to pass the approval gate while bash executes the denied command with the agent's auto-execute privileges on the developer's machine.

    Published: 8 Sept 2026
    7.7
    High

    CVE-2026-82536

    Last Modified: 8 Sept 2026

    Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted prefix followed by the stderr-redirecting pipe operator and a denied command, causing the parser to approve the full pipeline while bash executes the denied component with the agent's auto-execute privileges on the developer's machine.

    Published: 8 Sept 2026
    2.1
    Low

    CVE-2026-86674

    Last Modified: 8 Sept 2026

    A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fixiation. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-79721

    Last Modified: 9 Sept 2026

    Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

    Published: 8 Sept 2026
    9.3
    Critical

    CVE-2026-76200

    Last Modified: 9 Sept 2026

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

    Published: 8 Sept 2026
    9.3
    Critical

    CVE-2026-76201

    Last Modified: 9 Sept 2026

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-77109

    Last Modified: 9 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    7.6
    High

    CVE-2026-77110

    Last Modified: 10 Sept 2026

    Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-77108

    Last Modified: 9 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

    Published: 8 Sept 2026
    8.2
    High

    CVE-2026-76202

    Last Modified: 10 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-77774

    Last Modified: 9 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    8.7
    High

    CVE-2026-77111

    Last Modified: 11 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58941

    Last Modified: 9 Sept 2026

    In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58874

    Last Modified: 9 Sept 2026

    In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-58848

    Last Modified: 9 Sept 2026

    In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58846

    Last Modified: 9 Sept 2026

    In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58839

    Last Modified: 9 Sept 2026

    In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58823

    Last Modified: 9 Sept 2026

    In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    9.8
    Critical

    CVE-2026-58822

    Last Modified: 9 Sept 2026

    In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58820

    Last Modified: 10 Sept 2026

    In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional execution privileges required.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-55294

    Last Modified: 9 Sept 2026

    In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-55290

    Last Modified: 11 Sept 2026

    In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-55285

    Last Modified: 9 Sept 2026

    In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    8
    High

    CVE-2026-55277

    Last Modified: 8 Sept 2026

    In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-55273

    Last Modified: 9 Sept 2026

    In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-55256

    Last Modified: 11 Sept 2026

    In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49932

    Last Modified: 8 Sept 2026

    In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49927

    Last Modified: 9 Sept 2026

    In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    9.8
    Critical

    CVE-2026-49921

    Last Modified: 9 Sept 2026

    In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49919

    Last Modified: 10 Sept 2026

    In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49918

    Last Modified: 11 Sept 2026

    In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.5
    Low

    CVE-2026-49895

    Last Modified: 11 Sept 2026

    In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49887

    Last Modified: 11 Sept 2026

    In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49884

    Last Modified: 11 Sept 2026

    In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-49882

    Last Modified: 10 Sept 2026

    In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49881

    Last Modified: 11 Sept 2026

    In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-49879

    Last Modified: 11 Sept 2026

    In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-45531

    Last Modified: 10 Sept 2026

    In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.3
    High

    CVE-2026-45528

    Last Modified: 11 Sept 2026

    In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 8 Sept 2026
    4.3
    Medium

    CVE-2026-45527

    Last Modified: 10 Sept 2026

    In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-45525

    Last Modified: 10 Sept 2026

    In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-45521

    Last Modified: 10 Sept 2026

    In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-45520

    Last Modified: 10 Sept 2026

    In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    Items Per Page