Common Vulnerabilities and Exposures (CVE)

CVE-2026-21093

Sep 9, 2026 04:47:41 UTC

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2026-21092

Sep 9, 2026 04:47:40 UTC

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

CVE-2026-21091

Sep 9, 2026 04:47:39 UTC

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2026-21090

Sep 9, 2026 04:47:38 UTC

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2026-21089

Sep 9, 2026 04:47:36 UTC

Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2026-21088

Sep 9, 2026 04:47:35 UTC

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2026-21087

Sep 9, 2026 04:47:34 UTC

Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

CVE-2026-21086

Sep 9, 2026 04:47:33 UTC

Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.

CVE-2026-21085

Sep 9, 2026 04:47:32 UTC

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2026-21042

Sep 9, 2026 04:42:50 UTC

Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.

CVE-2026-11821

Sep 9, 2026 04:28:34 UTC

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that ...

CVE-2026-19945

Sep 9, 2026 04:28:34 UTC

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possi...

CVE-2026-69314

Sep 9, 2026 04:28:07 UTC

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69607

Sep 9, 2026 04:27:52 UTC

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

CVE-2026-76202

Sep 9, 2026 04:27:45 UTC

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue doe...