Security Box Score — July 14, 2026 — page 2
Edition of July 14, 2026, continued — page 2 of 3. Back to page 1 · page 3
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-54124 | 7.8 | 38.3 | Microsoft | Windows 10 Version 21H2 | CWE-190 | Windows Terminal Remote Code Execution Vulnerability |
| CVE-2026-54131 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-54993 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1809 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-55017 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55018 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55022 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55024 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55025 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55029 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55031 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55036 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55037 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55039 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-191 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55041 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55043 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-55044 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55048 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55049 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55053 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55056 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55058 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55120 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-55123 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-55129 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55131 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55133 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft OneNote Remote Code Execution Vulnerability |
| CVE-2026-55136 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55137 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55140 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55141 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55899 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55947 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55948 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55949 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-56156 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-58609 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-58610 | 7.8 | 38.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-58618 | 7.8 | 38.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-54988 | 6.1 | 38.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-15700 | 2.0 | 38.0 | n/a | DedeCMS | CWE-22 | DedeCMS Album Publishing Feature zip.class.php ExtractFile path traversal |
| CVE-2026-45073 | 6.3 | 37.7 | symfony | symfony | CWE-89 | Symfony: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix |
| CVE-2026-50416 | 3.3 | 37.7 | Microsoft | Windows 11 Version 24H2 | CWE-200 | Win32k Information Disclosure Vulnerability |
| CVE-2026-50419 | 3.3 | 37.7 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50462 | 7.8 | 37.7 | Microsoft | Windows 10 Version 1607 | CWE-73 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-15698 | 2.1 | 37.7 | kofrasa | mingo | CWE-94 | kofrasa mingo Update API updateMany prototype pollution |
| CVE-2026-15702 | 2.1 | 37.7 | n/a | tamagui | CWE-94 | tamagui config.ts updateConfig prototype pollution |
| CVE-2026-48000 | 6.1 | 37.7 | Adobe | Adobe Commerce | CWE-601 | Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) |
| CVE-2026-62393 | 4.3 | 37.5 | Apache Software Foundation | Apache Kylin | CWE-280 | Apache Kylin: Improper authorization in job information retrieval |
| CVE-2026-15776 | 8.8 | 37.3 | Chrome | CWE-843 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 a… | |
| CVE-2026-55026 | 5.5 | 37.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-14504 | 8.2 | 37.0 | Sonatype | Nexus Repository 3 | CWE-862 | Nexus Repository 3 - Authorization Bypass in Component Upload API |
| CVE-2026-15753 | 2.1 | 37.0 | zhinianboke | xianyu-auto-reply | CWE-650 | zhinianboke xianyu-auto-reply review approve trusting http permission methods… |
| CVE-2026-55045 | 8.4 | 36.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-15697 | 2.1 | 37.0 | svgdotjs | svg.js | CWE-94 | svgdotjs svg.js npm Package API EventTarget.on prototype pollution |
| CVE-2026-15699 | 2.1 | 37.0 | spencermountain | compromise | CWE-94 | spencermountain compromise Public Root API extend.js nlp.extend prototype pol… |
| CVE-2026-59197 | 8.2 | 36.9 | python-pillow | Pillow | CWE-190 | Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integ… |
| CVE-2026-45754 | 6.9 | 36.8 | symfony | symfony | CWE-287 | Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret —… |
| CVE-2026-48125 | 5.3 | 36.8 | faisalman | ua-parser-js | CWE-400 | UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withCl… |
| CVE-2026-49180 | 5.5 | 36.7 | Microsoft | Windows 10 Version 1607 | CWE-59 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
| CVE-2026-49177 | 5.5 | 36.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows TCP/IP Information Disclosure Vulnerability |
| CVE-2026-15416 | 8.9 | 36.6 | argoproj | argo-helm | CWE-306 | Argo-cd: argo cd unauthenticated remote code execution in repo-server via gen… |
| CVE-2026-15389 | 8.7 | 36.5 | Sesame Time | Sesame Time | CWE-639 | Inadequate access control in Sesame Time session management |
| CVE-2026-62643 | 10.0 | 36.5 | Roundcube | Webmail | CWE-918 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Casca… |
| CVE-2024-7708 | 7.5 | 36.5 | Eclipse Foundation | Eclipse Jetty | CWE-400 | For requests that have a body, but reading the body may end up in reading 0 b… |
| CVE-2026-49168 | 6.8 | 36.3 | Microsoft | Windows 10 Version 1607 | CWE-190 | Storage Spaces Direct Elevation of Privilege Vulnerability |
| CVE-2026-50298 | 6.8 | 36.3 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Spaceport.sys Elevation of Privilege Vulnerability |
| CVE-2026-50299 | 6.8 | 36.3 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Storage Spaces Direct Remote Code Execution Vulnerability |
| CVE-2026-50492 | 6.8 | 36.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-50668 | 6.8 | 36.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-54132 | 6.8 | 36.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-11390 | 6.4 | 36.3 | blazethemes | News Kit Addons For Elementor | CWE-79 | News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored … |
| CVE-2026-15690 | 1.3 | 36.3 | n/a | open62541 | CWE-404 | open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null … |
| CVE-2026-47481 | 6.5 | 36.2 | NVIDIA | Triton Inference Server | CWE-288 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-61520 | 6.3 | 36.2 | SimpleMachines | SMF | CWE-918 | Simple Machines Forum SSRF via image proxy |
| CVE-2026-44761 | 9.1 | 36.0 | SAP_SE | SAP Commerce Cloud | CWE-1392 | Insecure Sample Credentials in SAP Commerce Cloud |
| CVE-2026-15711 | 7.5 | 35.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service… |
| CVE-2026-15675 | 5.5 | 35.7 | code-projects | Online Job Portal | CWE-74 | code-projects Online Job Portal EditUser.php sql injection |
| CVE-2026-15676 | 5.5 | 35.7 | code-projects | Online Job Portal | CWE-74 | code-projects Online Job Portal DeleteUser.php sql injection |
| CVE-2026-15703 | 5.5 | 35.7 | SourceCodester | Simple and Nice Shopping Cart Script | CWE-74 | SourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.ph… |
| CVE-2026-15619 | 2.1 | 35.7 | mosaxiv | clawlet | CWE-918 | mosaxiv clawlet IPv4 tool_web_fetch.go web_fetch server-side request forgery |
| CVE-2026-45075 | 8.3 | 35.5 | symfony | symfony | CWE-863 | Symfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[Is… |
| CVE-2026-10051 | 6.9 | 35.5 | Eclipse Foundation | Eclipse Jetty | CWE-200 | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to… |
| CVE-2026-14902 | 6.1 | 35.5 | ivanti | Xtraction | CWE-601 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote … |
| CVE-2025-11698 | 9.2 | 35.4 | Rockwell Automation | CompactLogix® 5380 Recovery Image Compact GuardLogix® 5380 Recovery Image CompactLogix® 5480 Recovery Image ControlLogix® 5580 Recovery Image GuardLogix® 5580 Recovery Image | CWE-120 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer … |
| CVE-2025-12011 | 9.2 | 35.4 | Rockwell Automation | CompactLogix® 5370 Compact GuardLogix® 5370 ControlLogix® 5570 GuardLogix® 5570 | CWE-120 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer … |
| CVE-2025-12012 | 9.2 | 35.4 | Rockwell Automation | CompactLogix® 5370 Compact GuardLogix® 5370 ControlLogix® 5570 GuardLogix® 5570 | CWE-120 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer … |
| CVE-2026-8590 | 8.7 | 35.4 | Spotfire | Spotfire Enterprise | — | Spotfire OAuth2 PKCE Bypass for public clients |
| CVE-2026-9140 | 8.7 | 35.4 | Rockwell Automation | 1718-AENTR/1719-AENTR | CWE-770 | 1718-AENTR/1719-AENTR - Denial of Service |
| CVE-2026-10573 | 8.7 | 35.4 | Rockwell Automation | 1734 POINT I/O | CWE-770 | 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object |
| CVE-2026-12659 | 8.7 | 35.4 | Rockwell Automation | The FLEX 5000® EtherNet/IP Adapter | CWE-415 | Rockwell Automation Flex 5000® Adapter - Denial of Service |
| CVE-2026-15626 | 2.1 | 35.2 | nextlevelbuilder | GoClaw | CWE-22 | nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile pat… |
| CVE-2026-15629 | 2.1 | 35.2 | louisho5 | picobot | CWE-59 | louisho5 picobot Workspace filesystem.go GetSkill link following |
| CVE-2026-15627 | 2.1 | 34.7 | nextlevelbuilder | GoClaw | CWE-200 | nextlevelbuilder GoClaw tool.go handleNavigate information disclosure |
| CVE-2026-15767 | 8.8 | 34.6 | Chrome | CWE-122 | Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.787… | |
| CVE-2026-48806 | 7.1 | 34.6 | twigphp | Twig | CWE-693 | Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys |
| CVE-2026-50428 | 5.5 | 34.0 | Microsoft | Windows 11 version 26H1 | CWE-125 | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclo… |
| CVE-2026-54999 | 8.8 | 33.8 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-47423 | 8.2 | 33.8 | cure53 | DOMPurify | CWE-79 | DOMPurify XSS via `selectedcontent` re-clone |
| CVE-2026-50377 | 7.8 | 33.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-47999 | 4.8 | 33.7 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48327 | 9.0 | 33.7 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-50420 | 5.5 | 33.6 | Microsoft | Windows 11 Version 24H2 | CWE-125 | HTTP.sys Information Disclosure Vulnerability |
| CVE-2026-58547 | 7.8 | 33.5 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vul… |
| CVE-2026-48808 | 6.0 | 33.6 | twigphp | Twig | CWE-693 | Twig: Sandbox property allowlist bypass via the `column` filter under `Source… |
| CVE-2026-10577 | 10.0 | 33.4 | Rockwell Auotmation | 1715 EtherNet/IP Communications Module | CWE-306 | Rockwell Automation 1715 Redundant IO – Access Control Vulnerability |
| CVE-2026-10672 | 9.1 | 33.4 | zephyrproject | zephyr | CWE-125 | Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Pac… |
| CVE-2026-49458 | 6.1 | 33.3 | cure53 | DOMPurify | CWE-79 | DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact … |
| CVE-2026-40422 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-49801 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows SMB Information Disclosure Vulnerability |
| CVE-2026-50300 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-50341 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-50381 | 5.5 | 33.3 | Microsoft | Windows 10 Version 21H2 | CWE-843 | Composite Image File System driver (cimfs.sys) Information Disclosure Vulnera… |
| CVE-2026-50383 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1809 | CWE-126 | Windows Print Spooler Information Disclosure Vulnerability |
| CVE-2026-50401 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
| CVE-2026-50437 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-50455 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-908 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
| CVE-2026-50690 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows SMB Information Disclosure Vulnerability |
| CVE-2026-54997 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows SMB Information Disclosure Vulnerability |
| CVE-2026-58614 | 5.5 | 33.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Kernel Security Feature Bypass Vulnerability |
| CVE-2026-60118 | 6.9 | 33.1 | HiEventsDev | Hi.Events | CWE-862 | Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint |
| CVE-2026-47732 | 7.1 | 33.0 | twigphp | Twig | CWE-863 | Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string co… |
| CVE-2026-12478 | 4.8 | 32.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup webs… |
| CVE-2026-48334 | 9.3 | 32.9 | Adobe | Illustrator Desktop 2026 | CWE-20 | Illustrator | Improper Input Validation (CWE-20) |
| CVE-2026-50657 | 5.5 | 32.9 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-359 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
| CVE-2026-15620 | 2.1 | 32.6 | mosaxiv | clawlet | CWE-918 | mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery |
| CVE-2026-15668 | 2.1 | 32.6 | louisho5 | picobot | CWE-918 | louisho5 picobot web Tool web.go WebTool.Execute server-side request forgery |
| CVE-2026-47995 | 8.1 | 32.5 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-15750 | 2.1 | 32.5 | mastergo-design | mastergo-magic-mcp | CWE-918 | mastergo-design mastergo-magic-mcp mcp__getComponentLink get-component-link.t… |
| CVE-2026-59835 | 8.6 | 32.4 | Fortinet | FortiSandbox | CWE-668 | A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox… |
| CVE-2026-50697 | 7.8 | 32.3 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-50684 | 4.8 | 32.4 | Microsoft | Windows 10 Version 1607 | CWE-79 | Active Directory Federation Server Spoofing Vulnerability |
| CVE-2026-46639 | 7.1 | 32.3 | twigphp | Twig | CWE-693 | Twig: Sandbox property and method bypass via object-destructuring assignment |
| CVE-2026-59204 | 8.7 | 32.2 | python-pillow | Pillow | CWE-770 | Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used… |
| CVE-2026-56189 | 8.4 | 32.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-13699 | 6.5 | 32.1 | Eclipse Foundation | Eclipse KUKSA - Databroker | CWE-20 | Databroker 0.6.1 PublishValue missing data_point panic |
| CVE-2026-15643 | 9.2 | 31.8 | AWS | awslabs.healthlake-mcp-server | CWE-918 | AWS HealthLake MCP Server SSRF via Pagination URL |
| CVE-2026-24233 | 8.4 | 31.8 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpi… |
| CVE-2026-45070 | 6.3 | 31.8 | symfony | symfony | CWE-93 | Symfony: Email Header Injection via Non-Token Characters in Mime Parameter Names |
| CVE-2026-48263 | 5.4 | 31.8 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48355 | 5.4 | 31.8 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48371 | 5.4 | 31.8 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-15043 | 9.8 | 31.5 | HMBRAND | DBI::SQL::Nano | CWE-480 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and … |
| CVE-2026-60082 | 9.1 | 31.5 | HMBRAND | DBI | CWE-125 | DBI versions before 1.651 for Perl do not enforce statement handle consistenc… |
| CVE-2026-59199 | 7.5 | 31.3 | python-pillow | Pillow | CWE-787 | Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed … |
| CVE-2026-59200 | 7.5 | 31.3 | python-pillow | Pillow | CWE-400 | Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() |
| CVE-2026-59205 | 7.5 | 31.3 | python-pillow | Pillow | CWE-787 | Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` vi… |
| CVE-2026-23573 | 6.1 | 31.2 | Fortinet | FortiOS | CWE-79 | An Improper Neutralization of Input During Web Page Generation ('Cross-site S… |
| CVE-2025-43892 | 4.3 | 30.9 | Fortinet | FortiOS | CWE-126 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, For… |
| CVE-2026-15718 | 4.3 | 30.8 | Mozilla | Firefox | CWE-763 | Invalid pointer in the JavaScript: WebAssembly component |
| CVE-2026-49791 | 7.8 | 30.7 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulne… |
| CVE-2026-15736 | 8.3 | 30.5 | Snowflake | Snowflake SQLAlchemy | CWE-73 | Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowfla… |
| CVE-2026-58613 | 7.8 | 30.4 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-58478 | 6.3 | 30.3 | Dan-in-CA | SIP | CWE-918 | Sustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL |
| CVE-2026-50475 | 5.5 | 30.3 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-55011 | 7.8 | 30.1 | Microsoft | Microsoft Malware Protection Engine | CWE-191 | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2026-55012 | 7.8 | 30.1 | Microsoft | Microsoft Malware Protection Engine | CWE-190 | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2026-15628 | 2.1 | 30.2 | zhayujie | chatgpt-on-wechat CowAgent | CWE-918 | zhayujie chatgpt-on-wechat CowAgent Vision Tool vision.py Vision._download_to… |
| CVE-2025-62826 | 4.3 | 29.9 | Fortinet | FortiPAM | CWE-113 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response … |
| CVE-2026-59083 | 9.1 | 29.7 | Apache Software Foundation | Apache Tomcat | CWE-177 | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security cont… |
| CVE-2026-50438 | 8.8 | 29.7 | Microsoft | Microsoft PC Manager | CWE-59 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-50454 | 7.8 | 29.7 | Microsoft | Windows 11 Version 24H2 | CWE-23 | Windows User Interface Core Elevation of Privilege Vulnerability |
| CVE-2026-50469 | 7.8 | 29.7 | Microsoft | Windows 10 Version 1809 | CWE-59 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-58636 | 7.8 | 29.7 | Microsoft | Microsoft PC Manager | CWE-59 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-57085 | 3.3 | 29.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Print Spooler Information Disclosure Vulnerability |
| CVE-2026-45063 | 9.1 | 29.3 | symfony | symfony | CWE-290 | Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator |
| CVE-2026-48807 | 7.1 | 29.4 | twigphp | Twig | CWE-693 | Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `r… |
| CVE-2026-48801 | 8.7 | 29.3 | markdown-it | linkify-it | CWE-1333 | linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop |
| CVE-2026-15624 | 2.1 | 29.3 | nextlevelbuilder | GoClaw | CWE-918 | nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDown… |
| CVE-2026-54572 | 8.8 | 29.1 | rclone | rclone | CWE-59 | rclone: Unvalidated symlink target in local `--links` — arbitrary file write … |
| CVE-2026-49853 | 7.7 | 29.2 | tornadoweb | tornado | CWE-200 | Tornado: Authorization header forwarded across cross-origin redirects in Simp… |
| CVE-2026-60081 | 7.5 | 29.2 | HMBRAND | DBI::ProfileData | CWE-770 | DBI::ProfileData versions before 1.651 for Perl do not limit the path index |
| CVE-2026-49459 | 6.1 | 29.2 | cure53 | DOMPurify | CWE-79 | DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, al… |
| CVE-2026-49798 | 9.3 | 29.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-54122 | 8.4 | 29.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-54128 | 8.4 | 29.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DHCP Client Remote Code Execution Vulnerability |
| CVE-2026-14646 | 4.9 | 29.1 | Sonatype | Nexus Repository 3 | CWE-918 | Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect |
| CVE-2026-50498 | 7.8 | 29.0 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg… |
| CVE-2026-50501 | 7.8 | 29.0 | Microsoft | Windows 11 Version 24H2 | CWE-121 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-58530 | 7.8 | 29.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-58542 | 7.8 | 29.0 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Media Remote Code Execution Vulnerability |
| CVE-2026-49981 | 6.0 | 28.8 | twigphp | Twig | CWE-693 | Twig: Sandbox filter, tag and function allow-list bypass when sandbox state c… |
| CVE-2026-44752 | 8.2 | 28.7 | SAP_SE | SAP NetWeaver Application Server Java(Configuration Wizard) | CWE-79 | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server … |
| CVE-2026-50348 | 8.1 | 28.7 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50452 | 8.1 | 28.7 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-49789 | 7.8 | 28.6 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-49790 | 7.8 | 28.6 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg… |
| CVE-2026-50482 | 7.8 | 28.6 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50510 | 7.8 | 28.6 | Microsoft | GitHub Copilot Plugin for JetBrains IDEs | CWE-641 | GitHub Copilot Remote Code Execution Vulnerability |
| CVE-2026-58640 | 7.8 | 28.6 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-48253 | 5.4 | 28.6 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48254 | 5.4 | 28.6 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48255 | 5.4 | 28.6 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48257 | 5.4 | 28.6 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48260 | 5.4 | 28.6 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48261 | 5.4 | 28.6 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48262 | 5.4 | 28.6 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-9341 | 4.3 | 28.0 | kodezen | Academy LMS | CWE-639 | Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Ref… |
| CVE-2026-50520 | 8.4 | 27.8 | Microsoft | Visual Studio Code | CWE-77 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-49167 | 7.8 | 27.6 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50312 | 7.8 | 27.6 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-58545 | 5.5 | 27.6 | Microsoft | Windows 10 Version 1607 | CWE-284 | Windows Kernel Security Feature Bypass Vulnerability |
| CVE-2026-59884 | 7.5 | 27.5 | pyasn1 | pyasn1 | CWE-400 | pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs |
| CVE-2026-47472 | 7.8 | 27.4 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communicati… |
| CVE-2026-58647 | 5.4 | 27.4 | Microsoft | Power BI Report Server | CWE-79 | Microsoft PowerBI Report Server Spoofing Vulnerability |
| CVE-2026-48784 | 5.1 | 27.4 | symfony | symfony | CWE-172 | Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or… |
| CVE-2026-45065 | 2.3 | 27.4 | symfony | symfony | CWE-185 | Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternati… |
| CVE-2026-15678 | 2.0 | 27.4 | code-projects | Online Job Portal | CWE-79 | code-projects Online Job Portal DetailJob.php cross site scripting |
| CVE-2026-50374 | 6.8 | 27.3 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-15766 | 6.5 | 27.2 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a … | |
| CVE-2026-15770 | 6.5 | 27.2 | Chrome | CWE-457 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a re… | |
| CVE-2026-59889 | 6.5 | 27.1 | FasterXML | jackson-databind | CWE-863 | jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties o… |
| CVE-2026-44753 | 3.7 | 27.2 | SAP_SE | SAP HANA Extended Application Services classic model (User Self Service) | CWE-204 | Information Disclosure vulnerability in SAP HANA Extended Application Service… |
| CVE-2026-15773 | 9.6 | 27.1 | Chrome | CWE-416 | Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 al… | |
| CVE-2026-48761 | 5.3 | 27.0 | symfony | symfony | CWE-79 | Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object… |
| CVE-2026-55000 | 6.4 | 26.4 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-15719 | 5.4 | 26.3 | Mozilla | Firefox | — | Site isolation issue in the DOM: Navigation component |
| CVE-2026-50680 | 7.8 | 26.3 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-49165 | 7.1 | 26.2 | Microsoft | Windows 10 Version 1607 | CWE-908 | Microsoft Windows App Store Information Disclosure Vulnerability |
| CVE-2026-48760 | 5.3 | 26.2 | symfony | symfony | CWE-451 | Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded … |
| CVE-2026-49854 | 5.3 | 26.2 | tornadoweb | tornado | CWE-126 | Tornado: Out-of-bounds memory access in C extension |
| CVE-2026-45064 | 2.3 | 26.2 | symfony | symfony | CWE-451 | Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters →… |
| CVE-2026-45066 | 2.3 | 26.2 | symfony | symfony | CWE-184 | Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Pa… |
| CVE-2026-45753 | 2.1 | 26.2 | symfony | symfony | CWE-79 | Symfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/c… |
| CVE-2026-47971 | 7.8 | 26.2 | Adobe | Adobe Media Encoder | CWE-121 | Media Encoder | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-48269 | 7.8 | 26.2 | Adobe | Premiere | CWE-122 | Premiere Pro | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-48339 | 7.8 | 26.2 | Adobe | Adobe Bridge | CWE-122 | Bridge | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-49184 | 7.8 | 26.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-54992 | 7.8 | 26.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability |
| CVE-2026-45363 | 9.1 | 25.9 | jwt | ruby-jwt | CWE-287 | `jwt` (Ruby gem) - empty-key HMAC bypass |
| CVE-2026-59885 | 7.5 | 25.9 | pyasn1 | pyasn1 | CWE-400 | pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing… |
| CVE-2026-59886 | 7.5 | 25.9 | pyasn1 | pyasn1 | CWE-400 | pyasn1: Uncontrolled resource consumption when converting decoded REAL values |
| CVE-2026-11917 | 7.2 | 25.9 | Rockwell Automation | FactoryTalk ThinManager | CWE-22 | ThinManager® - Path Traversal via API |
| CVE-2026-50302 | 6.5 | 25.8 | Microsoft | Windows 10 Version 21H2 | CWE-295 | Windows Cryptographic Services Security Feature Bypass Vulnerability |
| CVE-2026-49978 | 6.3 | 25.8 | cure53 | DOMPurify | CWE-79 | DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <templ… |
| CVE-2026-49795 | 8.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50382 | 8.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-822 | DirectX Graphics Kernel Remote Code Execution Vulnerability |
| CVE-2026-50692 | 8.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-42982 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-1288 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-49166 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Print Configuration Elevation of Privilege Vulnerability |
| CVE-2026-49173 | 7.8 | 25.7 | Microsoft | Windows 11 version 26H1 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-49175 | 7.8 | 25.7 | Microsoft | Windows 10 Version 21H2 | CWE-122 | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-49783 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-358 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-49792 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-49793 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-49800 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-190 | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulne… |
| CVE-2026-50293 | 7.8 | 25.7 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Internal Task Bar Elevation of Privilege Vulnerability |
| CVE-2026-50306 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-50309 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50315 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-476 | Windows Image Acquisition Elevation of Privilege Vulnerability |
| CVE-2026-50318 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50326 | 7.8 | 25.7 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Unified Consent System Elevation of Privilege Vulnerability |
| CVE-2026-50327 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Media Remote Code Execution Vulnerability |
| CVE-2026-50329 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-416 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-50331 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Application Model Core API Elevation of Privilege Vulnerability |
| CVE-2026-50332 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50336 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50337 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-704 | Windows Notification Elevation of Privilege Vulnerability |
| CVE-2026-50353 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50357 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50363 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-50367 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-118 | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-50387 | 7.8 | 25.7 | Microsoft | Microsoft Office 365 for Mac | CWE-121 | Windows GDI Elevation of Privilege Vulnerability |
| CVE-2026-50399 | 7.8 | 25.7 | Microsoft | Windows 10 Version 21H2 | CWE-125 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50400 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-50402 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-681 | NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50407 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50412 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50413 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50417 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50421 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-843 | Windows Connected User Experiences and Telemetry Elevation of Privilege Vulne… |
| CVE-2026-50422 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50425 | 7.8 | 25.7 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Internal System User Profile Elevation of Privilege Vulnerability |
| CVE-2026-50433 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50435 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2026-50436 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50441 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-822 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50466 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50477 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50478 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50479 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-822 | Windows USB Hub Driver Elevation of Privilege Vulnerability |
| CVE-2026-50480 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulne… |
| CVE-2026-50484 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50486 | 7.8 | 25.7 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50489 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50493 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50494 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50499 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2026-50670 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50679 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Search Service Elevation of Privilege Vulnerability |
| CVE-2026-50687 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54109 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-54114 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54115 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
| CVE-2026-54986 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54987 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2026-55004 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows Print Configuration Elevation of Privilege Vulnerability |
| CVE-2026-56175 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-56176 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-56182 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-56643 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-56644 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-56650 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Network File System Elevation of Privilege Vulnerability |
| CVE-2026-57091 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows File History Service Elevation of Privilege Vulnerability |
| CVE-2026-57096 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulne… |
| CVE-2026-57968 | 7.8 | 25.7 | Microsoft | Windows Subsystem for Linux (WSL2) | CWE-126 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58532 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58534 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability |
| CVE-2026-58536 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-58537 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnera… |
| CVE-2026-58538 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Bluetooth Service Elevation of Privilege Vulnerability |
| CVE-2026-58541 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-843 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-58601 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
| CVE-2026-58602 | 7.8 | 25.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-58632 | 7.8 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
| CVE-2026-58633 | 7.8 | 25.7 | Microsoft | Windows 11 version 26H1 | CWE-416 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-58634 | 7.8 | 25.7 | Microsoft | Windows 11 version 26H1 | CWE-416 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-50354 | 7.1 | 25.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-15672 | 2.1 | 25.7 | itsourcecode | Electronic Judging System | CWE-74 | itsourcecode Electronic Judging System add_judges.php sql injection |
| CVE-2026-12588 | 6.0 | 25.5 | Trellix | Trellix HX Console | CWE-409 | An attacker with access to an HX 10.0.0 and previous versions, may send speci… |
| CVE-2026-7640 | 6.4 | 25.5 | aguilatechnologies | WP Customer Area | CWE-79 | WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Sc… |
| CVE-2026-46635 | 5.3 | 25.4 | twigphp | Twig | CWE-863 | Twig: Sandbox property allowlist bypass via the `column` filter (array_column… |
| CVE-2026-36214 | 6.4 | 25.3 | osTicket | osTicket | CWE-79 | osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vul… |
| CVE-2026-8384 | 5.3 | 25.4 | Eclipse Foundation | Eclipse Jetty | CWE-647 | In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt resu… |
| CVE-2026-62422 | 9.8 | 25.2 | JetBrains | YouTrack | CWE-306 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025… |
| CVE-2026-48350 | 8.6 | 25.1 | Adobe | Adobe Animate 2023 | CWE-22 | Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path … |
| CVE-2026-59198 | 7.5 | 24.7 | python-pillow | Pillow | CWE-125 | Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into … |
| CVE-2026-62655 | 5.7 | 24.7 | NETGEAR | RBR860 | CWE-121 | A DoS vulnerability due to stack overflow exists in certain NETGEAR Orbi models |
| CVE-2026-15769 | 8.3 | 24.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in Linux Toolkit Theming in Google… | |
| CVE-2026-24220 | 6.4 | 24.5 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen s… |
| CVE-2026-50488 | 7.8 | 24.5 | Microsoft | Windows 11 Version 24H2 | CWE-77 | Clipboard User Service Elevation of Privilege Vulnerability |
| CVE-2026-58635 | 7.8 | 24.5 | Microsoft | Windows 10 Version 1809 | CWE-77 | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-55651 | 7.1 | 23.9 | alextselegidis | easyappointments | CWE-200 | Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Expo… |
| CVE-2026-15183 | 9.2 | 23.5 | Snowflake | Snowflake Spark Connector | CWE-89 | Input Validation Vulnerabilities in Snowflake Spark Connector |
| CVE-2026-48342 | 7.8 | 23.6 | Adobe | Adobe Bridge | CWE-190 | Bridge | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-47471 | 7.5 | 23.6 | NVIDIA | TensorRT-LLM | CWE-122 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deser… |
| CVE-2026-59840 | 4.3 | 23.5 | Fortinet | FortiOS | CWE-126 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, For… |
| CVE-2026-54433 | 10.0 | 23.3 | Roundcube | Webmail | CWE-79 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cr… |
| CVE-2026-58475 | 5.3 | 23.2 | Dan-in-CA | SIP | CWE-79 | Sustainable Irrigation Platform 5.2.16 Stored XSS via Program Name |
| CVE-2026-50310 | 4.7 | 23.2 | Microsoft | Windows 10 Version 1809 | CWE-190 | Windows Human Interface Device Information Disclosure Vulnerability |
| CVE-2026-52840 | 2.7 | 23.2 | alextselegidis | easyappointments | CWE-918 | Easy!Appointments has server-side request forgery in CalDAV connection test t… |
| CVE-2026-6790 | 5.3 | 23.2 | Eclipse Foundation | Eclipse Jetty | CWE-20 | In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict … |
| CVE-2026-59888 | 6.5 | 23.0 | FasterXML | jackson-databind | CWE-915 | jackson-databind: @JsonIgnore on a Record property is bypassed with a Propert… |
| CVE-2026-44769 | 5.5 | 22.9 | SAP_SE | SAP S/4HANA Project Management (PPM-PRO) | CWE-89 | SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO) |
| CVE-2026-50451 | 7.8 | 22.8 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulne… |
| CVE-2026-52100 | 7.5 | 22.8 | n/a | n/a | CWE-352 | Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 th… |
| CVE-2026-54127 | 8.4 | 22.5 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-46637 | 5.1 | 22.6 | twigphp | Twig | CWE-79 | Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => [… |
| CVE-2026-45072 | 2.0 | 22.6 | symfony | symfony | CWE-79 | Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped N… |
| CVE-2026-15772 | 8.3 | 22.4 | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 all… | |
| CVE-2026-15774 | 8.3 | 22.4 | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a rem… | |
| CVE-2026-15764 | 7.5 | 22.4 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 all… | |
| CVE-2026-15765 | 7.5 | 22.4 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a re… | |
| CVE-2026-15777 | 7.5 | 22.4 | Chrome | CWE-416 | Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowe… | |
| CVE-2026-50459 | 7.8 | 22.4 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50295 | 5.5 | 22.2 | Microsoft | Windows 11 Version 24H2 | CWE-269 | Windows Zero Trust DNS Security Feature Bypass Vulnerability |
| CVE-2026-50495 | 5.5 | 22.2 | Microsoft | Windows 10 Version 1809 | CWE-284 | DNS Client Tampering Vulnerability |
| CVE-2026-15771 | 5.3 | 22.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome on Windo… | |
| CVE-2026-62658 | 4.7 | 22.3 | NETGEAR | RAX43 | CWE-20 | Post-authentication Command Injection Vulnerability in certain Nighthawk RAX … |
| CVE-2026-49171 | 7.8 | 22.0 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Speech Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50342 | 8.8 | 21.8 | Microsoft | Windows 11 Version 24H2 | CWE-284 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-48581 | 7.8 | 21.8 | Microsoft | Microsoft Surface Go | CWE-1220 | Surface Broker SDMA Elevation of Privilege Vulnerability |
| CVE-2026-49170 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1809 | CWE-1220 | Windows StateRepository API Server file Elevation of Privilege Vulnerability |
| CVE-2026-50311 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-284 | Windows Server Elevation of Privilege Vulnerability |
| CVE-2026-50333 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Spaceport.sys Elevation of Privilege Vulnerability |
| CVE-2026-50335 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1809 | CWE-284 | Windows Operating Systems Elevation of Privilege Vulnerability |
| CVE-2026-50343 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1809 | CWE-269 | Microsoft Install Service Elevation of Privilege Vulnerability |
| CVE-2026-50344 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-285 | Windows OLE Elevation of Privilege Vulnerability |
| CVE-2026-50346 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-285 | Netlogon RPC Elevation of Privilege Vulnerability |
| CVE-2026-50351 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-284 | Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability |
| CVE-2026-50373 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1809 | CWE-284 | Windows Search Service Elevation of Privilege Vulnerability |
| CVE-2026-50391 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-269 | Windows Group Policy Elevation of Privilege Vulnerability |
| CVE-2026-50405 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-1220 | Windows Filtering Platform Elevation of Privilege Vulnerability |
| CVE-2026-50423 | 7.8 | 21.8 | Microsoft | Windows 10 Version 21H2 | CWE-284 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-55001 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-295 | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2026-55006 | 7.8 | 21.8 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-1220 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-55014 | 7.8 | 21.8 | Microsoft | Windows Remote Help | CWE-284 | Windows Remote Help Defense Elevation of Privilege Vulnerability |
| CVE-2026-57088 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1809 | CWE-284 | Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability |
| CVE-2026-57107 | 7.8 | 21.8 | Microsoft | Windows Admin Center | CWE-287 | Windows Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-58540 | 7.8 | 21.8 | Microsoft | Windows 10 Version 1607 | CWE-285 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-58631 | 7.8 | 21.8 | Microsoft | Windows Admin Center | CWE-285 | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-50465 | 7.1 | 21.8 | Microsoft | Windows 11 Version 24H2 | CWE-284 | Windows DNS Client Tampering Vulnerability |
| CVE-2026-60119 | 5.1 | 21.8 | HiEventsDev | Hi.Events | CWE-862 | Hi.Events < 1.11.0 XSS via Event Title JSON.stringify Injection |
| CVE-2026-15778 | 6.5 | 21.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in Navigation in Google Chrome pri… | |
| CVE-2026-12606 | 6.3 | 21.7 | Eclipse Foundation | Eclipse GlassFish | CWE-444 | Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer s… |
| CVE-2026-50650 | 7.8 | 21.6 | Microsoft | .NET 8.0 | CWE-94 | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-48290 | 8.2 | 21.5 | Adobe | Content Credentials Rust SDK | CWE-918 | CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-12511 | 8.1 | 21.5 | Unknown | AI Engine | — | AI Engine < 3.5.5 - Editor+ Arbitrary File Write via Path Traversal |
| CVE-2026-50375 | 7.8 | 21.4 | Microsoft | Windows 10 Version 1809 | CWE-122 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-46628 | 5.1 | 21.5 | twigphp | Twig | CWE-116 | Twig: The `spaceless` filter implicitly marks its output as safe |
| CVE-2026-47730 | 5.1 | 21.5 | twigphp | Twig | CWE-79 | Twig: XSS in profiler HtmlDumper via unescaped template and profile names |
| CVE-2026-48275 | 8.6 | 21.3 | Adobe | Illustrator Desktop 2026 | CWE-426 | Illustrator | Untrusted Search Path (CWE-426) |
| CVE-2026-48340 | 7.8 | 21.3 | Adobe | Adobe Bridge | CWE-822 | Bridge | Untrusted Pointer Dereference (CWE-822) |
| CVE-2026-11567 | 5.9 | 21.3 | Unknown | SureForms | — | SureForms < 2.11.1 - Unauthenticated Payment Amount Bypass |
| CVE-2026-15641 | 7.1 | 21.2 | Devolutions | Server | CWE-863 | Improper authorization in the access request status endpoint in Devolutions S… |
| CVE-2026-48354 | 6.2 | 20.8 | Adobe | Content Credentials Rust SDK | CWE-190 | CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-44759 | 6.1 | 20.5 | SAP_SE | SAP NetWeaver Enterprise Portal | CWE-79 | Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal |
| CVE-2026-44767 | 6.1 | 20.5 | SAP_SE | @ui5/webcomponents-base | CWE-79 | Allowlist Bypass in setThemeRoot() Enables Cross-Origin CSS Injection |
| CVE-2026-48312 | 6.8 | 20.1 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-44770 | 4.3 | 20.0 | SAP_SE | SAP S/4 HANA (Create Single Payment) | CWE-862 | Missing Authorization check in SAP S/4 HANA (Create Single Payment) |
| CVE-2026-44771 | 4.3 | 20.0 | SAP_SE | SAP S/4HANA (Draft operation) | CWE-862 | Missing Authorization check in SAP S/4HANA (Draft operation) |
| CVE-2026-12988 | 6.4 | 19.9 | Unknown | WP 2FA | CWE-862 | WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding |
| CVE-2026-50307 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-50358 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50359 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Microsoft XML Core Services Elevation of Privilege Vulnerability |
| CVE-2026-50390 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-843 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50393 | 7.8 | 19.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-50396 | 7.8 | 19.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-50406 | 7.8 | 19.8 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Backup Engine Elevation of Privilege Vulnerability |
| CVE-2026-50476 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Network Connections Service Elevation of Privilege Vulnerability |
| CVE-2026-50490 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-50491 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability |
| CVE-2026-50674 | 7.8 | 19.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-50688 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54129 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-54989 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnera… |
| CVE-2026-56187 | 7.8 | 19.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-57093 | 7.8 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-56181 | 8.3 | 19.5 | Microsoft | Windows 11 Version 24H2 | CWE-346 | Windows Network Address Translation (NAT) Spoofing Vulnerability |
| CVE-2026-58476 | 7.0 | 18.8 | Dan-in-CA | SIP | CWE-352 | Sustainable Irrigation Platform 5.2.16 CSRF via Administrative GET Requests |
| CVE-2025-62675 | 4.3 | 18.8 | Fortinet | FortiOS | CWE-113 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response … |
| CVE-2026-49174 | 6.1 | 18.6 | Microsoft | Windows 10 Version 1809 | CWE-306 | DNS Client Tampering Vulnerability |
| CVE-2026-34346 | 5.5 | 18.6 | Microsoft | Windows 10 Version 1607 | CWE-319 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerab… |
| CVE-2026-50303 | 5.5 | 18.6 | Microsoft | Windows 10 Version 1809 | CWE-1240 | Windows Key Guard Security Feature Bypass Vulnerability |
| CVE-2026-45755 | 6.9 | 18.4 | symfony | symfony | CWE-306 | Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMA… |
| CVE-2026-47212 | 6.9 | 18.4 | symfony | symfony | CWE-306 | Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature… |
| CVE-2026-48302 | 6.2 | 18.3 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-47737 | 7.5 | 18.0 | puma | puma | CWE-290 | Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connec… |
| CVE-2026-50418 | 6.1 | 18.0 | Microsoft | Windows 11 Version 24H2 | CWE-284 | Windows System Secure Feature Bypass Vulnerability |
| CVE-2026-54429 | 6.0 | 18.0 | Siemens | SIMATIC S7-PLCSIM Advanced | CWE-770 | A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versio… |
| CVE-2026-48571 | 7.0 | 17.8 | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-49162 | 7.0 | 17.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50296 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50323 | 7.0 | 17.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50372 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability |
| CVE-2026-50392 | 7.0 | 17.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-50397 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50410 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50449 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-56173 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows WebView Elevation of Privilege Vulnerability |
| CVE-2026-56183 | 7.0 | 17.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-58544 | 7.0 | 17.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Management Services Elevation of Privilege Vulnerability |
| CVE-2026-58619 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-58629 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58637 | 7.0 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Client-Side Caching Elevation of Privilege Vulnerability |
| CVE-2026-48758 | 5.4 | 17.9 | sigstore | sigstore-js | CWE-347 | sigstore-js: DSSE payloadType type-binding failure |
| CVE-2026-48353 | 5.5 | 17.7 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-48346 | 7.9 | 17.6 | Adobe | Adobe Animate 2023 | CWE-426 | Animate | Untrusted Search Path (CWE-426) |
| CVE-2026-47969 | 5.5 | 17.4 | Adobe | Audition | CWE-125 | Audition | Out-of-bounds Read (CWE-125) |
| CVE-2026-47979 | 5.5 | 17.4 | Adobe | Adobe Media Encoder | CWE-125 | Media Encoder | Out-of-bounds Read (CWE-125) |
| CVE-2026-59732 | 5.0 | 17.3 | rclone | rclone | CWE-22 | rclone archive extract allows S3 destination prefix escape via crafted archiv… |
| CVE-2026-48296 | 6.2 | 17.2 | Adobe | Content Credentials Rust SDK | CWE-191 | CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
| CVE-2026-48298 | 6.2 | 17.2 | Adobe | Content Credentials Rust SDK | CWE-191 | CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
| CVE-2026-48357 | 6.2 | 17.2 | Adobe | Content Credentials Rust SDK | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-44768 | 4.1 | 17.2 | SAP_SE | SAP CRM (WebClient UI) | CWE-15 | Security misconfiguration in SAP CRM (WebClient UI) |
| CVE-2026-45069 | 8.8 | 17.1 | symfony | symfony | CWE-345 | Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims |
| CVE-2026-50385 | 8.8 | 16.8 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-47967 | 7.8 | 16.9 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-47968 | 7.8 | 16.9 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-47976 | 7.8 | 16.9 | Adobe | Adobe Media Encoder | CWE-787 | Media Encoder | Out-of-bounds Write (CWE-787) |
| CVE-2026-48270 | 7.8 | 16.9 | Adobe | Premiere | CWE-787 | Premiere Pro | Out-of-bounds Write (CWE-787) |
| CVE-2026-48274 | 7.8 | 16.9 | Adobe | After Effects | CWE-787 | After Effects | Out-of-bounds Write (CWE-787) |
| CVE-2026-48309 | 7.8 | 16.9 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-48311 | 7.8 | 16.9 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-48335 | 7.8 | 16.9 | Adobe | Illustrator Desktop 2026 | CWE-787 | Illustrator | Out-of-bounds Write (CWE-787) |
| CVE-2026-48336 | 7.8 | 16.9 | Adobe | Illustrator Desktop 2026 | CWE-787 | Illustrator | Out-of-bounds Write (CWE-787) |
| CVE-2026-48337 | 7.8 | 16.9 | Adobe | Illustrator Desktop 2026 | CWE-787 | Illustrator | Out-of-bounds Write (CWE-787) |
| CVE-2026-48341 | 7.8 | 16.9 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-48343 | 7.8 | 16.9 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-48365 | 7.8 | 16.9 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-48366 | 7.8 | 16.9 | Adobe | Adobe Media Encoder | CWE-787 | Media Encoder | Out-of-bounds Write (CWE-787) |
| CVE-2026-48367 | 7.8 | 16.9 | Adobe | After Effects | CWE-787 | After Effects | Out-of-bounds Write (CWE-787) |
| CVE-2026-48368 | 7.8 | 16.9 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-48369 | 7.8 | 16.9 | Adobe | Premiere | CWE-787 | Premiere Pro | Out-of-bounds Write (CWE-787) |
| CVE-2026-48370 | 7.8 | 16.9 | Adobe | Adobe Media Encoder | CWE-787 | Media Encoder | Out-of-bounds Write (CWE-787) |
| CVE-2026-50305 | 7.8 | 16.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50361 | 7.8 | 16.8 | Microsoft | Windows 11 Version 24H2 | CWE-415 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50427 | 7.8 | 16.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Content Delivery Manager Elevation of Privilege Vulnerability |
| CVE-2026-50457 | 7.8 | 16.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50458 | 7.8 | 16.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50677 | 7.8 | 16.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50689 | 7.8 | 16.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Clipboard Server Elevation of Privilege Vulnerability |
| CVE-2026-54125 | 7.8 | 16.8 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-62656 | 5.4 | 16.8 | NETGEAR | RAXE450 | CWE-20 | Post-authenticated command injection vulnerability found in certain NETGEAR R… |
| CVE-2026-15747 | 9.1 | 16.7 | SRI | Mojolicious | CWE-204 | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable represent… |
| CVE-2026-15305 | 6.3 | 16.6 | TYPO3 | TYPO3 CMS | CWE-351 | TYPO3 CMS - Unrestricted File Upload in Form Framework |
| CVE-2026-15637 | 7.5 | 16.5 | Devolutions | Server | CWE-639 | Improper authorization in the PAM SSH key and certificate retrieval endpoints… |
| CVE-2026-50130 | 8.8 | 16.4 | pi-hole | pi-hole | CWE-282 | Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/piho… |
| CVE-2026-15757 | 6.3 | 16.2 | NETGEAR | DGND3700v1 | CWE-20 | Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router |
| CVE-2026-59839 | 5.5 | 16.2 | Fortinet | FortiProxy | CWE-22 | A improper limitation of a pathname to a restricted directory ('path traversa… |
| CVE-2026-11563 | 9.6 | 16.0 | Unknown | Word Count and Social Shares | — | Word Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via… |
| CVE-2026-48747 | 6.3 | 15.7 | symfony | symfony | CWE-347 | Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Req… |
| CVE-2026-58543 | 6.3 | 15.3 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Universal Print Management Service Elevation of Privilege Vulnerability |
| CVE-2026-8085 | 7.0 | 15.2 | Rockwell Automation | Arena® Simulation | CWE-787 | Rockwell Automation Arena® - Memory Corruption Vulnerability |
| CVE-2026-52838 | 2.6 | 15.2 | alextselegidis | easyappointments | CWE-79 | Easy!Appointments disable_booking_message rendered as raw HTML on public book… |
| CVE-2026-48308 | 5.9 | 15.1 | Adobe | Premiere | CWE-20 | Premiere Pro | Improper Input Validation (CWE-20) |
| CVE-2026-62659 | 4.3 | 14.8 | NETGEAR | WAX333 | CWE-20 | Authenticated users can make unauthorized changes on NETGEAR WAX333 Access Po… |
| CVE-2026-21840 | 3.1 | 14.9 | HCLSoftware | HCL BigFix Platform | CWE-208 | HCL BigFix Platform is affected by a user enumeration vulnerability |
| CVE-2026-12482 | 6.5 | 14.6 | keras-team | keras-team/keras | CWE-22 | Path Traversal via Symlink Name Validation Bypass in keras-team/keras |
| CVE-2026-15768 | 6.5 | 14.6 | Chrome | CWE-346 | Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 1… | |
| CVE-2026-15775 | 6.5 | 14.6 | Chrome | CWE-346 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 a… | |
| CVE-2026-7494 | 5.3 | 14.4 | Sonatype | Nexus Repository | CWE-918 | Nexus Repository - SSRF in SSL Certificate Retrieval |
| CVE-2026-49805 | 7.0 | 14.3 | Microsoft | Windows 10 Version 1607 | CWE-284 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50297 | 7.0 | 14.3 | Microsoft | Windows 10 Version 1607 | CWE-284 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50325 | 7.0 | 14.3 | Microsoft | Windows 10 Version 1607 | CWE-284 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-48349 | 8.1 | 14.2 | Adobe | Adobe Animate 2023 | CWE-863 | Animate | Incorrect Authorization (CWE-863) |
| CVE-2026-59841 | 7.5 | 14.2 | Fortinet | FortiSIEMWindowsAgent | CWE-923 | A improper restriction of communication channel to intended endpoints vulnera… |
| CVE-2026-58638 | 5.5 | 14.2 | Microsoft | Windows 10 Version 1809 | CWE-325 | Windows Boot Loader Security Feature Bypass Vulnerability |
| CVE-2026-56178 | 7.0 | 14.0 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-367 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
| CVE-2026-9653 | 8.7 | 13.8 | Rockwell Automation | 1756-EN2, 1756-EN3 | CWE-354 | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID |
| CVE-2026-8312 | 7.0 | 13.5 | Rockwell Auotmation | Arena® Simulation | CWE-787 | Rockwell Automation Arena® - Memory Corruption Vulnerability |
| CVE-2026-8313 | 7.0 | 13.5 | Rockwell Automation | Arena® Simulation | CWE-787 | Rockwell Automation Arena® - Memory Corruption Vulnerability |
| CVE-2026-8314 | 7.0 | 13.5 | Rockwell Automation | Arena® Simulation | CWE-787 | Rockwell Automation Arena® - Memory Corruption Vulnerability |
| CVE-2026-52839 | 3.3 | 13.5 | alextselegidis | easyappointments | CWE-639 | Easy!Appointments appointments/store and appointments/update allow cross-prov… |
| CVE-2026-50526 | 5.5 | 13.3 | Microsoft | .NET 10.0 | CWE-59 | .NET Tampering Vulnerability |
| CVE-2026-48272 | 7.8 | 13.2 | Adobe | Creative Cloud Desktop | CWE-427 | Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-44760 | 4.7 | 13.3 | SAP_SE | SAP NetWeaver Application Server ABAP (applications based on Business Server Pages) | CWE-79 | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server … |
| CVE-2025-15665 | 5.4 | 13.1 | Unknown | Ultimate Before After Image Slider & Gallery | — | BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field |
| CVE-2026-24268 | 7.8 | 13.0 | NVIDIA | TensorRT | CWE-122 | NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap… |
| CVE-2026-48287 | 7.4 | 12.9 | Adobe | Content Credentials Rust SDK | CWE-426 | CAI Content Credentials | Untrusted Search Path (CWE-426) |
| CVE-2026-55144 | 7.1 | 13.0 | Microsoft | Windows 11 Version 24H2 | CWE-325 | Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability |
| CVE-2026-59836 | 9.8 | 12.4 | Fortinet | FortiClientEMS | CWE-295 | A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.… |
| CVE-2026-48348 | 7.7 | 12.1 | Adobe | Adobe Animate 2023 | CWE-863 | Animate | Incorrect Authorization (CWE-863) |
| CVE-2026-57973 | 4.7 | 11.9 | Microsoft | Windows Subsystem for Linux (WSL2) | CWE-367 | Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability |
| CVE-2026-47304 | 9.8 | 11.8 | Microsoft | .NET 10.0 | CWE-347 | .NET Security Feature Bypass Vulnerability |
| CVE-2026-9636 | 8.2 | 11.9 | Rockwell Automation | ControlLogix® 5580, CompactLogix® 5380, GuardLogix® 5580, Compact GuardLogix® 5380, 1756-EN4TR | CWE-299 | Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communic… |
| CVE-2026-50673 | 7.8 | 11.5 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58526 | 7.8 | 11.5 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-50317 | 7.0 | 11.5 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Operating Systems Elevation of Privilege Vulnerability |
| CVE-2026-50321 | 7.0 | 11.5 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows USB Driver Elevation of Privilege Vulnerability |
| CVE-2026-50378 | 7.0 | 11.5 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Key Guard Elevation of Privilege Vulnerability |
| CVE-2026-50440 | 7.0 | 11.5 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Audio Service Elevation of Privilege Vulnerability |
| CVE-2026-50667 | 7.0 | 11.5 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-50676 | 7.0 | 11.5 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-54107 | 7.0 | 11.5 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54991 | 7.0 | 11.5 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-58527 | 7.0 | 11.5 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-0487 | 8.4 | 11.0 | SAP_SE | SAProuter on Microsoft Windows | CWE-427 | DLL Hijacking vulnerability in SAProuter on Microsoft Windows |
| CVE-2026-15058 | 3.1 | 11.0 | Devolutions | Server | CWE-639 | Improper authorization in the secure messages deletion endpoint in Devolution… |
| CVE-2026-24238 | 7.8 | 10.8 | NVIDIA | TensorRT | CWE-129 | NVIDIA TensorRT for contains a vulnerability where an attacker might cause an… |
| CVE-2026-24272 | 7.8 | 10.8 | NVIDIA | TensorRT | CWE-122 | NVIDIA TensorRT contains a vulnerability where an attacker might cause an ove… |
| CVE-2026-54432 | 4.7 | 10.6 | Roundcube | Webmail | CWE-79 | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Si… |
| CVE-2026-52841 | 3.1 | 10.6 | alextselegidis | easyappointments | CWE-639 | Easy!Appointments: Authorization bypass in Google OAuth provider binding lets… |
| CVE-2026-44800 | 7.8 | 10.0 | Microsoft | Windows 11 version 23H2 | CWE-362 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-49808 | 7.8 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58628 | 7.8 | 10.0 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Wireless Network Manager Elevation of Privilege Vulnerability |
| CVE-2026-48572 | 7.0 | 10.0 | Microsoft | Windows 11 version 23H2 | CWE-362 | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-49183 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Clipboard Server Elevation of Privilege Vulnerability |
| CVE-2026-49784 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1607 | CWE-362 | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-49802 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-49803 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows AppX Deployment Extensions Elevation of Privilege Vulnerability |
| CVE-2026-49806 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-50322 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50345 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50356 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1607 | CWE-362 | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-50371 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerab… |
| CVE-2026-50384 | 7.0 | 10.1 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Clip Service Elevation of Privilege Vulnerability |
| CVE-2026-50403 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50404 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50450 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Network Connections Service Elevation of Privilege Vulnerability |
| CVE-2026-50503 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50658 | 7.0 | 10.0 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-367 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
| CVE-2026-50669 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Telephony Server Elevation of Privilege Vulnerability |
| CVE-2026-50672 | 7.0 | 10.1 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-54111 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Universal Print Management Service Elevation of Privilege Vulnerability |
| CVE-2026-54112 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54996 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-42447 | 5.0 | 9.6 | skylot | jadx | CWE-79 | jadx: HTML Injection in Summary panel |
| CVE-2026-42049 | 8.4 | 9.5 | skylot | jadx | CWE-94 | jadx: RCE Via Groovy Code Injection in Gradle Export |
| CVE-2026-15075 | 8.2 | 9.4 | Eclipse Foundation | Eclipse Vert.x | CWE-200 | In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 … |
| CVE-2026-15076 | 8.2 | 9.4 | Eclipse Foundation | Eclipse Vert.x | CWE-346 | In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), t… |
| CVE-2026-9561 | 8.8 | 8.9 | Eclipse Foundation | Eclipse Kura | CWE-345 | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-Fo… |
| CVE-2026-48815 | 7.5 | 8.6 | sigstore | sigstore-js | CWE-347 | sigstore-js: `certificateOIDs` verification constraints are silently dropped … |
| CVE-2026-24259 | 6.4 | 7.7 | NVIDIA | TensorRT-LLM | CWE-306 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker coul… |
| CVE-2026-14852 | 5.2 | 7.5 | Checkmk GmbH | Checkmk | CWE-78 | mk_sap_hana: Privilege escalation via crafted sapstartsrv process name |
| CVE-2026-10669 | 7.8 | 7.2 | zephyrproject | zephyr | CWE-190 | Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypas… |
| CVE-2026-15621 | 4.8 | 6.7 | mosaxiv | clawlet | CWE-59 | mosaxiv clawlet File Tools fs_ops.go edit_file link following |
| CVE-2026-15749 | 1.9 | 6.7 | mastergo-design | mastergo-magic-mcp | CWE-22 | mastergo-design mastergo-magic-mcp mcp__C2d get-c2d.ts execute path traversal |
| CVE-2026-15751 | 1.9 | 6.7 | mastergo-design | mastergo-magic-mcp | CWE-22 | mastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workf… |
| CVE-2026-48344 | 7.8 | 6.6 | Adobe | Creative Cloud Desktop | CWE-367 | GoCart | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) |
| CVE-2026-59674 | 7.1 | 6.4 | SUSE | openSUSE Tumbleweed | CWE-61 | LPE from suricata user to root due to chown in %post in suricata packaging |
| CVE-2026-53566 | 6.8 | 6.1 | Citrix | Citrix Secure Access Client for Windows | CWE-125 | Out-of-bounds memory read |
| CVE-2025-40945 | 8.5 | 5.8 | Siemens | COMOS V10.4.5 | CWE-426 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.… |
| CVE-2026-15392 | 7.7 | 5.6 | HMBRAND | DBD::File | CWE-22 | DBD::File versions before 1.651 for Perl do not ensure the table file is not … |
| CVE-2026-24229 | 7.3 | 5.6 | NVIDIA | TensorRT-LLM | CWE-306 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated o… |
| CVE-2026-54684 | 7.0 | 5.6 | skylot | jadx | CWE-22 | jadx: XAPK archive entries with absolute paths can plant drop-in plugins and … |
| CVE-2026-24271 | 6.2 | 5.4 | NVIDIA | TensorRT-LLM | CWE-770 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inferen… |
| CVE-2026-47470 | 6.2 | 5.4 | NVIDIA | TensorRT-LLM | CWE-20 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC ser… |
| CVE-2026-47475 | 6.2 | 5.4 | NVIDIA | TensorRT-LLM | CWE-617 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inferen… |
| CVE-2026-10671 | 7.1 | 5.3 | zephyrproject | zephyr | CWE-1188 | User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queu… |
| CVE-2026-48816 | 6.5 | 5.1 | sigstore | sigstore-js | CWE-345 | sigstore-js: Insufficient Verification of Data Authenticity |
| CVE-2026-47473 | 7.4 | 5.0 | NVIDIA | TensorRT-LLM | CWE-123 | NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a … |
| CVE-2026-24226 | 6.3 | 4.9 | NVIDIA | TensorRT-LLM | CWE-829 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker coul… |
| CVE-2026-15642 | 3.3 | 4.7 | Devolutions | Server | CWE-200 | Insertion of sensitive information into a file in the Recovery Kit response f… |
| CVE-2026-53565 | 8.5 | 4.6 | Citrix | Secure Access Client for Windows | CWE-269 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privil… |
| CVE-2026-24234 | 6.8 | 4.5 | NVIDIA | TensorRT-LLM | CWE-918 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal medi… |
| CVE-2026-10670 | 5.5 | 4.5 | zephyrproject | zephyr | CWE-476 | User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy… |
| CVE-2026-9127 | 7.3 | 4.4 | Rockwell Automation | Studio 5000 Logix Designer | CWE-863 | Studio 5000 Logix Designer® – Multiple Vulnerabilities |
| CVE-2026-62657 | 4.9 | 4.4 | NETGEAR | MR70 | CWE-599 | Certificate validation vulnerability in NETGEAR Gaming Router and certain Nig… |
| CVE-2026-6851 | 7.0 | 4.3 | Bitdefender | Total Security | CWE-59 | Improper link resolution before file access in Bitdefender Total Security via… |
| CVE-2026-0515 | 6.2 | 4.4 | BlackBerry Ltd | QNX Software Development Platform | CWE-233 | Insufficient parameter validation in the QNX Neutrino kernel impacts versions… |