Common Vulnerabilities and Exposures (CVE)

CVE-2026-19546

Sep 9, 2026 21:58:19 UTC

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546...

CVE-2026-88069

Sep 9, 2026 21:55:26 UTC

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remain...

CVE-2026-87922

Sep 9, 2026 21:45:08 UTC

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the compo...

CVE-2026-88002

Sep 9, 2026 21:40:06 UTC

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tracke...

CVE-2026-88001

Sep 9, 2026 21:38:05 UTC

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect destinations when AIOH...

CVE-2026-73024

Sep 9, 2026 21:36:37 UTC

Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69492

Sep 9, 2026 21:36:36 UTC

Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69334

Sep 9, 2026 21:36:35 UTC

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-68877

Sep 9, 2026 21:36:35 UTC

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.

CVE-2026-69508

Sep 9, 2026 21:36:34 UTC

Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-69777

Sep 9, 2026 21:36:34 UTC

Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2026-83711

Sep 9, 2026 21:36:33 UTC

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-80098

Sep 9, 2026 21:36:33 UTC

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70352

Sep 9, 2026 21:36:32 UTC

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62906

Sep 9, 2026 21:36:32 UTC

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.