Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
390,160 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 S...Show more |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreSep 10, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreSep 10, 2026 Sep 8, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
1Microsoft 4365 Apps Office 2019Office 2021+1 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
1Microsoft 5365 Apps Microsoft 365Office 2019+2 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
1Microsoft 5Windows 11 23h2 Windows 11 24h2Windows 11 25h2+2 moreSep 10, 2026 Sep 8, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. |
Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-...Show more |
Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shel...Show more |
Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the c...Show more |
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab s...Show more |
A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked...Show more |
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fa...Show more |
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in...Show more |
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/open_webui/utils/tools.py captured a cookie jar from the enclosing connection loop instead of bindin...Show more |
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is a...Show more |
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data....Show more |
An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, i...Show more |
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file. |
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov. |
1Microsoft 5365 Apps Office 2016Office 2019+2 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. |
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. |
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19 |
1Microsoft 5365 Apps Microsoft 365Office 2019+2 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreSep 10, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. |