Common Vulnerabilities and Exposures (CVE)

CVE-2026-100208

Sep 26, 2026 03:55:54 UTC

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

CVE-2026-91839

Sep 26, 2026 03:55:53 UTC

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivilege...

CVE-2026-91840

Sep 26, 2026 03:55:52 UTC

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to ...

CVE-2026-91841

Sep 26, 2026 03:55:52 UTC

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrar...

CVE-2026-87902

Sep 26, 2026 03:55:51 UTC

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are me...

CVE-2026-84882

Sep 26, 2026 03:55:50 UTC

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.

CVE-2026-84862

Sep 26, 2026 03:55:50 UTC

IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.

CVE-2026-93643

Sep 26, 2026 03:55:49 UTC

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

CVE-2026-93647

Sep 26, 2026 03:55:48 UTC

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

CVE-2026-85029

Sep 26, 2026 03:55:47 UTC

IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.

CVE-2026-84884

Sep 26, 2026 03:55:46 UTC

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an admin...

CVE-2026-85542

Sep 26, 2026 03:55:45 UTC

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to ...

CVE-2026-67279

Sep 26, 2026 03:55:45 UTC

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the se...

CVE-2026-82164

Sep 26, 2026 03:55:44 UTC

Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to In...

CVE-2026-89325

Sep 26, 2026 03:55:43 UTC

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessm...