SEPTEMBER 23, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,446 records on file
Page 554 of 4,949
CVE ID Score Description
Exploit 1mo ago
7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single unauthenticated WebSocket frame containing a deeply nested JSON document crashes the FreeSWITCH process via stack overflow, terminating all calls and sessions on the host. The recursion drives the worker thread's stack pointer into the stack guard page, raising SIGSEGV from the kernel before any usable write primitive develops. This issue has been patched in version 1.11.1.

Exploit 1mo ago
7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's WebSocket frame loop intercepts a #-prefixed speed-test protocol (#SPU / #SPB / #SPE) before any authentication check. The declared payload size in #SPU was parsed with atoi() and only rejected non-positive values, so an unauthenticated peer could request up to INT_MAX bytes. The server then wrote roughly size * 10 bytes back during the download phase, on the order of 20 GB per request, yielding strong outbound bandwidth amplification from a short request. This issue has been patched in version 1.11.1.

Exploit 1mo ago
7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packet whose declared attribute length is shorter than the structure the parser casts to causes the parser to read and write past the end of the attribute, producing an out-of-bounds memory access on the per-leg media buffer. This issue has been patched in version 1.11.0.

1mo ago
7.8

Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

1mo ago
7.5

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

1mo ago
7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

1mo ago
7.9

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

1mo ago
7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

1mo ago
7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

1mo ago
7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

1mo ago
7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

1mo ago
7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

1mo ago
7.1

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

1mo ago
7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

1mo ago
7.8

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

1mo ago
7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

1mo ago
7.9

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

1mo ago
7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

1mo ago
8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

1mo ago
8.2

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

1mo ago
7

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

1mo ago
8.4

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

1mo ago
7.3

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

1mo ago
8.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1mo ago
8

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

1mo ago
7

Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

1mo ago
8.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

1mo ago
7.1

Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.

Exploit 1mo ago
7.2

md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the resulting page without sanitization, allowing arbitrary JavaScript execution in the context of the affected domain. This issue has been patched in version 1.10.3.