Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
388,135 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. |
Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. |
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. |
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. |
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
Use after free in SQL Server allows an authorized attacker to execute code over a network. |
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification use...Show more |
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend...Show more |
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking anothe...Show more |
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could ex...Show more |
Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption. Scenario caused by f...Show more |
Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code. |
PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_d...Show more |
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects a...Show more |
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. |
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. |
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |