CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Microsoft.diagnostics.runtime
Visual Studio 2022Visual Studio 2026
Sep 29, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
1Microsoft
1Spring Cloud
Sep 29, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
1Microsoft
1Webp Image Extension
Sep 29, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Sep 29, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
1Microsoft
1Power Automate For Desktop
Sep 29, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
1Microsoft
1Dynamics 365
Sep 29, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
1Microsoft
1Azure Cyclecloud
Sep 29, 2026
Sep 8, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Sep 29, 2026
Sep 8, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Sep 29, 2026
Sep 8, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
1Microsoft
8Windows 10 21h2
Windows 10 22h2Windows 11 23h2+5 more
Sep 29, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
1Mongodb
1Mongodb
Sep 29, 2026
Sep 11, 2026
7.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holdi...Show more
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Successful use of this issue may impact the confidentiality, integrity, and availability of the affected server process.Show less
1Microsoft
1Windows 11 26h1
Sep 29, 2026
Sep 14, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
1Sonatype
1Nexus Repository Manager
Sep 29, 2026
Sep 2, 2026
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components t...Show more
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.Show less
1Mongodb
1C Driver
Sep 29, 2026
Sep 17, 2026
9.2 CRITICAL· v4
8.1 HIGH· v3
N/A· v2
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontr...Show more
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.Show less
-
-
Sep 29, 2026
Sep 25, 2026
2.1 LOW· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such man...Show more
A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file managevideos2.php. Such manipulation of the argument editassid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Sep 29, 2026
Sep 25, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can...Show more
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users via POST /sys/user/update and POST /sys/user/delete endpoints.Show less
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted...Show more
Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)Show less
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTM...Show more
Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)Show less
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security se...Show more
Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)Show less
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity...Show more
Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)Show less
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (...Show more
Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)Show less
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML...Show more
Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)Show less
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted H...Show more
Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)Show less
-
-
Sep 29, 2026
Sep 29, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)