Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
388,134 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally. |
Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network. |
Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges over a network. |
1Microsoft 7Windows 10 1607 Windows 10 1809Windows Server 2012+4 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.0 HIGH· v3 N/A· v2 Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. |
Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally. |
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. |
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. |
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges...Show more |
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicio...Show more |
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refr...Show more |
1Wso2 8Api Control Plane Api ManagerIdentity Server+5 moreSep 9, 2026 Sep 3, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code...Show more |
A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal....Show more |
1Hitachienergy 1Microscada X Sys600 Sep 9, 2026 Sep 3, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control ov...Show more |
1Hitachienergy 1Microscada X Sys600 Sep 9, 2026 Sep 3, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system i...Show more |
1Hitachienergy 1Microscada X Sys600 Sep 9, 2026 Sep 3, 2026 4.6 MEDIUM· v4 7.8 HIGH· v3 N/A· v2 A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment con...Show more |
1Microsoft 5365 Apps Office 2019Office 2021+2 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network. |
1Microsoft 5365 Apps Office 2016Office 2019+2 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. |
1Microsoft 5365 Apps Office 2016Office 2019+2 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. |
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destinati...Show more |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreSep 9, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
1Microsoft 5365 Apps Office 2019Office 2021+2 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
1Microsoft 5365 Apps Microsoft 365Office 2019+2 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network. |
1Microsoft 5365 Apps Office 2016Office 2019+2 moreSep 9, 2026 Sep 8, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. |