CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
-
-
Sep 10, 2026
Sep 9, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
-
-
Sep 10, 2026
Sep 8, 2026
10.0 CRITICAL· v4
N/A· v3
N/A· v2
In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional exec...Show more
In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
1Synacor
1Zimbra Collaboration Suite
Sep 10, 2026
Sep 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to inc...Show more
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.Show less
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Sep 10, 2026
Sep 13, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Microsoft
10Windows 10 1507
Windows 10 1511Windows 10 1607+7 more
Sep 10, 2026
Nov 10, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server...Show more
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."Show less
4Adobe
OpensuseRedhat+1 more
9Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server From Rhui+6 more
Sep 10, 2026
May 11, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
-
-
Sep 10, 2026
Aug 18, 2026
6.0 MEDIUM· v4
N/A· v3
N/A· v2
The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatch...Show more
The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.Show less
1Redhat
2Mirror Registry For Red Hat Openshift
Quay
Sep 9, 2026
Apr 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execut...Show more
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.Show less
-
-
Sep 9, 2026
Jul 21, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organizati...Show more
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.Show less
-
-
Sep 9, 2026
Aug 11, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/securit...Show more
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.Show less
-
-
Sep 9, 2026
Aug 19, 2026
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template liter...Show more
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod schema generation without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts function formatDefaultValue. This issue is fixed in version 8.21.0.Show less
-
-
Sep 9, 2026
Aug 19, 2026
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level templ...Show more
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitted by zod schema generation without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts function formatDefaultValue. This issue is fixed in version 8.21.0.Show less
-
-
Sep 9, 2026
Aug 19, 2026
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level temp...Show more
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emitted by zod schema generation without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts function formatDefaultValue. This issue is fixed in version 8.21.0.Show less
-
-
Sep 9, 2026
Aug 19, 2026
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template...Show more
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted by zod schema generation without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts function formatDefaultValue. This issue is fixed in version 8.21.0.Show less
-
-
Sep 9, 2026
Aug 19, 2026
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template litera...Show more
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod schema generation without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts function formatDefaultValue. This issue is fixed in version 8.21.0.Show less
-
-
Sep 9, 2026
Aug 19, 2026
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated M...Show more
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated mock factory is called by tests or an MSW handler, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/core/src/getters/keys.ts function getKey and MSW mock generation. This issue is fixed in version 8.21.0.Show less