CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 2h ago | 9.1 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| 2h ago | 9.8 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. |
| Exploit 2h ago | 9.8 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
| 2h ago | 9.8 | Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| 2h ago | 9.8 | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9 | Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.8 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9 | Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network. |
| 2h ago | 9.6 | Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. |
| Exploit 2h ago | 9.6 | DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to escape its own OS sandbox, escalate to unconfined execution, and disable the approval prompt. When the port is externally reachable via tunnel, SSH forward, or reverse proxy, a remote attacker can exploit the same flaw to create sessions, execute arbitrary commands, and exfiltrate stored conversation transcripts without credentials. |
| Exploit 2h ago | 9.8 | mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. |
| Exploit 2h ago | 9.8 | Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. |
| Exploit 2h ago | 9.3 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed. |
| Exploit 2h ago | 9.1 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignments are then read from that attacker-controlled token. Anyone able to register an Azure tenant can therefore authenticate to the Airflow UI with no prior access to the deployment. The fix for **CVE-2026-59243** was incomplete, and this advisory closes the remaining gap: that fix made the provider verify the `id_token` signature, but did not add issuer or audience checks. Operators who already applied the CVE-2026-59243 fix are **still affected and must upgrade again** — 3.7.3 is the release that shipped that fix, so every version containing it falls inside this affected range. Upgrade to apache-airflow-providers-fab `3.8.1` or later. |
| 2h ago | 9.9 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests. |
| Exploit 2h ago | 9.1 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement. |
| Exploit 2h ago | 9.8 | An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. |
| Exploit 2h ago | 9.8 | An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request. |
| Exploit 2h ago | 9.8 | An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. |