| CVE-2026-64901 | 8.8 | 78.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-58231 | 10.0 | 75.6 | SAP_SE | SAP Commerce Cloud (Data Hub Adapter) | CWE-94 | Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) |
| CVE-2026-59132 | 7.5 | 75.2 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-59124 | 9.8 | 75.2 | Microsoft | Microsoft HPC Pack 2019 | CWE-502 | Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnera… |
| CVE-2026-61929 | 7.0 | 75.1 | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-65788 | 7.0 | 75.1 | Microsoft | Windows 11 version 23H2 | CWE-416 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-46670 | 9.8 | 74.7 | YesWiki | yeswiki | CWE-89 | YesWiki: Unauthenticated SQL Injection |
| CVE-2026-14863 | 8.7 | 74.7 | FileRun | FileRun | CWE-78 | FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection |
| CVE-2026-12571 | 9.8 | 74.4 | zohocorp | manageengine_ddi_central | CWE-287 | Authentication Bypass Leading to Account Takeover |
| CVE-2026-61348 | 7.0 | 73.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-66805 | 8.8 | 73.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-62766 | 7.0 | 72.7 | Microsoft | Windows 11 Version 24H2 | CWE-415 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-63514 | 8.8 | 72.6 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-73034 | 9.3 | 72.5 | eosphoros-ai | DB-GPT | CWE-22 | DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header |
| CVE-2026-65658 | 8.8 | 70.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65663 | 8.8 | 70.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-63516 | 6.5 | 69.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-62912 | 6.5 | 68.5 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-502 | Microsoft Exchange Server Denial of Service Vulnerability |
| CVE-2026-70321 | 8.8 | 67.8 | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-502 | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-62878 | 9.8 | 67.3 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-48385 | 7.7 | 65.0 | Adobe | ColdFusion 2025 | CWE-78 | ColdFusion | Improper Neutralization of Special Elements used in an OS Comman… |
| CVE-2026-66148 | 6.3 | 65.0 | SonicWall | GMS | CWE-94 | An authenticated command injection vulnerability was identified in GMS Comman… |
| CVE-2026-54113 | 7.5 | 63.8 | Microsoft | Windows 10 Version 1607 | CWE-770 | Remote Procedure Call Denial of Service Vulnerability |
| CVE-2026-62898 | 7.5 | 63.5 | Microsoft | .NET 10.0 | CWE-416 | Microsoft QUIC Information Disclosure Vulnerability |
| CVE-2026-66808 | 8.8 | 63.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-62901 | 7.5 | 61.9 | Microsoft | .NET 10.0 | CWE-606 | .NET Denial of Service Vulnerability |
| CVE-2026-11739 | 4.9 | 61.8 | NETGEAR | MR60 | CWE-78 | Command injection vulnerability in some NETGEAR Nighthawk devices |
| CVE-2026-59138 | 6.5 | 61.5 | Microsoft | Windows 10 Version 1607 | CWE-476 | Microsoft Remote Registry Service Denial of Service Vulnerability |
| CVE-2026-61345 | 6.5 | 61.5 | Microsoft | Windows 10 Version 1607 | CWE-476 | Microsoft Remote Registry Service Denial of Service Vulnerability |
| CVE-2026-64921 | 8.8 | 60.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-306 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-16053 | 8.5 | 59.9 | Zohocorp | ManageEngine M365 Manager Plus | CWE-23 | Path Traversal |
| CVE-2026-62815 | 9.8 | 59.6 | Microsoft | Windows 11 version 23H2 | CWE-416 | Microsoft QUIC Remote Code Execution Vulnerability |
| CVE-2026-62818 | 8.8 | 59.3 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution V… |
| CVE-2026-62911 | 8.0 | 58.6 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-294 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-62702 | 8.6 | 58.3 | Microsoft | Windows 10 Version 21H2 | CWE-476 | Windows Graphics Kernel Denial of Service Vulnerability |
| CVE-2026-59133 | 8.8 | 58.3 | Microsoft | Windows App Client for Windows Desktop | CWE-250 | Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulner… |
| CVE-2026-47299 | 7.2 | 58.2 | Microsoft | Azure Monitor Agent Linux Extension | CWE-77 | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2026-62784 | 8.8 | 58.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vuln… |
| CVE-2026-62800 | 8.8 | 58.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-65815 | 8.8 | 57.9 | Microsoft | Microsoft Dynamics 365 (on-premises) version 9.1 | CWE-502 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-45618 | 10.0 | 57.7 | harttle | liquidjs | CWE-94 | LiquidJS is Vulnerable to Remote Code Execution |
| CVE-2026-18129 | 8.1 | 56.7 | Ivanti | Endpoint Manager | CWE-295 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoin… |
| CVE-2026-65681 | 7.5 | 56.5 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows iSCSI Target Service Denial of Service Vulnerability |
| CVE-2026-5917 | 9.4 | 56.5 | libgit2 | libgit2 | CWE-78 | libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend |
| CVE-2026-61918 | 7.5 | 56.0 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-47285 | 6.5 | 56.0 | Microsoft | Visual Studio Code | CWE-77 | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-62782 | 7.5 | 56.0 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-62837 | 6.5 | 55.8 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-23 | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-70327 | 6.5 | 55.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70328 | 6.5 | 55.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-50516 | 9.4 | 55.0 | Microsoft | Azure Kubernetes Service | CWE-306 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2026-62785 | 8.8 | 55.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vu… |
| CVE-2026-58639 | 6.5 | 54.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-918 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-49179 | 8.8 | 54.8 | Microsoft | Windows 10 Version 1607 | CWE-77 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-61924 | 7.5 | 54.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-61921 | 6.5 | 54.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-11814 | 4.9 | 54.6 | NETGEAR | BE9300 | CWE-295 | Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers |
| CVE-2026-18125 | 7.5 | 54.5 | Ivanti | Endpoint Manager | CWE-125 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version … |
| CVE-2026-73218 | 7.7 | 54.4 | cursor | cursor | CWE-269 | Cursor: Sandbox escape via launching privileged containers |
| CVE-2026-62869 | 8.8 | 54.3 | Microsoft | Microsoft Entra | CWE-345 | Azure Entra ID Spoofing Vulnerability |
| CVE-2026-57104 | 9.6 | 54.1 | Microsoft | Azure Storage Explorer | CWE-79 | Azure Storage Explorer Elevation of Privilege Vulnerability |
| CVE-2026-58612 | 7.5 | 54.1 | Microsoft | PowerShell 7.4 | CWE-918 | PowerShell Information Disclosure Vulnerability |
| CVE-2026-19091 | 8.1 | 54.0 | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | CWE-22 | GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion… |
| CVE-2026-70337 | 8.8 | 53.7 | Microsoft | PowerShell 7.4 | CWE-23 | Microsoft PowerShell Remote Code Execution Vulnerability |
| CVE-2026-71398 | 10.0 | 53.6 | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-62902 | 6.5 | 53.1 | Microsoft | .NET 8.0 | CWE-829 | .NET Information Disclosure Vulnerability |
| CVE-2026-48411 | 6.5 | 52.9 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-40375 | 6.5 | 52.8 | Microsoft | Microsoft Dynamics 365 Business Central 2024 Release Wave 2 | CWE-862 | Microsoft Dynamics Business Central Information Disclosure Vulnerability |
| CVE-2026-70306 | 9.3 | 52.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-65660 | 6.5 | 51.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-94 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48386 | 7.5 | 51.6 | Adobe | ColdFusion 2025 | CWE-327 | ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327) |
| CVE-2026-13716 | 9.1 | 51.5 | Arcadia Technology, LLC | Crafty Controller | CWE-35 | Path Traversal: '.../...//' in Crafty Controller |
| CVE-2026-62827 | 8.8 | 51.5 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-287 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-69223 | 9.1 | 51.4 | Apache Software Foundation | Apache Allura | CWE-918 | Apache Allura: Server-side request forgery |
| CVE-2026-27302 | 10.0 | 50.8 | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-62792 | 8.1 | 50.7 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-62899 | 5.9 | 50.6 | Microsoft | .NET 10.0 | CWE-444 | .NET Security Feature Bypass Vulnerability |
| CVE-2026-72713 | 8.7 | 50.5 | OpenBMB | XAgent | CWE-22 | XAgent Path Traversal Arbitrary File Read via /workspace/file |
| CVE-2026-70324 | 8.8 | 50.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-918 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-59113 | 8.8 | 50.2 | Microsoft | Visual Studio Code | CWE-862 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-72538 | 8.8 | 50.1 | PrefectHQ | Prefect | CWE-88 | PrefectHQ Prefect - Argument Injection |
| CVE-2026-68819 | 7.5 | 49.8 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Network File System Denial of Service Vulnerability |
| CVE-2026-66301 | 6.5 | 49.8 | Microsoft | Microsoft Dynamics 365 (on-premises) version 9.1 | CWE-200 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2026-62910 | 8.8 | 49.6 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-99 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-44758 | 9.1 | 49.2 | SAP_SE | SAP Manufacturing Integration and Intelligence | CWE-94 | Code Injection vulnerability in Manufacturing Integration and Intelligence |
| CVE-2026-70329 | 8.8 | 49.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-72556 | 8.8 | 49.2 | ZoneMinder | ZoneMinder | CWE-78 | ZoneMinder ZoneMinder - Remote Code Execution |
| CVE-2026-62817 | 8.8 | 49.1 | Microsoft | Windows 10 Version 1809 | CWE-787 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-72551 | 8.8 | 49.1 | Apioo | Fusio | CWE-78 | Apioo Fusio - Remote Code Execution |
| CVE-2026-62790 | 8.8 | 49.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-62823 | 8.8 | 48.9 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-65769 | 7.5 | 48.9 | Microsoft | Microsoft Teams for iOS | CWE-200 | Microsoft Teams iOS Information Disclosure Vulnerability |
| CVE-2026-72748 | 6.9 | 48.9 | WWBN | AVideo | CWE-306 | AVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.php |
| CVE-2026-58115 | 10.0 | 48.5 | Siemens | SIMATIC IoT2050 Advanced | CWE-306 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA0… |
| CVE-2026-62913 | 8.8 | 48.5 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-122 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-65794 | 6.5 | 48.4 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-65813 | 8.8 | 48.4 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-918 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-62822 | 8.8 | 47.6 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-48413 | 8.7 | 47.4 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-62839 | 6.5 | 47.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-522 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-65768 | 9.8 | 47.3 | Microsoft | Microsoft Teams for Android | CWE-22 | Microsoft Teams Remote Code Execution Vulnerability |
| CVE-2026-62824 | 8.8 | 47.3 | Microsoft | Windows 10 Version 1607 | CWE-121 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-61363 | 8.1 | 47.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-59134 | 8.1 | 47.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-13457 | 7.5 | 47.2 | instawp | InstaWP Connect – 1-click WP Staging & Migration | CWE-434 | InstaWP Connect <= 0.1.3.6 - Unauthenticated Cryptographic Key Disclosure |
| CVE-2026-48384 | 4.9 | 46.9 | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-62882 | 4.3 | 46.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-522 | Microsoft Outlook Spoofing Vulnerability |
| CVE-2026-62795 | 8.8 | 46.4 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vu… |
| CVE-2026-70336 | 8.8 | 46.4 | Microsoft | Visual Studio Code | CWE-94 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-70340 | 8.8 | 46.2 | Microsoft | Azure CycleCloud 8.9.1 | CWE-862 | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-65791 | 9.8 | 46.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-54984 | 7.8 | 46.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-70326 | 8.8 | 45.5 | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-918 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-48381 | 9.0 | 45.2 | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-57105 | 5.4 | 45.1 | Microsoft | Microsoft SharePoint Server 2019 | CWE-79 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-62819 | 8.1 | 45.0 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulner… |
| CVE-2026-65806 | 6.5 | 44.9 | Microsoft | Azure CycleCloud 8.9.2 | CWE-862 | Azure CycleCloud Information Disclosure Vulnerability |
| CVE-2026-62750 | 6.5 | 44.8 | Microsoft | Windows 10 Version 1607 | CWE-187 | Windows HTTP Protocol Stack Tampering Vulnerability |
| CVE-2026-34265 | 9.8 | 44.6 | SAP_SE | SAP NetWeaver and ABAP Platform | CWE-787 | Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver … |
| CVE-2026-65679 | 8.1 | 44.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-62889 | 8.1 | 44.0 | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnera… |
| CVE-2026-17061 | 10.0 | 43.9 | Dassault Systèmes | SIMULIA Execution Engine | CWE-502 | Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine f… |
| CVE-2026-66145 | 9.1 | 43.9 | SonicWall | GMS | CWE-94 | An unauthenticated remote code execution vulnerability was identified in GMS … |
| CVE-2026-48440 | 8.1 | 43.8 | Adobe | ColdFusion 2025 | CWE-122 | ColdFusion | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-53415 | 8.3 | 43.5 | Zoom Communications | Zoom Clients | CWE-416 | Zoom Clients - Use After Free |
| CVE-2026-13738 | 9.2 | 43.4 | Commvault | Commvault Cloud | CWE-863 | Improper Authorization Validation |
| CVE-2026-48397 | 8.6 | 43.4 | Adobe | Lightroom Classic | CWE-502 | Lightroom Classic | Deserialization of Untrusted Data (CWE-502) |
| CVE-2026-62900 | 5.9 | 43.3 | Microsoft | .NET 10.0 | CWE-212 | .NET Information Disclosure Vulnerability |
| CVE-2026-63512 | 6.5 | 43.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-863 | Microsoft SharePoint Server Tampering Vulnerability |
| CVE-2026-65789 | 8.1 | 43.2 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62820 | 8.1 | 43.1 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-72781 | 8.7 | 42.9 | craftcms | cms | CWE-693 | Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape |
| CVE-2026-62872 | 8.8 | 42.9 | Microsoft | Microsoft .NET Framework 3.5 | CWE-863 | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-62814 | 6.5 | 42.8 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-47704 | 7.1 | 42.7 | baptisteArno | typebot.io | CWE-639 | TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` l… |
| CVE-2026-48414 | 7.7 | 42.6 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-62787 | 7.5 | 42.4 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-65796 | 8.1 | 42.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-65811 | 8.8 | 42.1 | Microsoft | Power BI Report Server | CWE-20 | Power BI Remote Code Execution Vulnerability |
| CVE-2026-62781 | 8.1 | 41.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | RPC Runtime Library Remote Code Execution Vulnerability |
| CVE-2026-48375 | 6.5 | 41.6 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-21273 | 8.7 | 41.3 | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-48438 | 7.5 | 41.0 | Adobe | Content Credentials Rust SDK | CWE-476 | CAI Content Credentials | NULL Pointer Dereference (CWE-476) |
| CVE-2026-48439 | 7.5 | 41.0 | Adobe | Content Credentials Rust SDK | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-62778 | 8.1 | 40.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2025-31114 | 9.3 | 40.7 | lllyasviel | Fooocus | CWE-95 | Fooocus webui vulnerable to Remote Code Execution |
| CVE-2026-72550 | 9.8 | 40.7 | Friendica | Friendica | CWE-89 | Friendica Friendica - SQL Injection |
| CVE-2026-65675 | 6.5 | 40.4 | Microsoft | Microsoft Visual Studio Code CoPilot Chat Extension | CWE-862 | CoPilot Chat Security Feature Bypass Vulnerability |
| CVE-2026-16230 | 9.8 | 40.3 | Strategy11 | Formidable Digital Signatures | CWE-23 | Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Delet… |
| CVE-2026-48416 | 7.5 | 40.2 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-72602 | 7.5 | 39.9 | AsyncFuncAI | deepwiki-open | CWE-22 | AsyncFuncAI deepwiki-open - Path Traversal |
| CVE-2026-61920 | 6.6 | 39.5 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62915 | 6.5 | 39.5 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-862 | Microsoft Exchange Server Security Feature Bypass Vulnerability |
| CVE-2026-62715 | 6.5 | 39.3 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62718 | 6.5 | 39.3 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62742 | 6.5 | 39.3 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62735 | 7.8 | 39.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-21279 | 8.2 | 38.9 | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-19425 | 9.3 | 38.8 | Win Men Intermational | Travel Agency Management System | CWE-89 | Win Men Intermational|Travel Agency Management System - SQL Injection |
| CVE-2026-72971 | 5.5 | 38.8 | Microsoft | Windows 11 version 26H1 | CWE-59 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerab… |
| CVE-2026-69109 | 8.7 | 38.7 | Siemens | Siemens License Server (SLS) | CWE-35 | A vulnerability has been identified in Siemens License Server (SLS) (All vers… |
| CVE-2026-72770 | 7.1 | 38.7 | n8n-io | n8n | CWE-22 | n8n before 1.123.67 Path Traversal via Git Node Operations |
| CVE-2016-20097 | 8.7 | 38.6 | Weaver Network Co., Ltd. | E-cology 8.0 | CWE-89 | Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad |
| CVE-2026-15565 | 7.5 | 38.5 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-120 | Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint w… |
| CVE-2026-62714 | 6.5 | 38.4 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62716 | 6.5 | 38.4 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62720 | 6.5 | 38.4 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-29035 | 8.3 | 38.3 | civetweb | civetweb | CWE-787 | CivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate Decompre… |
| CVE-2026-70314 | 5.5 | 38.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2022-50997 | 8.7 | 38.1 | Weaver Network Co., Ltd. | E-cology 9.0 | CWE-89 | Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp |
| CVE-2026-70355 | 8.7 | 38.1 | Microsoft | Microsoft SharePoint Server 2019 | CWE-79 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-63530 | 5.5 | 37.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-69320 | 8.8 | 37.6 | Microsoft | Visual Studio Code | CWE-78 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-13737 | 9.2 | 37.6 | Commvault | Commvault Cloud | CWE-863 | Command Restriction Bypass |
| CVE-2026-71331 | 8.1 | 37.5 | Microsoft | Windows 10 Version 1809 | CWE-190 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
| CVE-2026-65767 | 7.6 | 37.5 | Microsoft | Microsoft Teams for Android | CWE-79 | Microsoft Teams for Android Spoofing Vulnerability |
| CVE-2026-72548 | 7.5 | 37.5 | OpenSignLabs | OpenSign | CWE-200 | OpenSignLabs OpenSign - Information Disclosure |
| CVE-2026-72543 | 7.5 | 37.3 | OpenSignLabs | OpenSign | CWE-639 | OpenSignLabs OpenSign - Insecure Direct Object Reference |
| CVE-2026-61350 | 4.6 | 37.1 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-72778 | 8.7 | 37.0 | craftcms | cms | CWE-915 | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
| CVE-2026-68797 | 5.5 | 37.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-64900 | 5.4 | 37.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-69102 | 9.3 | 36.6 | dromara | MaxKey | CWE-798 | MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust |
| CVE-2026-65807 | 8.8 | 36.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-73232 | 7.5 | 36.5 | ffuf | ffuf | CWE-409 | ffuf denial of service (OOM) via HTTP response decompression bomb |
| CVE-2026-47922 | 4.7 | 36.5 | Adobe | Content Credentials Rust SDK | CWE-918 | CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-65657 | 7.8 | 36.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-54123 | 5.5 | 36.3 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-200 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
| CVE-2026-62917 | 4.6 | 36.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-20 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-73032 | 9.4 | 36.3 | papersgpt | papersgpt-for-zotero | CWE-94 | PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() |
| CVE-2026-15567 | 7.5 | 36.1 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-789 | Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on… |
| CVE-2026-15562 | 7.5 | 36.1 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-190 | Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pr… |
| CVE-2026-15560 | 8.1 | 35.9 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-829 | Openjdk-orb: unauthed class loading via iiop in eap |
| CVE-2026-18692 | 7.7 | 35.8 | MongoDB | MongoDB Server | CWE-416 | Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Servi… |
| CVE-2026-72552 | 7.5 | 35.7 | Dub | Dub | CWE-918 | Dub Dub - Server-Side Request Forgery |
| CVE-2026-61352 | 8.1 | 35.4 | Microsoft | Windows 10 Version 1607 | CWE-362 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-39452 | 6.3 | 35.4 | n/a | Intel(R) Transfer Learning Tool | CWE-693 | Protection mechanism failure for some Intel(R) Transfer Learning Tool before … |
| CVE-2026-70348 | 5.5 | 35.2 | Microsoft | Windows 11 Version 24H2 | CWE-59 | Windows Management Services Denial of Service Vulnerability |
| CVE-2026-72535 | 8.6 | 35.1 | Chaskiq | Chaskiq | CWE-306 | Chaskiq Chaskiq - Missing Authentication |
| CVE-2026-72536 | 8.6 | 35.1 | Chaskiq | Chaskiq | CWE-306 | Chaskiq Chaskiq - Missing Authentication |
| CVE-2026-73214 | 8.2 | 35.0 | coturn | coturn | CWE-400 | coturn allocates a full per-peer SSL/session before verifying the DTLS cookie… |
| CVE-2026-73210 | 5.1 | 35.0 | Lookyloo | PlaywrightCapture | CWE-918 | Server-Side Request Forgery via Favicon Retrieval in Lookyloo PlaywrightCapture |
| CVE-2026-68798 | 7.8 | 34.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-70335 | 7.8 | 34.8 | Microsoft | Visual Studio Code | CWE-78 | GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-51584 | 9.8 | 34.6 | n/a | n/a | CWE-287 | An issue in usememos v0.27.1 allows a remote attacker to achieve account take… |
| CVE-2026-72712 | 6.9 | 34.5 | Nmap Project | Nmap | CWE-835 | Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet |
| CVE-2026-18247 | 5.3 | 34.5 | BlackBerry | BlackBerry AtHoc IWS | CWE-79 | DOM-Based Cross-Site Scripting in BlackBerry AtHoc Web Portals |
| CVE-2026-18127 | 7.7 | 34.3 | Ivanti | Endpoint Manager | CWE-73 | External control of a filename in the Core of Ivanti Endpoint Manager before … |
| CVE-2026-14180 | 5.3 | 34.1 | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-444 | Undertow-core: undertow:http request smuggling via oversized chunk-size bit o… |
| CVE-2026-69306 | 8.2 | 34.0 | Microsoft | Visual Studio Code | CWE-636 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-71217 | 7.5 | 34.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-20 | Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabl… |
| CVE-2026-64897 | 5.4 | 34.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64902 | 5.4 | 34.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64916 | 5.4 | 34.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64922 | 5.4 | 34.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-19424 | 8.7 | 33.8 | Inventec Appliances | Chiline Cloud | CWE-639 | Inventec Appliances|Chiline Cloud - Insecure Direct Object Reference |
| CVE-2026-71467 | 7.5 | 33.8 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-287 | Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated v… |
| CVE-2026-62699 | 6.8 | 33.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution… |
| CVE-2026-72920 | 9.8 | 33.7 | seaweedfs | seaweedfs | CWE-306 | SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative co… |
| CVE-2026-73216 | 6.5 | 33.3 | coturn | coturn | CWE-400 | coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity |
| CVE-2026-58641 | 7.8 | 33.2 | Microsoft | .NET 10.0 | CWE-190 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-58651 | 7.8 | 33.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-62886 | 7.8 | 33.3 | Microsoft | .NET 10.0 | CWE-190 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-64914 | 7.8 | 33.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-68812 | 7.8 | 33.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68814 | 7.8 | 33.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68817 | 7.8 | 33.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-72533 | 8.8 | 32.6 | Portainer | Portainer CE | CWE-287 | Portainer Portainer CE - Authentication Bypass |
| CVE-2026-72545 | 7.5 | 32.5 | OpenSignLabs | OpenSign | CWE-639 | OpenSignLabs OpenSign - Insecure Direct Object Reference |
| CVE-2026-62871 | 7.8 | 32.4 | Microsoft | .NET 8.0 | CWE-787 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-48412 | 2.7 | 32.2 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-73211 | 9.8 | 32.1 | Chocobozzz | PeerTube | CWE-89 | PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() |
| CVE-2026-62816 | 8.8 | 32.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vu… |
| CVE-2026-54981 | 7.8 | 32.1 | Microsoft | Python extension for Visual Studio Code | CWE-829 | Visual Studio Code Python Extension Security Feature Bypass Vulnerability |
| CVE-2026-68806 | 7.8 | 32.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-4757 | 7.2 | 31.8 | Axis Communications AB | AXIS OS | CWE-732 | A VAPIX API parameter had improper input validation which could allow code ex… |
| CVE-2026-48436 | 6.5 | 31.7 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-53414 | 6.5 | 31.6 | Zoom Communications | Zoom Clients | CWE-126 | Zoom Clients - Buffer Over-read |
| CVE-2026-19556 | 8.8 | 31.5 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remot… |
| CVE-2026-19559 | 8.8 | 31.5 | Google | Chrome | CWE-416 | Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a rem… |
| CVE-2026-19560 | 8.8 | 31.5 | Google | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a re… |
| CVE-2026-72767 | 8.7 | 31.5 | n8n-io | n8n | CWE-78 | n8n before 1.123.67 Remote Code Execution via Git node |
| CVE-2026-59128 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
| CVE-2026-59137 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-61347 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-61360 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-822 | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-61933 | 5.5 | 31.5 | Microsoft | Windows 11 Version 24H2 | CWE-125 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-62703 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-62709 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows GDI+ Information Disclosure Vulnerability |
| CVE-2026-62730 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Wired AutoConfig Service Information Disclosure Vulnerability |
| CVE-2026-62738 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Management Instrumentation Information Disclosure Vulnerability |
| CVE-2026-62740 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Imaging Component Information Disclosure Vulnerability |
| CVE-2026-62743 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Win32k Information Disclosure Vulnerability |
| CVE-2026-62746 | 5.5 | 31.5 | Microsoft | Windows 10 Version 1607 | CWE-126 | Win32k Information Disclosure Vulnerability |
| CVE-2026-47705 | 9.6 | 31.4 | baptisteArno | typebot.io | CWE-1236 | TypeBot vulnerable to CSV injection in result export |
| CVE-2026-73226 | 8.8 | 31.3 | electerm | electerm | CWE-913 | Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/fu… |
| CVE-2026-73080 | 9.3 | 31.2 | seaweedfs | seaweedfs | CWE-918 | SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.Fetc… |
| CVE-2026-71218 | 5.3 | 31.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-789 | Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows una… |
| CVE-2026-73241 | 8.3 | 30.9 | FreeRDP | FreeRDP | CWE-287 | FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities … |
| CVE-2026-61925 | 7.8 | 30.8 | Microsoft | Windows 10 Version 1607 | CWE-863 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-72773 | 4.9 | 30.9 | n8n-io | n8n | CWE-22 | n8n before 2.32.1 Path Traversal via computer-use search_files |
| CVE-2026-62712 | 7.8 | 30.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62721 | 7.8 | 30.8 | Microsoft | Windows 10 Version 1607 | CWE-1220 | Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability |
| CVE-2024-14042 | 2.1 | 30.7 | n/a | Open5GS | CWE-119 | Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow |
| CVE-2026-48056 | 10.0 | 30.7 | truelockmc | streambert | CWE-20 | Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler |
| CVE-2026-65785 | 6.5 | 30.5 | Microsoft | Windows 11 Version 24H2 | CWE-400 | Windows DHCP Client Denial of Service Vulnerability |
| CVE-2026-63525 | 7.8 | 30.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-197 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-58236 | 5.5 | 30.4 | SAP_SE | SAP NetWeaver Application Server ABAP and ABAP Platform | CWE-78 | OS Command Injection vulnerability in Application Server ABAP of SAP NetWeave… |
| CVE-2026-70315 | 5.5 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70316 | 5.5 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70319 | 5.5 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-70320 | 5.5 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70322 | 5.5 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70323 | 5.5 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70325 | 5.5 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-72764 | 5.8 | 30.1 | n8n-io | n8n | CWE-668 | n8n before 1.123.67 Module Cache Poisoning via Code Node |
| CVE-2026-72742 | 9.2 | 30.0 | Stanford NLP | DSPy | CWE-73 | DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing |
| CVE-2026-61368 | 5.5 | 30.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2026-72765 | 8.7 | 29.8 | n8n-io | n8n | CWE-94 | n8n before 2.32.1 Remote Code Execution via Expression Sandbox Escape |
| CVE-2026-62803 | 7.8 | 29.8 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62807 | 7.8 | 29.8 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-59136 | 5.5 | 29.7 | Microsoft | Windows 10 Version 1607 | CWE-908 | Microsoft COM for Windows Information Disclosure Vulnerability |
| CVE-2026-71384 | 9.6 | 29.4 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-73031 | 8.2 | 29.1 | GramSearch | telegram-search | CWE-79 | telegram-search Stored XSS via v-html in MessageList.vue |
| CVE-2026-56721 | 8.7 | 28.8 | owen2345 | CamaleonCMS | CWE-639 | CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersContro… |
| CVE-2026-62688 | 7.8 | 28.7 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-62698 | 7.8 | 28.7 | Microsoft | Windows 10 Version 1607 | CWE-197 | Microsoft Digest Authentication Elevation of Privilege Vulnerability |
| CVE-2026-73088 | 7.5 | 28.8 | browserslist | browserslist | CWE-248 | Browserslist: Uncaught crash / prototype write via untrusted browserslist-sta… |
| CVE-2026-62745 | 6.5 | 28.7 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-66802 | 8.1 | 28.6 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
| CVE-2026-73089 | 7.5 | 28.7 | browserslist | browserslist | CWE-770 | Browserslist: Unbounded memory growth (no cache eviction) via distinct query … |
| CVE-2026-62842 | 5.5 | 28.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-63517 | 5.5 | 28.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-70318 | 5.5 | 28.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70317 | 5.5 | 28.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-65656 | 7.8 | 28.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-77 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-62829 | 5.4 | 28.3 | Microsoft | Microsoft SharePoint Server 2019 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-73069 | 9.1 | 28.1 | twentyhq | twenty | CWE-89 | Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary P… |
| CVE-2026-62761 | 7.8 | 28.1 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-72600 | 7.5 | 28.1 | Idurar | IDURAR ERP CRM | CWE-284 | Idurar IDURAR ERP CRM - Broken Access Control |
| CVE-2026-72601 | 7.5 | 28.1 | CSZ CMS | CSZ CMS | CWE-284 | CSZ CMS CSZ CMS - Broken Access Control |
| CVE-2026-72549 | 5.3 | 28.1 | OpenSignLabs | OpenSign | CWE-200 | OpenSignLabs OpenSign - Information Disclosure |
| CVE-2026-63513 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63515 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-63518 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63519 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-65664 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-66807 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-68794 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68804 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-197 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-40130 | 5.3 | 27.7 | SAP_SE | SAPSPrint Service | CWE-121 | Memory Corruption vulnerability in SAPSPrint Service |
| CVE-2026-73242 | 8.3 | 27.6 | FreeRDP | FreeRDP | CWE-122 | FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-b… |
| CVE-2026-48415 | 7.6 | 27.5 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-73246 | 7.5 | 27.3 | kestra-io | kestra | CWE-200 | Kestra: Unauthenticated management `/worker` endpoint exposes live task confi… |
| CVE-2026-18697 | 8.7 | 27.2 | MongoDB | MongoDB Server | CWE-617 | Improper Input Validation in MongoDB Aggregation Framework Allows Unauthentic… |
| CVE-2026-15561 | 7.5 | 27.1 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-770 | Undertow-core: oom via missing limits in chunked trailer in eap's undertow |
| CVE-2026-63524 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-63528 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-63529 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-63531 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-64899 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-64917 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-68799 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68802 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68808 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68813 | 5.5 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-24329 | 4.9 | 26.9 | Red Hat | Red Hat Fuse 7 | CWE-91 | Wildfly-core: wildfly core: denial of service via malformed payload injection… |
| CVE-2026-19434 | 5.1 | 26.8 | maalfer | Pentestify | CWE-79 | Stored Cross-site Scripting in Pentestify finding severity field |
| CVE-2026-15426 | 8.8 | 26.8 | acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | CWE-269 | AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to … |
| CVE-2026-18706 | 7.5 | 26.8 | MongoDB | MongoDB Server | CWE-416 | Use-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of S… |
| CVE-2026-48494 | 7.1 | 26.6 | baptisteArno | typebot.io | CWE-639 | TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via globa… |
| CVE-2026-73219 | 5.3 | 26.7 | cvat-ai | cvat | CWE-1288 | CVAT: Denial of service with regards to automatic annotation |
| CVE-2026-73244 | 5.3 | 26.6 | kekingcn | kkFileView | CWE-22 | kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrar… |
| CVE-2026-63526 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63532 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64898 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64903 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64907 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64909 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-191 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64910 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64911 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-68816 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-13739 | 8.8 | 26.3 | Commvault | Commvault Cloud | CWE-918 | Server-Side Request Forgery (SSRF) |
| CVE-2026-73224 | 8.8 | 26.3 | electerm | electerm | CWE-78 | Electerm check folder size function may get attacked by unsafe folder name |
| CVE-2026-11734 | 1.1 | 26.3 | NETGEAR | MR70 | CWE-121 | Device administrator can interrupt the normal operation of some NETGEAR Night… |
| CVE-2026-72599 | 9.8 | 26.2 | e107 | e107 | CWE-89 | e107 e107 - SQL Injection |
| CVE-2026-59130 | 5.6 | 26.1 | Microsoft | Windows 10 Version 1607 | CWE-200 | AMD Zen Information Disclosure Vulnerability |
| CVE-2026-73078 | 8.6 | 26.0 | vim | vim | CWE-77 | Vim: Arbitrary Code Execution via Netrw Menu Construction |
| CVE-2026-62897 | 7.0 | 26.0 | Microsoft | .NET 10.0 | CWE-190 | .NET Framework Remote Code Execution Vulnerability |
| CVE-2026-62914 | 5.4 | 25.9 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-79 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-61359 | 7.8 | 25.8 | Microsoft | Windows 11 version 23H2 | CWE-122 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-62797 | 7.8 | 25.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62811 | 7.8 | 25.8 | Microsoft | Windows 11 version 23H2 | CWE-122 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-72554 | 6.5 | 25.8 | Ladybird Web Solution | Faveo Helpdesk | CWE-284 | Ladybird Web Solution Faveo Helpdesk - Broken Access Control |
| CVE-2026-62788 | 7.0 | 25.6 | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58243 | 8.8 | 25.4 | SAP_SE | SAP ABAP Developer Tools | CWE-862 | Privilege Escalation vulnerability in SAP ABAP Developer Tools |
| CVE-2026-73215 | 7.1 | 25.4 | coturn | coturn | CWE-400 | The coturn server can end in a state where it does not accept more requests w… |
| CVE-2026-48483 | 5.4 | 25.4 | baptisteArno | typebot.io | CWE-918 | TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, a… |
| CVE-2026-73156 | 5.3 | 25.3 | MISP | cti-transmute | CWE-79 | cti-transmute Sunburst and Treemap Tooltips Allow Cross-Site Scripting via Cr… |
| CVE-2026-72557 | 8.8 | 25.2 | Cockpit CMS | Cockpit CMS | CWE-434 | Cockpit CMS Cockpit CMS - Unrestricted File Upload |
| CVE-2026-48813 | 8.7 | 24.9 | david-a-wheeler | flawfinder | CWE-74 | Flawfinder output manipulation via untrusted filenames and source text |
| CVE-2026-11733 | 1.1 | 24.9 | NETGEAR | RAX41 | CWE-121 | Buffer overflow vulnerability in some NETGEAR Nighthawk routers |
| CVE-2026-20702 | 8.9 | 24.8 | n/a | Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts. | CWE-693 | Protection mechanism failure for some Intel(R) Data Center Attestation Primit… |
| CVE-2026-65661 | 7.8 | 24.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-68793 | 7.8 | 24.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68795 | 7.8 | 24.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68796 | 7.8 | 24.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68800 | 7.8 | 24.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68801 | 7.8 | 24.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68805 | 7.8 | 24.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-70313 | 7.8 | 24.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-62769 | 6.7 | 24.8 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62881 | 6.7 | 24.8 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-72604 | 6.5 | 24.8 | Intelliants | Subrion CMS | CWE-22 | Intelliants Subrion CMS - Path Traversal |
| CVE-2026-70130 | 7.8 | 24.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |