SEPTEMBER 17, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

169,313 records on file
Page 68 of 5,644
CVE ID Score Description
3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

3h ago
6.5

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

3h ago
6.8

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

3h ago
6.5

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

3h ago
6.5

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.

3h ago
6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

3h ago
6.5

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Exploit 3h ago
5.5

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.

Exploit 3h ago
4.3

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploit 3h ago
4.7

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

3h ago
6.5

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

3h ago
5.1

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>