Common Vulnerabilities and Exposures (CVE)

CVE-2026-89156

Sep 11, 2026 04:03:05 UTC

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

CVE-2026-69600

Sep 11, 2026 03:56:52 UTC

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69911

Sep 11, 2026 03:56:51 UTC

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-81353

Sep 11, 2026 03:56:50 UTC

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

CVE-2026-81046

Sep 11, 2026 03:56:49 UTC

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within th...

CVE-2026-81468

Sep 11, 2026 03:56:48 UTC

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit t...

CVE-2026-81467

Sep 11, 2026 03:56:47 UTC

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit ...

CVE-2026-79987

Sep 11, 2026 03:56:46 UTC

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

CVE-2026-81049

Sep 11, 2026 03:56:45 UTC

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

CVE-2026-81048

Sep 11, 2026 03:56:44 UTC

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit...

CVE-2026-85217

Sep 11, 2026 03:56:43 UTC

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fu...

CVE-2026-21085

Sep 11, 2026 03:56:41 UTC

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2026-21087

Sep 11, 2026 03:56:40 UTC

Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

CVE-2026-21095

Sep 11, 2026 03:56:39 UTC

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

CVE-2026-21096

Sep 11, 2026 03:56:38 UTC

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.