Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
375,278 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to...Show more |
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming request...Show more |
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. |
1Microsoft 1Azure Sql Managed Instance Aug 12, 2026 Aug 7, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. |
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. |
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. |
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |