CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Sep 10, 2026
Sep 10, 2026
5.8 MEDIUM· v4
N/A· v3
N/A· v2
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data....Show more
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.Show less
-
-
Sep 10, 2026
Sep 10, 2026
4.3 MEDIUM· v4
N/A· v3
N/A· v2
An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, i...Show more
An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.Show less
-
-
Sep 10, 2026
Sep 10, 2026
2.4 LOW· v4
N/A· v3
N/A· v2
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
-
-
Sep 10, 2026
Sep 10, 2026
1.1 LOW· v4
N/A· v3
N/A· v2
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
1Microsoft
5365 Apps
Office 2016Office 2019+2 more
Sep 10, 2026
Sep 8, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
1Microsoft
1Visual Studio Code
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.4 HIGH· v3
N/A· v2
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
1Vmware
1Spring Framework
Sep 10, 2026
Aug 27, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
1Microsoft
5365 Apps
Microsoft 365Office 2019+2 more
Sep 10, 2026
Sep 8, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
1Microsoft
6365 Apps
Microsoft 365Office 2016+3 more
Sep 10, 2026
Sep 8, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.
1Microsoft
6365 Apps
Microsoft 365Office 2016+3 more
Sep 10, 2026
Sep 8, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
1Microsoft
6365 Apps
Microsoft 365Office 2016+3 more
Sep 10, 2026
Sep 8, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
-
-
Sep 10, 2026
Sep 10, 2026
8.6 HIGH· v4
9.6 CRITICAL· v3
8.3 HIGH· v2
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The...Show more
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Sep 10, 2026
Sep 10, 2026
2.1 LOW· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a mani...Show more
A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.Show less
-
-
Sep 10, 2026
Sep 9, 2026
5.5 MEDIUM· v4
7.3 HIGH· v3
7.5 HIGH· v2
A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argum...Show more
A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_category/cid/update_brand/update_product leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.Show less
-
-
Sep 10, 2026
Sep 10, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output...Show more
The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Sep 10, 2026
Sep 10, 2026
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization...Show more
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and including 4.5.13.1. This is due to insufficient input sanitization in the user_meta_save() function (which only sanitizes array values, not scalar values) and improper output escaping in the Redux_Slider::render() method, which outputs slider values into unquoted HTML attributes. The vulnerability also exploits the fact that the clean_default() method only casts values to numeric types when they are empty or out of bounds, allowing malicious strings like '1 tabindex=0 autofocus onfocus=alert(1) x=' to pass validation through PHP's loose type comparison. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts into their user profile that will execute whenever an Administrator navigates to view the attacker's profile page.Show less
-
-
Sep 10, 2026
Sep 10, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform...Show more
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to import forged CSV submission records into any Contact Form 7 form managed by the plugin.Show less
-
-
Sep 10, 2026
Sep 10, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficien...Show more
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitize_file_name() later normalizes to a PHP extension. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.Show less
-
-
Sep 10, 2026
Sep 10, 2026
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and...Show more
The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Sep 10, 2026
Sep 10, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated at...Show more
The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloadable product exists on the site — not that the requested file path belongs to that product's configured downloads — making exploitation viable on any WooCommerce site with at least one such product.Show less
1Adobe
3Acrobat
Acrobat DcAcrobat Reader Dc
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op...Show more
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Microsoft
6365 Apps
AccessOffice 2016+3 more
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
1Microsoft
1Visual Studio 2026
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
1Microsoft
5365 Apps
AccessOffice 2019+2 more
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
1Microsoft
6365 Apps
AccessOffice 2016+3 more
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.