CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freerdp
1Freerdp
Sep 9, 2026
Sep 3, 2026
5.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with...Show more
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.Show less
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off s...Show more
Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication.Show less
-
-
Sep 9, 2026
Sep 4, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same network segment can int...Show more
Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same network segment can intercept MQTT traffic and obtain sensitive device information and operational data, including device identifiers, message metadata, and control-related information.Show less
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An att...Show more
UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.Show less
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
1Microsoft
1Sharepoint Server
Sep 9, 2026
Sep 8, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
6.6 MEDIUM· v3
N/A· v2
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.