A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
Edition of July 14, 2026, continued — page 3 of 3. Back to page 1 · page 2
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-10670 | 5.5 | 1.2 | zephyrproject | zephyr | CWE-476 | User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy… |
| CVE-2026-62657 | 4.9 | 1.2 | NETGEAR | MR70 | CWE-599 | Certificate validation vulnerability in NETGEAR Gaming Router and certain Nig… |
| CVE-2026-48344 | 7.8 | 1.2 | Adobe | Creative Cloud Desktop | CWE-367 | GoCart | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) |
| CVE-2026-9128 | 7.3 | 0.8 | Rockwell Automation | Studio 5000 Logix Designer | CWE-428 | Studio 5000 Logix Designer® – Multiple Vulnerabilities |
| CVE-2026-5040 | 7.1 | 0.6 | TP-Link Systems Inc. | Deco M5 Deco M5 V1 | CWE-916 | Weak Password Hashing Mechanism in TP-Link Deco M5 |
| CVE-2026-4018 | 6.4 | 0.6 | BlackBerry Ltd | QNX Software Development Platform | CWE-367 | TOCTOU race condition in the QNX Neutrino kernel impacts versions of the QNX … |
| CVE-2025-8412 | 2.0 | 0.5 | SUSE | Virtual Machine Driver Pack | CWE-120 | VMDP: Potential buffer overflow in the RtlQueryRegistryValues function |