Common Vulnerabilities and Exposures (CVE)

CVE-2026-16279

Sep 8, 2026 05:45:18 UTC

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

CVE-2026-76560

Sep 8, 2026 05:17:36 UTC

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control ...

CVE-2026-18922

Sep 8, 2026 05:17:32 UTC

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated succ...

CVE-2026-18453

Sep 8, 2026 05:17:28 UTC

A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests usi...

CVE-2026-18355

Sep 8, 2026 05:17:23 UTC

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, ...

CVE-2026-86519

Sep 8, 2026 04:00:07 UTC

A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack ca...

CVE-2026-86218

Sep 8, 2026 03:55:32 UTC

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

CVE-2026-20507

Sep 8, 2026 03:55:31 UTC

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitatio...

CVE-2026-77699

Sep 8, 2026 03:55:29 UTC

Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.

CVE-2026-77698

Sep 8, 2026 03:55:28 UTC

Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.

CVE-2026-20501

Sep 8, 2026 03:55:27 UTC

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS...

CVE-2026-20502

Sep 8, 2026 03:55:26 UTC

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS...

CVE-2026-20506

Sep 8, 2026 03:55:25 UTC

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitatio...

CVE-2026-20508

Sep 8, 2026 03:55:24 UTC

In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitatio...

CVE-2026-20509

Sep 8, 2026 03:55:23 UTC

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploit...