Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
388,121 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code. |
PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_d...Show more |
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects a...Show more |
An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an overs...Show more |
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and th...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformSep 9, 2026 Jun 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condit...Show more |
1Netgear 26Be9300 Firmware Mr60 FirmwareMs60 Firmware+23 moreSep 9, 2026 Aug 11, 2026 4.9 MEDIUM· v4 6.8 MEDIUM· v3 N/A· v2 A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality...Show more |
1Netgear 26Be9300 Firmware Mr60 FirmwareMs60 Firmware+23 moreSep 9, 2026 Aug 11, 2026 4.3 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. |
Insufficient input validation vulnerability in the NETGEAR R7000 models
allows authenticated administrators connected to the local network to
make unauthorized modification to router software and functionality. |
1Netgear 27Mr60 Firmware Mr70 FirmwareMr90 Firmware+24 moreSep 9, 2026 Aug 11, 2026 4.9 MEDIUM· v4 6.4 MEDIUM· v3 N/A· v2 A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise...Show more |
1Netgear 13Rax20 Firmware Rax41 FirmwareRax41v2 Firmware+10 moreSep 9, 2026 Aug 11, 2026 4.3 MEDIUM· v4 4.5 MEDIUM· v3 N/A· v2 Insufficient input validation vulnerability in the listed
NETGEAR models allows authenticated administrators connected to the
local network to make unauthorized modification to the device software and
functionality. |
1Netgear 11Rax41 Firmware Rax41v2 FirmwareRax42 Firmware+8 moreSep 9, 2026 Aug 11, 2026 1.1 LOW· v4 4.9 MEDIUM· v3 N/A· v2 A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. |
1Netgear 15Mr70 Firmware Mr90 FirmwareMs70 Firmware+12 moreSep 9, 2026 Aug 11, 2026 1.1 LOW· v4 2.7 LOW· v3 N/A· v2 A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. |
1Netgear 19Rax20 Firmware Rax35v2 FirmwareRax41 Firmware+16 moreSep 9, 2026 Aug 11, 2026 1.9 LOW· v4 4.9 MEDIUM· v3 N/A· v2 A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. |
1Netgear 20R7000 Firmware Rax20 FirmwareRax35v2 Firmware+17 moreSep 9, 2026 Aug 11, 2026 1.9 LOW· v4 4.9 MEDIUM· v3 N/A· v2 A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. |
The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed...Show more |
1Mediatek 19Mt2735 Firmware Mt6833 FirmwareMt6853 Firmware+16 moreSep 9, 2026 Sep 7, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional executio...Show more |
1Mediatek 57Mt2716 Firmware Mt2735 FirmwareMt2737 Firmware+54 moreSep 9, 2026 Sep 7, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional executio...Show more |
1Mediatek 53Mt2718 Firmware Mt6580 FirmwareMt6739 Firmware+50 moreSep 9, 2026 Sep 7, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...Show more |
1Mediatek 53Mt2718 Firmware Mt6580 FirmwareMt6739 Firmware+50 moreSep 9, 2026 Sep 7, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...Show more |
1Mediatek 22Mt2716 Firmware Mt6835 FirmwareMt6858 Firmware+19 moreSep 9, 2026 Sep 7, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01...Show more |
The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatch...Show more |
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker...Show more |
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-...Show more |
A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an err...Show more |