| CVE-2026-49787 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-770 | HTTP.sys Denial of Service Vulnerability |
| CVE-2026-49788 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-770 | HTTP/2 Denial of Service Vulnerability |
| CVE-2026-50304 | 7.5 | 65.1 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50355 | 7.5 | 65.1 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50368 | 7.5 | 65.1 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50411 | 7.5 | 65.1 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50424 | 7.5 | 65.1 | Microsoft | Windows 11 Version 24H2 | CWE-822 | Windows Domain Controller Denial of Service Vulnerability |
| CVE-2026-50496 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Network Policy Server SNMP Information Disclosure Vulnerability |
| CVE-2026-50506 | 7.5 | 65.1 | Microsoft | AspNet.OData | CWE-770 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-50647 | 7.5 | 65.1 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-835 | Active Directory Federation Server Denial of Service Vulnerability |
| CVE-2026-50653 | 7.5 | 65.1 | Microsoft | Azure Active Directory | CWE-835 | Azure Active Directory Denial of Service Vulnerability |
| CVE-2026-50695 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50696 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1809 | CWE-122 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
| CVE-2026-54119 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-835 | Windows Active Directory Denial of Service Vulnerability |
| CVE-2026-54983 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-58627 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-400 | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-48322 | 9.9 | 65.0 | Adobe | ColdFusion 2025 | CWE-94 | ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94) |
| CVE-2026-49181 | 9.8 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-54117 | 9.8 | 64.9 | Microsoft | Microsoft SQL Server 2025 (CU 6) | CWE-502 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-54118 | 9.8 | 64.9 | Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | CWE-502 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-49799 | 6.5 | 64.1 | Microsoft | Windows 10 Version 1607 | CWE-400 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service … |
| CVE-2026-50366 | 6.5 | 64.1 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows Active Directory Domain Services Denial of Service Vulnerability |
| CVE-2026-56168 | 6.5 | 64.1 | Microsoft | Windows 10 Version 21H2 | CWE-476 | Windows SMB Server Denial of Service Vulnerability |
| CVE-2026-57976 | 6.5 | 64.1 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows Active Directory Domain Services Denial of Service Vulnerability |
| CVE-2026-38450 | 9.8 | 64.1 | n/a | n/a | CWE-94 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote atta… |
| CVE-2026-56186 | 6.5 | 63.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Secure Channel Information Disclosure Vulnerability |
| CVE-2026-57108 | 7.5 | 63.3 | Microsoft | .NET 10.0 | CWE-843 | .NET Denial of Service Vulnerability |
| CVE-2026-48318 | 9.9 | 63.1 | Adobe | ColdFusion 2025 | CWE-22 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Pa… |
| CVE-2026-15701 | 8.9 | 63.0 | Totolink | NR1800X | CWE-119 | Totolink NR1800X lighttpd formLogout.htm Form_Logout stack-based overflow |
| CVE-2026-15669 | 1.9 | 62.6 | louisho5 | picobot | CWE-77 | louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection |
| CVE-2026-54108 | 6.5 | 62.5 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-73 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-50429 | 8.2 | 62.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-48310 | 8.6 | 61.6 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-22 | Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted … |
| CVE-2026-14903 | 6.5 | 61.4 | ivanti | Xtraction | CWE-23 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote au… |
| CVE-2026-58529 | 7.1 | 61.3 | Microsoft | Windows 11 version 26H1 | CWE-125 | Windows Active Directory Federation Services (ADFS) Information Disclosure Vu… |
| CVE-2026-47302 | 7.5 | 61.1 | Microsoft | .NET 10.0 | CWE-770 | .NET Denial of Service Vulnerability |
| CVE-2026-50463 | 7.5 | 61.0 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50470 | 7.5 | 61.0 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Network Policy Server SNMP Information Disclosure Vulnerability |
| CVE-2026-24227 | 9.8 | 60.8 | NVIDIA | TensorRT | CWE-502 | NVIDIA TensorRT for contains a vulnerability where a user might cause a deser… |
| CVE-2026-56170 | 7.5 | 60.4 | Microsoft | .NET 10.0 | CWE-770 | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-48359 | 9.6 | 60.3 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-611 | Adobe Experience Manager | Improper Restriction of XML External Entity Refere… |
| CVE-2026-15428 | 8.5 | 60.3 | TP-Link Systems Inc. | Archer VX1800v v1 | CWE-78 | OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer … |
| CVE-2026-48356 | 9.3 | 60.2 | Adobe | Adobe Commerce | CWE-434 | Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) |
| CVE-2026-50468 | 6.5 | 60.0 | Microsoft | Microsoft SQL Server 2025 (CU 6) | CWE-126 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-54116 | 6.5 | 60.0 | Microsoft | Microsoft SQL Server 2025 (CU 6) | CWE-843 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-57982 | 6.5 | 60.0 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-47992 | 7.2 | 59.9 | Adobe | Adobe Commerce | CWE-89 | Adobe Commerce | Improper Neutralization of Special Elements used in an SQL C… |
| CVE-2026-47295 | 8.8 | 59.8 | Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | CWE-89 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-42990 | 9.8 | 59.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | SQL Server ODBC driver Elevation of Privilege Vulnerability |
| CVE-2026-49172 | 9.8 | 59.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows FTP Service Remote Code Execution Vulnerability |
| CVE-2026-50447 | 9.8 | 59.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-50518 | 9.8 | 59.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-55010 | 9.8 | 59.4 | Microsoft | Minecraft Bedrock Dedicated Server | CWE-122 | Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability |
| CVE-2026-56159 | 9.8 | 59.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-56190 | 9.8 | 59.4 | Microsoft | Windows 10 Version 1607 | CWE-908 | Remote Desktop Protocol Remote Code Execution Vulnerability |
| CVE-2026-50646 | 7.8 | 59.2 | Microsoft | .NET 8.0 | CWE-693 | .NET Framework Remote Code Execution Vulnerability |
| CVE-2026-47301 | 8.8 | 59.0 | Microsoft | Microsoft Configuration Manager | CWE-284 | Configuration Manager Elevation of Privilege Vulnerability |
| CVE-2026-56196 | 8.8 | 58.7 | Microsoft | Windows Admin Center | CWE-23 | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-50432 | 6.5 | 58.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability |
| CVE-2026-55021 | 8.7 | 58.5 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55034 | 8.7 | 58.5 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55052 | 8.8 | 58.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-862 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-58277 | 8.8 | 58.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-285 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-50663 | 8.8 | 58.2 | Microsoft | Age of Empires II: Definitive Edition Game | CWE-23 | Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability |
| CVE-2026-50649 | 7.8 | 58.2 | Microsoft | .NET 8.0 | CWE-502 | .NET Remote Code Execution Vulnerability |
| CVE-2026-50682 | 7.1 | 57.9 | Microsoft | Windows 10 Version 21H2 | CWE-125 | Active Directory Denial of Service Vulnerability |
| CVE-2026-48351 | 7.5 | 57.8 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-48352 | 7.5 | 57.8 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-56197 | 8.8 | 57.6 | Microsoft | Windows Admin Center | CWE-77 | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-50445 | 7.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-50497 | 7.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-193 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-50504 | 7.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-57979 | 7.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-58533 | 7.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-58535 | 7.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-58539 | 7.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-50376 | 6.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-54126 | 6.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-55003 | 6.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-55054 | 6.5 | 57.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-58546 | 6.5 | 57.6 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-47429 | 5.9 | 57.6 | vitest-dev | vitest | CWE-22 | Vitest: Arbitrary file can be read and executed when Vitest UI server is list… |
| CVE-2026-57092 | 9.9 | 57.4 | Microsoft | Windows 10 Version 1607 | CWE-416 | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability |
| CVE-2026-48564 | 8.8 | 57.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-49178 | 8.8 | 57.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-50666 | 8.8 | 57.4 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Remote Access Elevation of Privilege Vulnerability |
| CVE-2026-55005 | 8.8 | 57.4 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-122 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-56194 | 8.8 | 57.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NFS Server Elevation of Privilege Vulnerability |
| CVE-2026-56642 | 8.8 | 57.4 | Microsoft | Service Fabric | CWE-121 | Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability |
| CVE-2026-56647 | 8.8 | 57.4 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerabi… |
| CVE-2026-58626 | 8.8 | 57.4 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2026-55051 | 6.5 | 57.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-918 | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-34348 | 6.5 | 57.2 | Microsoft | Windows 10 Version 1809 | CWE-693 | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-48259 | 9.6 | 56.9 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-918 | Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-53633 | 9.8 | 56.8 | vitest-dev | vitest | CWE-749 | Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Le… |
| CVE-2026-48252 | 8.6 | 56.7 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-306 | Adobe Experience Manager | Missing Authentication for Critical Function (CWE-… |
| CVE-2026-48345 | 8.2 | 56.7 | Adobe | Adobe Animate 2023 | CWE-78 | Animate | Improper Neutralization of Special Elements used in an OS Command (… |
| CVE-2026-48069 | 7.5 | 56.4 | grpc | grpc-node | CWE-248 | @grpc/grps-js: An incoming malformed compressed message can cause a client or… |
| CVE-2026-47996 | 6.8 | 56.2 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-47282 | 6.5 | 56.2 | Microsoft | Visual Studio Code | CWE-522 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-40400 | 8.0 | 56.0 | Microsoft | Windows 10 Version 1607 | CWE-23 | Windows PowerShell Remote Code Execution Vulnerability |
| CVE-2026-48561 | 9.6 | 55.8 | Microsoft | Microsoft Edge Copilot for Android | CWE-77 | Microsoft Edge Copilot Remote Code Execution Vulnerability |
| CVE-2026-55008 | 9.6 | 55.8 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-79 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-50415 | 7.5 | 55.8 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Media Information Disclosure Vulnerability |
| CVE-2026-50324 | 5.9 | 55.6 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-835 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-15691 | 7.4 | 55.5 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow |
| CVE-2026-15692 | 7.4 | 55.5 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro SafeUrlFilter fromSafeUrlFilter stack-based overflow |
| CVE-2026-15693 | 7.4 | 55.5 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow |
| CVE-2026-15694 | 7.4 | 55.5 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro SetIpBind fromSetIpBind stack-based overflow |
| CVE-2026-15695 | 7.4 | 55.5 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro DhcpListClient fromDhcpListClient stack-based overflow |
| CVE-2026-15696 | 7.4 | 55.5 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro VirtualSer fromVirtualSer stack-based overflow |
| CVE-2026-51808 | 9.8 | 55.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an atta… |
| CVE-2026-15429 | 5.1 | 55.2 | TP-Link Systems Inc. | Archer VX1800v v1 | CWE-93 | Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v |
| CVE-2026-50527 | 7.5 | 55.1 | Microsoft | .NET 10.0 | CWE-121 | .NET Framework Denial of Service Vulnerability |
| CVE-2026-50648 | 7.5 | 55.1 | Microsoft | .NET 10.0 | CWE-770 | .NET Framework Denial of Service Vulnerability |
| CVE-2026-50651 | 7.5 | 55.1 | Microsoft | .NET 10.0 | CWE-770 | .NET Denial of Service Vulnerability |
| CVE-2026-56185 | 6.5 | 55.1 | Microsoft | Windows Admin Center | CWE-287 | Windows Admin Center Information Disclosure Vulnerability |
| CVE-2026-48295 | 7.5 | 54.9 | Adobe | Content Credentials Rust SDK | CWE-522 | CAI Content Credentials | Insufficiently Protected Credentials (CWE-522) |
| CVE-2026-48328 | 7.7 | 54.5 | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-57090 | 9.8 | 54.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-58594 | 9.8 | 54.5 | Microsoft | Windows 10 Version 1607 | CWE-190 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-50380 | 9.6 | 54.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-50474 | 8.8 | 54.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-54990 | 8.8 | 54.5 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-57094 | 8.8 | 54.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-57102 | 8.8 | 54.5 | Microsoft | Visual Studio Code | CWE-829 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-49164 | 9.8 | 53.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-50439 | 9.8 | 53.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability |
| CVE-2026-50487 | 9.8 | 53.5 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-50694 | 9.8 | 53.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnera… |
| CVE-2026-54995 | 9.8 | 53.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vu… |
| CVE-2026-57087 | 7.8 | 53.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-58617 | 9.8 | 53.4 | Microsoft | Microsoft 365 Copilot for iOS | CWE-284 | M365 Copilot for iOS Elevation of Privilege Vulnerability |
| CVE-2026-15709 | 7.5 | 53.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-409 | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate… |
| CVE-2026-3014 | 6.4 | 53.2 | Milestone Systems | XProtect Management Server | CWE-78 | Remote Code Execution by administrative user on the Management Server |
| CVE-2026-50360 | 8.8 | 53.1 | Microsoft | Windows 10 Version 21H2 | CWE-303 | Windows SMB Server Elevation of Privilege Vulnerability |
| CVE-2026-50444 | 8.8 | 53.1 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability |
| CVE-2026-49169 | 8.8 | 52.3 | Microsoft | Windows Server 2025 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-53486 | 9.1 | 52.1 | XhmikosR | decompress | CWE-22 | decompress: Archive extraction can create files and links outside the target … |
| CVE-2026-58319 | 9.1 | 52.1 | Apache Software Foundation | Apache Doris | CWE-306 | Apache Doris: Improper Authentication in Frontend HTTP API |
| CVE-2026-50340 | 8.8 | 51.9 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50500 | 8.8 | 51.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Netlogon Elevation of Privilege Vulnerability |
| CVE-2026-50505 | 8.8 | 51.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-47303 | 8.8 | 51.7 | Microsoft | .NET 10.0 | CWE-302 | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-47767 | 8.3 | 51.2 | symfony | symfony | CWE-436 | Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still S… |
| CVE-2026-48347 | 7.7 | 51.1 | Adobe | Adobe Animate 2023 | CWE-78 | Animate | Improper Neutralization of Special Elements used in an OS Command (… |
| CVE-2026-48332 | 7.7 | 51.0 | Adobe | ColdFusion 2025 | CWE-918 | ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-47997 | 5.9 | 50.7 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-47998 | 5.9 | 50.7 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-50686 | 8.1 | 50.7 | Microsoft | Windows 10 Version 1607 | CWE-843 | Windows OLE Remote Code Execution Vulnerability |
| CVE-2026-15714 | 6.5 | 50.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multip… |
| CVE-2026-49488 | 6.5 | 50.5 | Apache Software Foundation | Apache OpenMeetings | CWE-22 | Apache OpenMeetings: Arbitrary File Read |
| CVE-2026-50369 | 8.8 | 50.4 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-56649 | 8.1 | 50.3 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Network File System Remote Code Execution Vulnerability |
| CVE-2026-55954 | 9.1 | 50.3 | ueberauth | ueberauth_apple | CWE-290 | Missing ID token claim validation in ueberauth_apple allows account takeover |
| CVE-2026-58595 | 8.1 | 50.0 | Microsoft | Microsoft Bing Search for iOS | CWE-1021 | Microsoft Bing App for IOS Spoofing Vulnerability |
| CVE-2026-46633 | 8.7 | 50.0 | twigphp | Twig | CWE-94 | Twig: PHP code injection via `{% use %}` template name |
| CVE-2026-62390 | 9.8 | 49.9 | Apache Software Foundation | Apache Kylin | CWE-89 | Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API |
| CVE-2026-45304 | 8.7 | 49.8 | symfony | symfony | CWE-776 | Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-A… |
| CVE-2026-45305 | 8.7 | 49.8 | symfony | symfony | CWE-1333 | Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup()… |
| CVE-2026-27690 | 9.1 | 49.7 | SAP_SE | SAP Approuter | CWE-444 | HTTP Request Smuggling in SAP Approuter |
| CVE-2026-57898 | 9.0 | 49.7 | Eclipse Foundation | Eclipse BaSyx - Java Server SDK | CWE-22 | In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milesto… |
| CVE-2026-51807 | 9.8 | 49.3 | n/a | n/a | CWE-121 | Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header()… |
| CVE-2026-59837 | 6.6 | 49.2 | Fortinet | FortiPAM | CWE-121 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through… |
| CVE-2026-47988 | 8.6 | 49.1 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-45077 | 8.3 | 49.1 | symfony | symfony | CWE-502 | Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:l… |
| CVE-2026-57089 | 9.8 | 49.0 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Executio… |
| CVE-2026-5270 | 9.8 | 49.0 | CIENA | Navigator NCS | CWE-287 | Authentication Bypass in Navigator and Blue Planet Products |
| CVE-2026-50685 | 7.5 | 48.9 | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-15712 | 5.9 | 48.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap… |
| CVE-2026-50485 | 5.7 | 48.6 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2026-59203 | 7.5 | 48.6 | python-pillow | Pillow | CWE-835 | Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop … |
| CVE-2026-50502 | 8.8 | 48.6 | Microsoft | Windows 10 Version 1607 | CWE-1220 | Windows Event Logging Service Remote Code Execution Vulnerability |
| CVE-2026-55126 | 5.4 | 48.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-15738 | 5.8 | 48.2 | Amazon | aws-load-balancer-controller | CWE-653 | Cross-namespace traffic interception via incorrect route precedence ordering … |
| CVE-2026-58279 | 6.5 | 48.1 | Microsoft | Azure CycleCloud 8.9.1 | CWE-862 | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-46640 | 8.7 | 48.0 | twigphp | Twig | CWE-94 | Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference com… |
| CVE-2026-47984 | 8.2 | 47.9 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-50524 | 7.5 | 47.6 | Microsoft | .NET 10.0 | CWE-1287 | .NET Framework Denial of Service Vulnerability |
| CVE-2026-45133 | 8.2 | 47.4 | symfony | symfony | CWE-674 | Symfony: [Yaml] Harden the parser when handling untrusted input |
| CVE-2026-45756 | 8.2 | 47.4 | symfony | symfony | CWE-400 | Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match(… |
| CVE-2026-47736 | 7.5 | 47.4 | puma | puma | CWE-400 | Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion |
| CVE-2026-47994 | 8.7 | 47.1 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-55002 | 8.8 | 46.9 | Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | CWE-73 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-48068 | 7.5 | 46.8 | grpc | grpc-node | CWE-248 | @grpc/grps-js: A malformed request can cause a server crash |
| CVE-2026-46634 | 7.7 | 46.8 | twigphp | Twig | CWE-693 | Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synt… |
| CVE-2025-56365 | 7.5 | 46.8 | n/a | n/a | CWE-617 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip… |
| CVE-2026-47428 | 9.6 | 46.6 | vitest-dev | vitest | CWE-79 | Vitest browser mode serves unsanitized otelCarrier query parameter as inline … |
| CVE-2026-56188 | 8.1 | 46.4 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Server Network driver Remote Code Execution Vulnerability |
| CVE-2026-50525 | 7.5 | 46.2 | Microsoft | .NET 10.0 | CWE-770 | .NET Denial of Service Vulnerability |
| CVE-2026-45067 | 6.3 | 45.9 | symfony | symfony | CWE-93 | Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\… |
| CVE-2026-48489 | 8.7 | 45.8 | symfony | symfony | CWE-863 | Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthentic… |
| CVE-2026-55023 | 5.5 | 45.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55027 | 5.5 | 45.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55028 | 5.5 | 45.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55047 | 5.5 | 45.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55050 | 5.5 | 45.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-55124 | 5.5 | 45.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-1287 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-55142 | 5.5 | 45.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-197 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-56192 | 5.5 | 45.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-15622 | 5.5 | 45.6 | poco-ai | poco-claw | CWE-285 | poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization |
| CVE-2025-56363 | 7.5 | 45.5 | n/a | n/a | CWE-476 | A null pointer dereference vulnerability exists in the Matter SDK (connectedh… |
| CVE-2025-56364 | 7.5 | 45.2 | n/a | n/a | CWE-457 | A use of uninitialized value vulnerability exists in the Matter SDK (connecte… |
| CVE-2026-55016 | 5.4 | 45.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55019 | 5.4 | 45.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55020 | 5.4 | 45.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55030 | 5.4 | 45.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55135 | 5.4 | 45.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2025-56361 | 7.5 | 45.1 | n/a | n/a | CWE-617 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip… |
| CVE-2025-56362 | 7.5 | 45.1 | n/a | n/a | CWE-617 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip… |
| CVE-2026-50683 | 8.0 | 44.9 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-55035 | 3.3 | 44.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-49855 | 7.5 | 44.7 | tornadoweb | tornado | CWE-409 | tornado AsyncHTTPClient accumulates decompressed chunks without size limit (g… |
| CVE-2026-55032 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55033 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55038 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55055 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55125 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55127 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55128 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55130 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55132 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-415 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55134 | 7.8 | 44.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45071 | 8.7 | 44.6 | symfony | symfony | CWE-611 | Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via valid… |
| CVE-2026-48736 | 6.9 | 44.6 | symfony | symfony | CWE-184 | Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, T… |
| CVE-2026-50414 | 8.8 | 44.5 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50398 | 7.5 | 44.5 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-58608 | 7.5 | 44.5 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Print Spooler Remote Code Execution Vulnerability |
| CVE-2026-48329 | 2.7 | 44.5 | Adobe | ColdFusion 2025 | CWE-613 | ColdFusion | Insufficient Session Expiration (CWE-613) |
| CVE-2026-44747 | 9.9 | 44.3 | SAP_SE | SAP NetWeaver Application Server ABAP | CWE-787 | Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP |
| CVE-2026-52837 | 6.9 | 44.3 | alextselegidis | easyappointments | CWE-200 | Easy!Appointments has unauthenticated customer PII disclosure on booking resc… |
| CVE-2026-50528 | 8.2 | 44.2 | Microsoft | .NET 10.0 | CWE-863 | .NET Security Feature Bypass Vulnerability |
| CVE-2026-15713 | 5.9 | 44.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-772 | Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of … |
| CVE-2026-14645 | 5.1 | 44.1 | Sonatype | Nexus Repository 3 | CWE-918 | Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global C… |
| CVE-2026-50426 | 6.8 | 43.9 | Microsoft | Windows 10 Version 1607 | CWE-23 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-58233 | 7.6 | 43.8 | SAP_SE | SAP Change and Transport System Attach Tool (ctsattach) | CWE-502 | Remote Code Execution vulnerability in SAP Change and Transport System Attach… |
| CVE-2026-48325 | 9.3 | 43.7 | Adobe | ColdFusion 2025 | CWE-306 | ColdFusion | Missing Authentication for Critical Function (CWE-306) |
| CVE-2026-15427 | 8.6 | 43.6 | TP-Link Systems Inc. | Archer VX1800v v1 | CWE-78 | OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer … |
| CVE-2026-12583 | 8.1 | 43.7 | Unknown | Newsletters | CWE-502 | Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Cust… |
| CVE-2026-15265 | 9.4 | 43.6 | tenable | tenable_agent | CWE-22 | Tenable Agent Path Traversal Leading to Remote Code Execution |
| CVE-2026-52101 | 9.1 | 43.5 | n/a | n/a | CWE-200 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote at… |
| CVE-2026-50659 | 6.5 | 43.5 | Microsoft | .NET 10.0 | CWE-116 | .NET Spoofing Vulnerability |
| CVE-2026-51105 | 7.5 | 43.3 | n/a | n/a | CWE-121 | Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote … |
| CVE-2026-11403 | 8.7 | 43.1 | Sonatype | Nexus Repository Manager | CWE-331 | Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Ge… |
| CVE-2026-15720 | 8.6 | 43.1 | open5gs | open5gs | CWE-125 | Pre-auth heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler |
| CVE-2026-42900 | 8.1 | 43.1 | Microsoft | Windows 10 Version 1607 | CWE-362 | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-50460 | 8.1 | 43.1 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50365 | 8.0 | 43.1 | Microsoft | Windows 10 Version 1607 | CWE-287 | Remote Access Management service/API (RPC server) Elevation of Privilege Vuln… |
| CVE-2026-46627 | 7.1 | 43.1 | twigphp | Twig | CWE-400 | Twig: Sandbox resource exhaustion via unbounded `for` / `range()` |
| CVE-2026-46629 | 5.3 | 43.1 | twigphp | Twig | CWE-770 | Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-co… |
| CVE-2026-48580 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-50408 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55042 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55046 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55057 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55138 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-56195 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-57083 | 5.5 | 43.1 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Media Photo Codec Information Disclosure Vulnerability |
| CVE-2026-57084 | 5.5 | 43.1 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-46644 | 6.9 | 42.9 | symfony | polyfill | CWE-1289 | symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes … |
| CVE-2026-42975 | 8.8 | 42.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Bluetooth Port Driver Remote Code Execution |
| CVE-2026-11802 | 5.3 | 42.8 | themelooks | FoodBook Lite – Online Food Ordering System | CWE-862 | FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Regist… |
| CVE-2026-54982 | 8.8 | 42.7 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vu… |
| CVE-2026-12523 | 7.5 | 42.6 | Cloudflare | quiche | CWE-400 | Resource exhaustion in quiche HTTP/3 and QPACK layers |
| CVE-2025-53379 | 7.5 | 42.3 | Fortinet | FortiAuthenticator | CWE-125 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 throu… |
| CVE-2026-47300 | 8.8 | 42.2 | Microsoft | .NET 10.0 | CWE-303 | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-57969 | 8.8 | 42.2 | Microsoft | Azure CycleCloud 8.9.1 | CWE-306 | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-9292 | 8.4 | 42.3 | Rockwell Automation | FactoryTalk® DataMosaix™ Private Cloud | CWE-79 | Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Sit… |
| CVE-2026-47477 | 7.5 | 42.3 | NVIDIA | Triton Inference Server | CWE-121 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-47478 | 7.5 | 42.2 | NVIDIA | Triton Inference Server | CWE-910 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-55122 | 7.1 | 42.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55145 | 7.1 | 42.1 | Microsoft | Microsoft Copilot | CWE-77 | Outlook Copilot Tampering Vulnerability |
| CVE-2026-45068 | 8.7 | 42.1 | symfony | symfony | CWE-88 | Symfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient … |
| CVE-2026-48038 | 5.3 | 42.0 | hapijs | joi | CWE-248 | joi: Uncaught RangeError on deeply nested input through recursive `link()` sc… |
| CVE-2026-58528 | 4.6 | 42.1 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-49476 | 7.5 | 41.9 | facelessuser | soupsieve | CWE-400 | Soup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in sou… |
| CVE-2026-49477 | 7.5 | 41.9 | facelessuser | soupsieve | CWE-400 | Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selecto… |
| CVE-2026-54058 | 8.3 | 41.9 | python-pillow | Pillow | CWE-125 | Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mma… |
| CVE-2026-62642 | 6.5 | 41.8 | Roundcube | Webmail | CWE-835 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop w… |
| CVE-2026-50338 | 8.2 | 41.6 | Microsoft | Azure Spring Apps | CWE-287 | Azure Spring Apps Elevation of Privilege Vulnerability |
| CVE-2026-36035 | 6.5 | 41.6 | n/a | n/a | CWE-284 | Incorrect access control in the /api/License/deactivateOffline endpoint of CA… |
| CVE-2026-55121 | 5.5 | 41.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-58477 | 8.8 | 41.3 | Dan-in-CA | SIP | CWE-915 | Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters |
| CVE-2026-50453 | 4.6 | 41.2 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-50379 | 7.5 | 41.1 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-56648 | 7.5 | 41.1 | Microsoft | Windows 10 Version 1607 | CWE-367 | Windows NFS Server Elevation of Privilege Vulnerability |
| CVE-2026-58531 | 7.5 | 41.1 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows SMB Elevation of Privilege Vulnerability |
| CVE-2026-50665 | 3.3 | 41.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-59084 | 9.1 | 40.9 | Apache Software Foundation | Apache Tomcat | CWE-1059 | Apache Tomcat: EncryptInterceptor requirements not clearly documented |
| CVE-2026-56169 | 8.8 | 40.9 | Microsoft | Windows Admin Center | CWE-287 | Windows Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-49807 | 6.2 | 40.9 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows DirectX Information Disclosure Vulnerability |
| CVE-2026-50294 | 6.2 | 40.9 | Microsoft | Windows 10 Version 1607 | CWE-497 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-48001 | 3.7 | 40.9 | Adobe | Adobe Commerce | CWE-200 | Adobe Commerce | Information Exposure (CWE-200) |
| CVE-2026-57097 | 6.8 | 40.7 | Microsoft | Windows 10 Version 1607 | CWE-426 | Microsoft XML Security Feature Bypass Vulnerability |
| CVE-2026-50370 | 8.8 | 40.6 | Microsoft | Windows 10 Version 1607 | CWE-122 | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-58229 | 8.2 | 40.6 | elixir-mint | mint | CWE-770 | Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint cau… |
| CVE-2026-59246 | 6.3 | 40.6 | elixir-mint | mint | CWE-770 | Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size c… |
| CVE-2026-62644 | 9.8 | 40.5 | Roundcube | Webmail | CWE-290 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugi… |
| CVE-2026-12707 | 7.5 | 40.6 | Cloudflare | quiche | CWE-770 | Unbounded path event queue growth in quiche via peer-driven source connection… |
| CVE-2026-15752 | 5.5 | 40.5 | zhinianboke | xianyu-auto-reply | CWE-862 | zhinianboke xianyu-auto-reply Backend User Endpoint users authorization |
| CVE-2026-60114 | 8.7 | 40.5 | Dan-in-CA | SIP | CWE-22 | Sustainable Irrigation Platform 5.2.16 Path Traversal via JSON Backup Restore |
| CVE-2026-56451 | 10.0 | 40.4 | Siemens | Opcenter X | CWE-347 | A vulnerability has been identified in Opcenter X (All versions < V2604). Aff… |
| CVE-2026-59733 | 8.8 | 40.4 | rclone | rclone | CWE-22 | rclone `serve restic --private-repos` authorization bypass: `..` in the URL p… |
| CVE-2026-47296 | 7.5 | 40.3 | Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | CWE-89 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-56157 | 5.4 | 40.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-284 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-56193 | 3.3 | 40.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-47632 | 8.8 | 40.2 | Microsoft | Azure Connected Machine Agent | CWE-295 | Azure Connected Machine Agent Elevation of Privilege Vulnerability |
| CVE-2026-15677 | 5.5 | 40.2 | code-projects | Online Job Portal | CWE-284 | code-projects Online Job Portal JobSeekerInsert.php unrestricted upload |
| CVE-2026-57095 | 7.8 | 39.9 | Microsoft | Windows 10 Version 1607 | CWE-200 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-45074 | 7.6 | 39.8 | symfony | symfony | CWE-290 | Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-… |
| CVE-2026-47476 | 7.5 | 39.8 | NVIDIA | Triton Inference Server | CWE-400 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-47479 | 7.5 | 39.8 | NVIDIA | Triton Inference Server | CWE-400 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-47480 | 7.5 | 39.8 | NVIDIA | Triton Inference Server | CWE-248 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-47482 | 7.5 | 39.8 | NVIDIA | Triton Inference Server | CWE-401 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-15715 | 2.1 | 39.6 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System exam.php cross site scripting |
| CVE-2026-5269 | 9.8 | 39.4 | CIENA | Navigator NCS | CWE-1393 | Navigator NCS and MCP System Accounts with Default Passwords |
| CVE-2026-49804 | 6.6 | 39.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows USB Video Driver Elevation of Privilege Vulnerability |
| CVE-2026-48805 | 5.3 | 39.4 | twigphp | Twig | CWE-693 | Twig: Sandbox state regression in deprecated internal wrappers in `src/Resour… |
| CVE-2026-57101 | 6.1 | 39.4 | Microsoft | Visual Studio Code | CWE-79 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-55139 | 3.3 | 39.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-11944 | 5.3 | 39.3 | OS4ED | openSIS-Classic | CWE-22 | openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment dow… |
| CVE-2026-50661 | 4.6 | 39.3 | Microsoft | Windows 10 Version 1607 | CWE-693 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-33842 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-34328 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Audio Service Information Disclosure Vulnerability |
| CVE-2026-34349 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Media Information Disclosure Vulnerability |
| CVE-2026-41087 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50316 | 5.5 | 39.1 | Microsoft | Windows 10 Version 21H2 | CWE-532 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50334 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50339 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50350 | 5.5 | 39.1 | Microsoft | Windows 10 Version 21H2 | CWE-200 | Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability |
| CVE-2026-50352 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Cryptographic Services Information Disclosure Vulnerability |
| CVE-2026-50389 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50394 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Media Information Disclosure Vulnerability |
| CVE-2026-50409 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Overlay Filter Information Disclosure Vulnerability |
| CVE-2026-50430 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50431 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vuln… |
| CVE-2026-50434 | 5.5 | 39.1 | Microsoft | Windows 10 Version 21H2 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50442 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50456 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50473 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50483 | 5.5 | 39.1 | Microsoft | Windows 11 Version 24H2 | CWE-200 | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2026-50681 | 5.5 | 39.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Secure Channel Information Disclosure Vulnerability |
| CVE-2026-56184 | 5.5 | 39.1 | Microsoft | Windows 10 Version 21H2 | CWE-200 | Win32k Information Disclosure Vulnerability |
| CVE-2026-15625 | 2.1 | 39.1 | nextlevelbuilder | GoClaw | CWE-183 | nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand inc… |
| CVE-2026-45496 | 5.5 | 38.9 | Microsoft | Visual Studio Code | CWE-22 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-59891 | 9.6 | 38.8 | sigstore | sigstore-js | CWE-522 | Credential confusion in @sigstore/oci can leak registry credentials to an att… |
| CVE-2026-55898 | 7.1 | 38.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-46638 | 6.0 | 38.8 | twigphp | Twig | CWE-693 | Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates … |
| CVE-2026-50678 | 3.3 | 38.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-48321 | 9.3 | 38.6 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-49176 | 7.8 | 38.6 | Microsoft | Windows 10 Version 1607 | CWE-269 | Windows WalletService Elevation of Privilege Vulnerability |
| CVE-2026-50364 | 7.3 | 38.5 | Microsoft | Windows 10 Version 21H2 | CWE-59 | Windows Backup Service Elevation of Privilege Vulnerability |
| CVE-2026-48338 | 6.8 | 38.4 | Adobe | ColdFusion 2025 | CWE-22 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Pa… |
| CVE-2026-49794 | 4.6 | 38.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-62641 | 6.5 | 38.4 | Roundcube | Webmail | CWE-770 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder w… |
| CVE-2026-44745 | 8.1 | 38.3 | SAP_SE | SAP Approuter | CWE-601 | Open Redirect vulnerability in SAP Approuter |
| CVE-2026-47290 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-47305 | 7.8 | 38.3 | Microsoft | Microsoft Visual Studio 2022 version 17.12 | CWE-693 | Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-47642 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-49796 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-49797 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50301 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-50308 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50313 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50314 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-50347 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Data.dll Remote Code Execution Vulnerability |
| CVE-2026-50362 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-50386 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50388 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50448 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50461 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50467 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-50471 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50655 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-50675 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |