Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
390,017 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data....Show more |
An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, i...Show more |
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file. |
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov. |
1Microsoft 5365 Apps Office 2016Office 2019+2 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. |
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. |
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19 |
1Microsoft 5365 Apps Microsoft 365Office 2019+2 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The...Show more |
A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a mani...Show more |
A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argum...Show more |
The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output...Show more |
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization...Show more |
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform...Show more |
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficien...Show more |
The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and...Show more |
The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated at...Show more |
1Adobe 3Acrobat Acrobat DcAcrobat Reader DcSep 10, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op...Show more |
1Microsoft 6365 Apps AccessOffice 2016+3 moreSep 10, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. |
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
1Microsoft 5365 Apps AccessOffice 2019+2 moreSep 10, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. |
1Microsoft 6365 Apps AccessOffice 2016+3 moreSep 10, 2026 Sep 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. |