CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-67386 | MEDIUM | 6.5 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-67385 | HIGH | 8.8 | Use after free in SQL Server allows an authorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-67383 | MEDIUM | 6.5 | Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-67379 | HIGH | 8.5 | Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-67376 | HIGH | 7.5 | Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-67369 | MEDIUM | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-66816 | MEDIUM | 6.5 | Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network. | Sep 8, 2026 | |
| CVE-2026-65812 | MEDIUM | 6.8 | Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-62895 | HIGH | 8.8 | Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-62804 | HIGH | 7.8 | External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Sep 8, 2026 | |
| CVE-2026-62801 | MEDIUM | 6.5 | Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network. | Sep 8, 2026 | |
| CVE-2026-62762 | MEDIUM | 6.5 | Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-62706 | HIGH | 8.8 | Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-62697 | HIGH | 7.8 | Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-58649 | MEDIUM | 6.5 | Origin validation error in .NET allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-57099 | HIGH | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-57098 | HIGH | 7.5 | Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-56172 | HIGH | 7.8 | Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-48707 | LOW | 3.1 | InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix. | Sep 8, 2026 | |
| CVE-2026-86668 | MEDIUM | 4.3 | A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | Sep 8, 2026 | |
| CVE-2026-86667 | MEDIUM | 4.7 | A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | Sep 8, 2026 | |
| CVE-2026-84392 | LOW | 2.7 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. | Sep 8, 2026 | |
| CVE-2026-84391 | MEDIUM | 6.5 | A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here> | Sep 8, 2026 | |
| CVE-2026-84387 | HIGH | 7.2 | A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | Sep 8, 2026 | |
| CVE-2026-84386 | MEDIUM | 5.1 | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here> | Sep 8, 2026 |