CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2026-86672

    Last Modified: 11 Sept 2026

    A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Sept 2026
    8.3
    High

    CVE-2026-81821

    Last Modified: 11 Sept 2026

    The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.

    Published: 8 Sept 2026
    8.3
    High

    CVE-2026-81822

    Last Modified: 11 Sept 2026

    The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.

    Published: 8 Sept 2026
    5.9
    Medium

    CVE-2026-86074

    Last Modified: 11 Sept 2026

    n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticated requests, redirects, or probes to reach another origin. The affected logic includes packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts and the extractServiceOrigin origin derivation. This issue is fixed in versions 2.37.7 and 2.38.2.

    Published: 8 Sept 2026
    6.9
    Medium

    CVE-2026-81823

    Last Modified: 11 Sept 2026

    The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.

    Published: 8 Sept 2026
    6.3
    Medium

    CVE-2026-81824

    Last Modified: 11 Sept 2026

    The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.

    Published: 8 Sept 2026
    2.9
    Low

    CVE-2026-86670

    Last Modified: 8 Sept 2026

    A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Sept 2026
    7.4
    High

    CVE-2026-76196

    Last Modified: 9 Sept 2026

    Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.

    Published: 8 Sept 2026
    5
    Medium

    CVE-2026-79904

    Last Modified: 9 Sept 2026

    Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    3.1
    Low

    CVE-2026-48707

    Last Modified: 11 Sept 2026

    InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-62804

    Last Modified: 8 Sept 2026

    External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 8 Sept 2026
    7.4
    High

    CVE-2026-84003

    Last Modified: 11 Sept 2026

    Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83498

    Last Modified: 10 Sept 2026

    Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-83501

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-85875

    Last Modified: 9 Sept 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-84000

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-83997

    Last Modified: 11 Sept 2026

    Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83995

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-83992

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83990

    Last Modified: 10 Sept 2026

    Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-83989

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83985

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83983

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83987

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83980

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83982

    Last Modified: 9 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83978

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83977

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83981

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83973

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-70145

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83968

    Last Modified: 10 Sept 2026

    Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83972

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83970

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83967

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83954

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-83971

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-69598

    Last Modified: 10 Sept 2026

    Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-72965

    Last Modified: 10 Sept 2026

    Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    4.6
    Medium

    CVE-2026-69381

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-69530

    Last Modified: 10 Sept 2026

    Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-83949

    Last Modified: 8 Sept 2026

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-83951

    Last Modified: 8 Sept 2026

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-81963

    Last Modified: 8 Sept 2026

    Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8
    High

    CVE-2026-83948

    Last Modified: 8 Sept 2026

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-77897

    Last Modified: 9 Sept 2026

    Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-57099

    Last Modified: 8 Sept 2026

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

    Published: 8 Sept 2026
    8.2
    High

    CVE-2026-83939

    Last Modified: 10 Sept 2026

    Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-83940

    Last Modified: 10 Sept 2026

    Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-77906

    Last Modified: 9 Sept 2026

    Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    Items Per Page