Export limit exceeded: 102834 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (102834 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69290 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-24 | 7.8 High |
| Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-95985 | 1 Amazon | 1 Kiro Ide | 2026-09-24 | 8.8 High |
| The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create. | ||||
| CVE-2026-69538 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-24 | 7.8 High |
| Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. | ||||
| CVE-2026-69535 | 1 Microsoft | 15 Windows 10 21h2, Windows 10 21h2, Windows 10 22h2 and 12 more | 2026-09-24 | 7.8 High |
| Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69534 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-24 | 7.8 High |
| Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69300 | 1 Microsoft | 11 Windows 11 23h2, Windows 11 23h2, Windows 11 24h2 and 8 more | 2026-09-24 | 7 High |
| Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69301 | 1 Microsoft | 25 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 22 more | 2026-09-24 | 8 High |
| Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69305 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-24 | 7.1 High |
| Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69309 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-24 | 7 High |
| Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69383 | 1 Microsoft | 10 Windows 11 23h2, Windows 11 23h2, Windows 11 24h2 and 7 more | 2026-09-24 | 7 High |
| External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-8431 | 1 Mongodb | 1 Ops Manager | 2026-09-24 | 7.2 High |
| An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax. This issue affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager versions 8.0.22 and prior. | ||||
| CVE-2026-24180 | 1 Nvidia | 2 Dali, Data Loading Library | 2026-09-24 | 7.3 High |
| NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-24181 | 1 Nvidia | 2 Dali, Data Loading Library | 2026-09-24 | 7.3 High |
| NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-78512 | 1 Microsoft | 12 365 Apps, Microsoft 365, Microsoft Office Ltsc For Mac 2021 and 9 more | 2026-09-24 | 8.8 High |
| Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-58820 | 1 Google | 1 Android | 2026-09-24 | 7.8 High |
| In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional execution privileges required. | ||||
| CVE-2026-58823 | 1 Google | 1 Android | 2026-09-24 | 7.8 High |
| In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-58839 | 1 Google | 1 Android | 2026-09-24 | 7.8 High |
| In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-58846 | 1 Google | 1 Android | 2026-09-24 | 7.8 High |
| In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-58848 | 1 Google | 1 Android | 2026-09-24 | 7 High |
| In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-93759 | 1 Mongodb | 1 Mongoid | 2026-09-24 | 8.6 High |
| Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance. | ||||