CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Aug 12, 2026
Jun 19, 2026
N/A· v4
7.6 HIGH· v3
N/A· v2
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to...Show more
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.Show less
-
-
Aug 12, 2026
Jul 28, 2026
N/A· v4
8.5 HIGH· v3
N/A· v2
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming request...Show more
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.Show less
-
-
Aug 12, 2026
Aug 10, 2026
10.0 CRITICAL· v4
10.0 CRITICAL· v3
N/A· v2
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
1Microsoft
1Azure Sql Managed Instance
Aug 12, 2026
Aug 7, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
-
-
Aug 12, 2026
Aug 11, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.