| CVE-2026-62646 | 9.1 | 24.0 | Siemens | Reyrolle 7SR5 | CWE-331 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). … |
| CVE-2026-71377 | 9.8 | 23.9 | Hitachi | Cosminexus Component Container | CWE-88 | Command Argument Injection Vulnerability in Cosminexus Component Container |
| CVE-2026-71374 | 9.8 | 23.9 | Hitachi | Cosminexus Component Container | CWE-502 | Deserialization of Untrusted Data Vulnerability in Cosminexus Component Conta… |
| CVE-2026-76969 | 9.4 | 21.7 | SAP_SE | SAP Cloud Application Programming Model (CAP) | CWE-522 | Credential disclosure in multitenant applications using SAP Cloud Application… |
| CVE-2026-86514 | 2.1 | 19.4 | n/a | vgmstream | CWE-119 | vgmstream txth-txtp txth.c sscanf stack-based overflow |
| CVE-2026-86550 | 6.5 | 18.6 | ZTE | NebulaOS | CWE-79 | UXSS vulnerability in ZTE browser products |
| CVE-2026-81790 | 7.5 | 18.3 | Viszt Péter | Csomagpontok és szállítási címkék WooCommerce-hez | CWE-862 | WordPress Csomagpontok és szállítási címkék WooCommerce-hez plugin < 4.2.8 - … |
| CVE-2026-48888 | 7.5 | 17.9 | Automattic | WooCommerce | CWE-770 | WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability |
| CVE-2026-66767 | 7.7 | 17.6 | SAP_SE | SAP NetWeaver Application Server for ABAP and ABAP Platform | CWE-191 | Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP … |
| CVE-2026-71375 | 7.4 | 15.8 | Hitachi | Cosminexus Component Container | CWE-611 | XXE Vulnerability in Cosminexus Component Container |
| CVE-2026-86516 | 5.1 | 13.9 | elenavanengelenmaslova | mocknest-serverless | CWE-266 | elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper … |
| CVE-2026-76968 | 6.5 | 13.9 | SAP_SE | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | CWE-497 | Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communic… |
| CVE-2026-44766 | 6.5 | 13.4 | SAP_SE | SAP S/4HANA (Intercompany Matching and Reconciliation) | CWE-89 | SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconci… |
| CVE-2026-76958 | 8.5 | 12.9 | SAP_SE | SAP Integration Suite | CWE-611 | XML External Entity (XXE) Vulnerability in SAP Integration Suite |
| CVE-2026-76977 | 4.3 | 12.8 | SAP_SE | SAPUI5(Frame Options Allowlist) | CWE-1289 | Clickjacking vulnerability in SAPUI5(Frame Options Allowlist) |
| CVE-2026-58113 | 8.5 | 12.1 | Siemens | Teamcenter V2412 | CWE-79 | A vulnerability has been identified in Teamcenter V2412 (All versions < V2412… |
| CVE-2026-76967 | 7.8 | 12.1 | SAP_SE | SAP NetWeaver Business Client | CWE-502 | Insecure Deserialization in SAP NetWeaver Business Client |
| CVE-2026-58234 | 2.2 | 11.4 | SAP_SE | SAP Process Integration (SOAP Adapter) | CWE-776 | Denial of Service vulnerability in SAP Process Integration (SOAP Adapter) |
| CVE-2026-86512 | 2.1 | 11.1 | java-json-tools | json-patch | CWE-266 | java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperat… |
| CVE-2026-62652 | 6.9 | 10.7 | Siemens | Reyrolle 7SR5 | CWE-215 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). … |
| CVE-2026-19397 | 7.7 | 10.5 | ASUS | Control Center Express Agent | CWE-306 | Missing authentication for a critical function in ASUS Control Center Express… |
| CVE-2026-86517 | 2.1 | 10.4 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql inj… |
| CVE-2026-86518 | 2.1 | 10.4 | code-projects | Student Crud Operation | CWE-74 | code-projects Student Crud Operation edit.php sql injection |
| CVE-2026-76962 | 4.3 | 10.2 | SAP_SE | SAP S/4HANA (Manage Bank Chains app) | CWE-862 | Missing Authorization check in SAP S/4HANA (Manage Bank Chains app) |
| CVE-2026-81792 | 6.5 | 9.4 | MultiVendorX | Product Catalog Enquiry for WooCommerce by MultiVendorX | CWE-266 | WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6… |
| CVE-2026-81802 | 6.5 | 9.4 | Magepeople inc. | WpEvently | CWE-639 | WordPress WpEvently plugin <= 5.6.0 - Insecure Direct Object References (IDOR… |
| CVE-2026-50093 | 8.9 | 8.8 | Siemens | Siveillance Control Pro V3.0 | CWE-434 | A vulnerability has been identified in Siveillance Control Pro V3.0 (All vers… |
| CVE-2026-81781 | 7.1 | 8.0 | Unbounce | Unbounce Landing Pages | CWE-862 | WordPress Unbounce Landing Pages plugin <= 1.1.4 - Broken Access Control vuln… |
| CVE-2026-62653 | 7.0 | 7.9 | Siemens | Reyrolle 7SR5 | CWE-787 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). … |
| CVE-2026-76963 | 4.3 | 6.3 | SAP_SE | SAP NetWeaver and ABAP Platform | CWE-862 | Missing Authorization Check in Application Server ABAP of SAP NetWeaver and A… |
| CVE-2026-81806 | 7.2 | 5.4 | John Darrel | Hide My WP Ghost | CWE-918 | WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SS… |
| CVE-2026-76971 | 6.5 | 4.3 | SAP_SE | SAP Manufacturing Integration and Intelligence | CWE-918 | Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence |
| CVE-2026-81798 | 7.1 | 4.2 | Easy Appointments | Easy Appointments | CWE-79 | WordPress Easy Appointments plugin <= 4.0.2.1 - Cross Site Scripting (XSS) vu… |
| CVE-2026-84817 | 7.1 | 4.2 | Crocoblock | JetFormBuilder | CWE-79 | WordPress JetFormBuilder plugin <= 3.6.5.1 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-84818 | 7.1 | 4.2 | 100plugins | Open User Map | CWE-79 | WordPress Open User Map plugin <= 1.4.50 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-84820 | 7.1 | 4.2 | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-79 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-34223 | 8.6 | 3.1 | Siemens | Desigo CC ClickOnce Client V6 | CWE-94 | A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All ver… |
| CVE-2026-74859 | 6.8 | 2.6 | Red Hat | Red Hat Enterprise Linux 8 | CWE-22 | Gnome-tweaks: path traversal in theme installer |
| CVE-2026-62654 | 7.0 | 1.4 | Siemens | Reyrolle 7SR5 | CWE-494 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). … |
| CVE-2026-75809 | 5.9 | 1.3 | ASUS | Armoury Crate | CWE-782 | Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a… |
| CVE-2026-75808 | 5.7 | 1.3 | ASUS | Armoury Crate | CWE-770 | Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate al… |
| CVE-2026-75810 | 5.7 | 1.3 | ASUS | Armoury Crate | CWE-749 | Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user… |
| CVE-2026-75811 | 5.8 | 1.2 | ASUS | Armoury Crate | CWE-1256 | Improper Restriction of Software Interfaces to Hardware Features in ASUS Armo… |
| CVE-2026-76960 | 3.5 | 0.7 | SAP_SE | SAP S/4HANA (Finance for Advanced Payment Management) | CWE-352 | Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for A… |
| CVE-2026-76961 | 3.5 | 0.7 | SAP_SE | SAP S/4HANA (Finance for Advanced Payment Management) | CWE-352 | Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for A… |
| CVE-2026-16004 | 5.9 | 0.5 | ASUS | Armoury Crate | CWE-782 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows… |
| CVE-2026-16005 | 5.8 | 0.5 | ASUS | Armoury Crate | CWE-763 | Release of Invalid Pointer or Reference in Armoury Crate driver allows a loca… |
| CVE-2026-16006 | 5.7 | 0.5 | ASUS | Armoury Crate | CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in… |
| CVE-2026-18023 | 5.7 | 0.5 | ASUS | Armoury Crate | CWE-226 | Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Cr… |
| CVE-2026-16003 | 2.0 | 0.5 | ASUS | Armoury Crate | CWE-782 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows… |
| CVE-2026-76959 | 4.6 | 0.4 | SAP_SE | SAP S/4HANA (Finance for Advanced Payment Management) | CWE-352 | Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for A… |
| CVE-2026-86597 | 6.5 | 0.4 | Snowflake | Snowflake Connector for Python | CWE-532 | Sensitive information written to logs by Snowflake drivers |
| CVE-2026-28659 | 10.0 | — | Google | Android XR | — | In MicroXR Blobstore, there is a possible way to access other app's files due… |
| CVE-2026-49883 | 10.0 | — | Google | Android Wear | — | In checkReadPermission of PermissionsManager.java, there is a possible way to… |
| CVE-2026-82004 | 10.0 | — | Adobe | Adobe Campaign Classic | CWE-78 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-12645 | 9.9 | — | Ivanti | Ivanti Neurons for ITSM | CWE-862 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.… |
| CVE-2026-12646 | 9.9 | — | Ivanti | Ivanti Neurons for ITSM | CWE-862 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.… |
| CVE-2026-12647 | 9.9 | — | Ivanti | Ivanti Neurons for ITSM | CWE-862 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.… |
| CVE-2026-12650 | 9.9 | — | Ivanti | Neurons for ITSM | CWE-502 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM … |
| CVE-2026-19232 | 9.9 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-863 | Adobe Experience Manager | Incorrect Authorization (CWE-863) |
| CVE-2026-26084 | 9.9 | — | Fortinet | FortiSandbox PaaS | CWE-284 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 throug… |
| CVE-2026-48273 | 9.9 | — | Adobe | ColdFusion 2025 | CWE-95 | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated C… |
| CVE-2026-78234 | 9.9 | — | Red Hat | Red Hat build of Apache Camel - HawtIO 4 | CWE-295 | Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-… |
| CVE-2026-83941 | 9.9 | — | Microsoft | Microsoft Entra | CWE-862 | Entra ID Elevation of Privilege Vulnerability |
| CVE-2026-84869 | 9.9 | — | ConnectWise | ScreenConnect | CWE-269 | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions |
| CVE-2026-86464 | 9.9 | — | Eclipse Foundation | Eclipse aeriOS | CWE-200 | In the current development version of Eclipse aeriOS, for which no official r… |
| CVE-2026-12744 | 9.8 | — | Ivanti | Neurons for ITSM | CWE-502 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM … |
| CVE-2026-12745 | 9.8 | — | Ivanti | Neurons for ITSM | CWE-502 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM … |
| CVE-2026-49921 | 9.8 | — | Google | Android | CWE-122 | In multiple locations, there is a possible memory safety issue due to a heap … |
| CVE-2026-58822 | 9.8 | — | Google | Android | CWE-704 | In multiple functions of ftsmooth.c, there is a possible memory safety issue … |
| CVE-2026-66302 | 9.8 | — | Microsoft | Skype for Business Server 2015 CU13 | CWE-73 | Skype for Business Remote Code Execution Vulnerability |
| CVE-2026-68839 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-20 | Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability |
| CVE-2026-69276 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability |
| CVE-2026-69408 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-69431 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Telnet Client Remote Code Execution Vulnerability |
| CVE-2026-69463 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-69491 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft DirectMusic Remote Code Execution Vulnerability |
| CVE-2026-69493 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Event Logging Service Remote Code Execution Vulnerability |
| CVE-2026-69496 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Compressed Folder Remote Code Execution Vulnerability |
| CVE-2026-69525 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2026-69579 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Message Queuing Remote Code Execution Vulnerability |
| CVE-2026-69586 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows PDF Remote Code Execution Vulnerability |
| CVE-2026-69590 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulner… |
| CVE-2026-69595 | 9.8 | — | Microsoft | Windows Server 2012 | CWE-416 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
| CVE-2026-69715 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Direct Show Remote Code Execution Vulnerability |
| CVE-2026-69730 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-69768 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows RNDIS Remote Code Execution Vulnerability |
| CVE-2026-69769 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows HTTP Print Provider Remote Code Execution Vulnerability |
| CVE-2026-69819 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-787 | RPC Runtime Library Remote Code Execution Vulnerability |
| CVE-2026-69824 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Standard XPS Remote Code Execution Vulnerability |
| CVE-2026-69829 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Shell Remote Code Execution Vulnerability |
| CVE-2026-69845 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-20 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-69910 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-70296 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-787 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-72979 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-72982 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Netlogon Remote Code Execution Vulnerability |
| CVE-2026-72983 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
| CVE-2026-73009 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnera… |
| CVE-2026-73010 | 9.8 | — | Microsoft | Windows 10 Version 1809 | CWE-416 | Microsoft Failover Cluster Remote Code Execution Vulnerability |
| CVE-2026-73025 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-1390 | Windows iSCSI Security Feature Bypass Vulnerability |
| CVE-2026-77493 | 9.8 | — | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-78445 | 9.8 | — | Microsoft | Windows Server 2012 | CWE-416 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
| CVE-2026-78509 | 9.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Outlook Remote Code Execution Vulnerability |
| CVE-2026-78510 | 9.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-79569 | 9.8 | — | n/a | n/a | CWE-89 | Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerabilit… |
| CVE-2026-79576 | 9.8 | — | n/a | n/a | CWE-287 | An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6… |
| CVE-2026-65669 | 9.6 | — | Microsoft | SQL Server Management Studio 22 | CWE-74 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-81376 | 9.6 | — | Microsoft | Visual Studio Code | CWE-693 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-82533 | 9.4 | — | DeepSeek | DeepSeek Harness | CWE-807 | DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing |
| CVE-2026-61516 | 9.3 | — | Netis Systems | NX10 | CWE-522 | Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint |
| CVE-2026-69356 | 9.3 | — | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-79 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-76200 | 9.3 | — | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-76201 | 9.3 | — | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-77089 | 9.3 | — | Commvault | Commvault Cloud | — | Command Center API Authentication Bypass |
| CVE-2026-86738 | 9.3 | — | grokability | snipe-it | CWE-79 | Snipe-IT before 8.7.0 CSS Injection via Custom CSS |
| CVE-2026-82067 | 9.2 | — | MongoDB | MongoDB Server | CWE-178 | Improper Case Sensitivity Handling in MongoDB Server Configuration Validation… |
| CVE-2026-84197 | 9.2 | — | Eclipse Foundation | Eclipse Ditto | CWE-295 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclip… |
| CVE-2026-53939 | 9.1 | — | OpenIDC | cjose | CWE-321 | OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encry… |
| CVE-2026-69641 | 9.1 | — | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-862 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-73309 | 9.1 | — | XenForo | XenForo | CWE-697 | XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint |
| CVE-2026-73311 | 9.1 | — | XenForo | XenForo | CWE-294 | XenForo < 2.3.13 OAuth2 Authorization Code Reuse |
| CVE-2026-73312 | 9.1 | — | XenForo | XenForo | CWE-294 | XenForo < 2.3.13 Refresh Token Replay via Expired Access Token |
| CVE-2026-75156 | 9.1 | — | Apache Software Foundation | Apache Airflow FAB provider | CWE-346 | Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not… |
| CVE-2026-75746 | 9.1 | — | Adobe | ColdFusion 2025 | CWE-89 | ColdFusion | Improper Neutralization of Special Elements used in an SQL Comma… |
| CVE-2026-86729 | 9.1 | — | WWBN | AVideo | CWE-307 | WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize |
| CVE-2026-53581 | 9.0 | — | opnsense | core | CWE-22 | ntp: write path traversal |
| CVE-2026-69854 | 9.0 | — | Microsoft | Spring Cloud Azure | CWE-287 | Spring Cloud Azure Elevation of Privilege Vulnerability |
| CVE-2026-85982 | 9.0 | — | Auth0 | Auth0 AD/LDAP Connector | CWE-79 | Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector |
| CVE-2026-12648 | 8.8 | — | Ivanti | Neurons for ITSM | CWE-502 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM … |
| CVE-2026-12651 | 8.8 | — | Ivanti | Neurons for ITSM | CWE-502 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM … |
| CVE-2026-16502 | 8.8 | — | livecomposer | Live Composer – Free WordPress Website Builder | CWE-502 | Live Composer <= 2.1.18 - Authenticated (Contributor+) PHP Object Injection v… |
| CVE-2026-18851 | 8.8 | — | Ivanti | Endpoint Manager Mobile | CWE-862 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.… |
| CVE-2026-62706 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-121 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-62744 | 8.8 | — | Microsoft | Windows 11 Version 24H2 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-62895 | 8.8 | — | Microsoft | Azure Arc SQL Server Extension | CWE-89 | Azure Arc SQL Server Extension Elevation of Privilege Vulnerability |
| CVE-2026-65772 | 8.8 | — | Microsoft | Microsoft Dynamics 365 (on-premises) version 9.1 | CWE-502 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-66814 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-1220 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-66818 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-269 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-66819 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-89 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-66820 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-89 | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-67368 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-59 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-67370 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-89 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-67373 | 8.8 | — | Microsoft | Microsoft SQL Server 2025 (CU8) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67380 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67381 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-67384 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67385 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-416 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67388 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67631 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67638 | 8.8 | — | Microsoft | Microsoft SQL Server 2025 (CU8) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67639 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67642 | 8.8 | — | Microsoft | Microsoft SQL Server 2025 (CU8) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67643 | 8.8 | — | Microsoft | Microsoft SQL Server 2022 (CU 26) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-68775 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-68786 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-68828 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-69266 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-69268 | 8.8 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-284 | Microsoft Office SharePoint Remote Code Execution Vulnerability |
| CVE-2026-69273 | 8.8 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-284 | Microsoft Office SharePoint Remote Code Execution Vulnerability |
| CVE-2026-69282 | 8.8 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-284 | Microsoft Office SharePoint Remote Code Execution Vulnerability |
| CVE-2026-69285 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-69291 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Volume Manager Extension Driver Remote Code Execution Vulnerability |
| CVE-2026-69334 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Volume Manager Extension Driver Remote Code Execution Vulnerability |
| CVE-2026-69355 | 8.8 | — | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-73 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-69360 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-69386 | 8.8 | — | Microsoft | Windows 10 Version 1809 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-69434 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows URL Moniker Remote Code Execution Vulnerability |
| CVE-2026-69439 | 8.8 | — | Microsoft | .NET 10.0 | CWE-122 | .NET and Visual Studio Elevation of Privilege Vulnerability |
| CVE-2026-69442 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-69461 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-69464 | 8.8 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-250 | Microsoft Office SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-69465 | 8.8 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-862 | Microsoft Office SharePoint Remote Code Execution Vulnerability |
| CVE-2026-69485 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-908 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-69494 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Event Logging Service Remote Code Execution Vulnerability |
| CVE-2026-69495 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Event Logging Service Remote Code Execution Vulnerability |
| CVE-2026-69499 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-69511 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-69518 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Remote Desktop Remote Code Execution Vulnerability |
| CVE-2026-69522 | 8.8 | — | Microsoft | .NET 10.0 | CWE-122 | .NET and Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-69529 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Access Remote Code Execution Vulnerability |
| CVE-2026-69547 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-69551 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-69556 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-69598 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-131 | Windows iSCSI Remote Code Execution Vulnerability |
| CVE-2026-69601 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-69603 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-69614 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office Access Remote Code Execution Vulnerability |
| CVE-2026-69628 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows iSCSI Remote Code Execution Vulnerability |
| CVE-2026-69629 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Outlook Remote Code Execution Vulnerability |
| CVE-2026-69632 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-69649 | 8.8 | — | Microsoft | Raw Image Extension | CWE-122 | Raw Image Extension Remote Code Execution Vulnerability |
| CVE-2026-69669 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kernel Remote Code Execution Vulnerability |
| CVE-2026-69671 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-69676 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-294 | Windows Kerberos Remote Code Execution Vulnerability |
| CVE-2026-69678 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-69686 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-69712 | 8.8 | — | Microsoft | Windows Server 2012 | CWE-416 | Windows Key Distribution Center Remote Code Execution Vulnerability |
| CVE-2026-69716 | 8.8 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-89 | Microsoft Office SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-69722 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-69724 | 8.8 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-862 | Microsoft Office SharePoint Remote Code Execution Vulnerability |
| CVE-2026-69729 | 8.8 | — | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Credential Providers Remote Code Execution Vulnerability |
| CVE-2026-69740 | 8.8 | — | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows Hello Elevation of Privilege Vulnerability |
| CVE-2026-69742 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Publisher Remote Code Execution Vulnerability |
| CVE-2026-69759 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-69764 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-69767 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-69772 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Network File System Remote Code Execution Vulnerability |
| CVE-2026-69778 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Access Remote Code Execution Vulnerability |
| CVE-2026-69784 | 8.8 | — | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Hello Elevation of Privilege Vulnerability |
| CVE-2026-69797 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-69860 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-70203 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Media Player Remote Code Execution Vulnerability |
| CVE-2026-70351 | 8.8 | — | Microsoft | WebP Image Extension | CWE-122 | Microsoft WebP Image Extension Remote Code Execution Vulnerability |
| CVE-2026-70586 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Paint Remote Code Execution Vulnerability |
| CVE-2026-71328 | 8.8 | — | Microsoft | .NET 10.0 | CWE-122 | .NET and Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-71336 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Work Folder Service Remote Code Execution Vulnerability |
| CVE-2026-71352 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows Remote Access Connection Manager Remote Code Execution Vulnerability |
| CVE-2026-72933 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability |
| CVE-2026-72940 | 8.8 | — | Microsoft | Windows 11 version 23H2 | CWE-122 | Windows Schannel Remote Code Execution Vulnerability |
| CVE-2026-72950 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulner… |
| CVE-2026-72959 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulner… |
| CVE-2026-72960 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Media Player Remote Code Execution Vulnerability |
| CVE-2026-72972 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-72973 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-72986 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Graphic Fonts Remote Code Execution Vulnerability |
| CVE-2026-73006 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-121 | DirectWrite Remote Code Execution Vulnerability |
| CVE-2026-73012 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Management Services Elevation of Privilege Vulnerability |
| CVE-2026-73013 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-73016 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | DirectWrite Remote Code Execution Vulnerability |
| CVE-2026-73018 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Graphic Fonts Remote Code Execution Vulnerability |
| CVE-2026-73023 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-73028 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-284 | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-77097 | 8.8 | — | Commvault | Commvault Cloud | CWE-306 | Private Metrics Server Denial of Service |
| CVE-2026-77098 | 8.8 | — | Commvault | Commvault Cloud | CWE-89 | Private Metrics Server SQL Injection |
| CVE-2026-77480 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-1220 | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-77481 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-77482 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-77483 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-1390 | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-77484 | 8.8 | — | Microsoft | Microsoft SQL Server 2019 (CU 32) | CWE-502 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-77486 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-77487 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-284 | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-77495 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-77504 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-415 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-77901 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-476 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-77906 | 8.8 | — | Microsoft | Microsoft Visual Studio 2026 version 18.9 | CWE-122 | Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-77907 | 8.8 | — | Microsoft | Microsoft Visual Studio 2026 version 18.9 | CWE-122 | Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-77908 | 8.8 | — | Microsoft | Microsoft Dynamics 365 Customer Engagement V9.1 | CWE-94 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-78439 | 8.8 | — | Microsoft | Microsoft Office 365 for Mac | CWE-121 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-78442 | 8.8 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Windows OLE DB Remote Code Execution Vulnerability |
| CVE-2026-78456 | 8.8 | — | Microsoft | Microsoft SQL Server 2022 (CU 26) | CWE-122 | SQL Server Remote Code Execution Vulnerability |
| CVE-2026-78462 | 8.8 | — | Microsoft | Visual Studio Code | CWE-639 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-78463 | 8.8 | — | Microsoft | Remote Desktop client for Windows Desktop | CWE-94 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-78504 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-78505 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-78507 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-78511 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-78512 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-78514 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-78517 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-78518 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office Excel Remote Code Execution Vulnerability |
| CVE-2026-78519 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Office Outlook Remote Code Execution Vulnerability |
| CVE-2026-78521 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-78524 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-78525 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Outlook Remote Code Execution Vulnerability |
| CVE-2026-78526 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-79376 | 8.8 | — | n/a | n/a | CWE-20 | An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 B… |
| CVE-2026-80074 | 8.8 | — | Microsoft | Remote Desktop client for Windows Desktop | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-80077 | 8.8 | — | Microsoft | Remote Desktop client for Windows Desktop | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-80080 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-415 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-80081 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-80083 | 8.8 | — | Microsoft | Windows 11 version 23H2 | CWE-822 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-80085 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-80096 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-81352 | 8.8 | — | Microsoft | Web Media Extensions | CWE-122 | Web Media Extensions Remote Code Execution Vulnerability |
| CVE-2026-81385 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-502 | Microsoft Office Publisher Remote Code Execution Vulnerability |
| CVE-2026-81952 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-81955 | 8.8 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-81996 | 8.8 | — | Adobe | Adobe Acrobat | CWE-863 | Acrobat Reader | Incorrect Authorization (CWE-863) |
| CVE-2026-83992 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-83996 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Error Reporting Elevation of Privilege Vulnerability |
| CVE-2026-83998 | 8.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-85877 | 8.8 | — | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Print Spooler Remote Code Execution Vulnerability |
| CVE-2026-12611 | 8.7 | — | Eclipse Foundation | Eclipse Jetty | CWE-400 | A client may issue HTTP/2 requests to a Jetty server that result in blocking … |
| CVE-2026-33197 | 8.7 | — | AMI | AptioV | CWE-184 | BDS Module Bypass Secure Boot Advisory |
| CVE-2026-55250 | 8.7 | — | macropay-solutions | maravel-framework | CWE-294 | Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Evic… |
| CVE-2026-73314 | 8.7 | — | XenForo | XenForo | CWE-754 | XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook |
| CVE-2026-73316 | 8.7 | — | XenForo | XenForo | CWE-345 | XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider |
| CVE-2026-77101 | 8.7 | — | Commvault | Commvault Cloud | CWE-121 | CommServe Stack-based Buffer Overflow |
| CVE-2026-77102 | 8.7 | — | Commvault | Commvault Cloud | CWE-122 | CommServe Denial of Service |
| CVE-2026-77103 | 8.7 | — | Commvault | Commvault Cloud | CWE-288 | CommServe Information Disclosure |
| CVE-2026-77105 | 8.7 | — | Commvault | Commvault Cloud | CWE-347 | CommServe Privilege Escalation |
| CVE-2026-77111 | 8.7 | — | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-80219 | 8.7 | — | Red Hat | Red Hat build of Apache Camel - HawtIO 4 | CWE-1390 | Hawtio-operator: hawtio-operator: oauthclient created with grantmethod auto a… |
| CVE-2026-82064 | 8.7 | — | MongoDB | MongoDB Server | CWE-617 | Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in … |
| CVE-2026-82075 | 8.7 | — | MongoDB | MongoDB Server | CWE-770 | Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Un… |
| CVE-2026-86075 | 8.7 | — | n8n-io | n8n | CWE-770 | n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client R… |
| CVE-2026-86076 | 8.7 | — | n8n-io | n8n | CWE-94 | n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScr… |
| CVE-2026-86721 | 8.7 | — | WWBN | AVideo | CWE-287 | AVideo through c3edcc274c Authorization Bypass via Session Cookie |
| CVE-2026-86727 | 8.7 | — | WWBN | AVideo | CWE-306 | AVideo through 29.0 Information Disclosure via stats.json.php |
| CVE-2026-86728 | 8.7 | — | WWBN | AVideo | CWE-306 | AVideo through 29.0 Unauthenticated Disclosure via epg.json.php |
| CVE-2026-86730 | 8.7 | — | craftcms | cms | CWE-94 | Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE |
| CVE-2026-86732 | 8.7 | — | craftcms | cms | CWE-94 | Craft CMS before 5.10.12 Remote Code Execution via element-index |
| CVE-2026-61517 | 8.6 | — | Netis Systems | NX10 | CWE-78 | Netis NX10 OS Command Injection via Ping Diagnostic Handler |
| CVE-2026-74239 | 8.6 | — | XenForo | XenForo | CWE-22 | XenForo < 2.3.13 Path Traversal via Style Archive Importer on Windows |
| CVE-2026-75990 | 8.6 | — | Adobe | Illustrator Desktop 2026 | CWE-863 | Illustrator | Incorrect Authorization (CWE-863) |
| CVE-2026-75991 | 8.6 | — | Adobe | Illustrator Desktop 2026 | CWE-20 | Illustrator | Improper Input Validation (CWE-20) |
| CVE-2026-76190 | 8.6 | — | Adobe | ColdFusion 2025 | CWE-95 | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated C… |
| CVE-2026-76199 | 8.6 | — | Adobe | Photoshop 2026 | CWE-427 | Photoshop Desktop | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-77109 | 8.6 | — | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-77774 | 8.6 | — | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-79721 | 8.6 | — | mlflow | mlflow | CWE-829 | Code execution can occur in versions of the MLflow platform running version 0… |
| CVE-2026-80097 | 8.6 | — | Microsoft | Microsoft Authenticator for Android | CWE-287 | Microsoft Authenticator Elevation of Privilege Vulnerability |
| CVE-2026-86712 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan before 3.8.2 Remote Code Execution via Clipboard |
| CVE-2026-86720 | 8.6 | — | WWBN | AVideo | CWE-639 | WWBN AVideo Missing Authorization via resendRestreamer.json.php |
| CVE-2026-86722 | 8.6 | — | WWBN | AVideo | CWE-287 | AVideo Authentication Bypass via SQL Cache Invalidation |
| CVE-2026-86723 | 8.6 | — | WWBN | AVideo | CWE-287 | AVideo LoginControl PGP Authentication Bypass via verifyChallenge |
| CVE-2026-86733 | 8.6 | — | grokability | snipe-it | CWE-78 | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore |
| CVE-2026-67378 | 8.5 | — | Microsoft | Microsoft SQL Server 2019 (CU 32) | CWE-822 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67379 | 8.5 | — | Microsoft | Microsoft SQL Server 2019 (CU 32) | CWE-121 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-67636 | 8.5 | — | Microsoft | Microsoft SQL Server 2019 (CU 32) | CWE-125 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-74860 | 8.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-763 | Libxml2: double-free/uaf in libxml2 python bindings |
| CVE-2026-75993 | 8.5 | — | Adobe | ColdFusion 2025 | CWE-79 | ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2026-77091 | 8.5 | — | Commvault | Commvault Cloud | CWE-22 | DataCube Security Feature Bypass |
| CVE-2026-85384 | 8.5 | — | TP-Link Systems Inc. | RE210 AC750 | CWE-121 | Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import |
| CVE-2026-69479 | 8.4 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-69638 | 8.4 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-75999 | 8.4 | — | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-77503 | 8.4 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-77827 | 8.4 | — | Maono | Maono Link | CWE-428 | Maono Link local privilege escalation |
| CVE-2026-86819 | 8.4 | — | Waves Audio Ltd. | Waves Central | CWE-862 | Waves Central local privilege escalation via Improper XPC Client Authenticati… |
| CVE-2026-19203 | 8.3 | — | Eclipse Foundation | Eclipse Jetty | CWE-444 | A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty ser… |
| CVE-2026-69646 | 8.3 | — | Microsoft | Skype for Business Server 2015 CU13 | CWE-347 | Skype for Business Spoofing Vulnerability |
| CVE-2026-77104 | 8.3 | — | Commvault | Commvault Cloud | CWE-22 | CommServe Path Traversal |
| CVE-2026-81821 | 8.3 | — | AVEVA | Pipeline Integrity Monitor | CWE-321 | AVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic key |
| CVE-2026-81822 | 8.3 | — | AVEVA | Pipeline Integrity Monitor | CWE-327 | AVEVA Pipeline Integrity Monitor Use of a Broken or Risky Cryptographic Algor… |
| CVE-2026-53938 | 8.2 | — | OpenIDC | cjose | CWE-122 | OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A… |
| CVE-2026-69820 | 8.2 | — | Microsoft | Windows 10 Version 21H2 | CWE-122 | Windows Hello Elevation of Privilege Vulnerability |
| CVE-2026-69846 | 8.2 | — | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-69874 | 8.2 | — | Microsoft | Windows 10 Version 1809 | CWE-822 | Windows ALPC Elevation of Privilege Vulnerability |
| CVE-2026-69906 | 8.2 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-72958 | 8.2 | — | Microsoft | Windows 11 Version 24H2 | CWE-415 | Windows Credential Guard Elevation of Privilege Vulnerability |
| CVE-2026-72961 | 8.2 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-72962 | 8.2 | — | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows USB Video Driver Elevation of Privilege Vulnerability |
| CVE-2026-73310 | 8.2 | — | XenForo | XenForo | CWE-863 | XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass |
| CVE-2026-76191 | 8.2 | — | Adobe | Adobe Animate 2023 | CWE-94 | Animate | Improper Control of Generation of Code ('Code Injection') (CWE-94) |
| CVE-2026-76202 | 8.2 | — | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-77968 | 8.2 | — | Red Hat | Red Hat build of Apache Camel - HawtIO 4 | CWE-269 | Hawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to … |
| CVE-2026-81354 | 8.2 | — | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Hello Elevation of Privilege Vulnerability |
| CVE-2026-81356 | 8.2 | — | Microsoft | Visual Studio Code | CWE-444 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-81357 | 8.2 | — | Microsoft | Visual Studio Code | CWE-918 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-81378 | 8.2 | — | Microsoft | Visual Studio Code | CWE-436 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-81379 | 8.2 | — | Microsoft | Visual Studio Code | CWE-636 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-81994 | 8.2 | — | Adobe | Adobe Acrobat | CWE-1321 | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attri… |
| CVE-2026-83939 | 8.2 | — | Microsoft | Windows 11 version 26H1 | CWE-822 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-86600 | 8.2 | — | Snowflake | Snowflake Connector for Python | CWE-441 | Workload identity attestation generated before login host validation in Snowf… |
| CVE-2026-47297 | 8.1 | — | Microsoft | Microsoft SQL Server 2019 (CU 32) | CWE-502 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-55007 | 8.1 | — | Microsoft | Microsoft Exchange Server 2019 Cumulative Update 14 | CWE-415 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-69325 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft JScript Remote Code Execution Vulnerability |
| CVE-2026-69380 | 8.1 | — | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-862 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-69438 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-681 | Microsoft JScript Remote Code Execution Vulnerability |
| CVE-2026-69510 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-69524 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-69530 | 8.1 | — | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vu… |
| CVE-2026-69546 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-69620 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-69680 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-346 | Windows DNS Spoofing Vulnerability |
| CVE-2026-69732 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerab… |
| CVE-2026-69782 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-69786 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Text Shaping Remote Code Execution Vulnerability |
| CVE-2026-69813 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-69827 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-69858 | 8.1 | — | Microsoft | Windows Server 2022 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-69989 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-70342 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-70563 | 8.1 | — | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows Shell Spoofing Vulnerability |