Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
388,134 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. |
Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. |
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally. |
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally. |
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this v...Show more |
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_l...Show more |
1Microsoft 6365 Apps Microsoft 365Office 2019+3 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. |
1Microsoft 6365 Apps Microsoft 365Office 2019+3 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. |
1Microsoft 6365 Apps Microsoft 365Office 2019+3 moreSep 9, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. |
1Captcha Protected Page Project 1Captcha Protected Page Sep 9, 2026 Sep 2, 2026 N/A· v4 3.7 LOW· v3 N/A· v2 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. |
1Address Suggestion Project 1Address Suggestion Sep 9, 2026 Sep 2, 2026 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0....Show more |
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experie...Show more |
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potenti...Show more |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access co...Show more |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access cou...Show more |
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. |