| CVE-2026-42985 | 8.8 | 67.1 | Microsoft | Remote Desktop client for Windows Desktop | CWE-787 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42835 | 8.1 | 67.1 | Microsoft | Microsoft Teams for Android | CWE-74 | Microsoft Teams for Android Information Disclosure Vulnerability |
| CVE-2026-8365 | 8.8 | 65.0 | creativethemeshq | Blocksy | CWE-502 | Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Des… |
| CVE-2026-42764 | 7.5 | 64.7 | OpenSSL | OpenSSL | CWE-476 | NULL Pointer Dereference in QUIC Server Initial Packet Handling |
| CVE-2026-45648 | 8.8 | 63.5 | Microsoft | Windows Server 2022 | CWE-121 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-44815 | 9.8 | 62.9 | Microsoft | Windows 10 Version 1607 | CWE-121 | DHCP Client Service Remote Code Execution Vulnerability |
| CVE-2026-11572 | 7.4 | 61.7 | n/a | degit | CWE-78 | Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are v… |
| CVE-2026-34183 | 7.5 | 61.4 | OpenSSL | OpenSSL | CWE-1325 | Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler |
| CVE-2026-48573 | 7.9 | 60.8 | Microsoft | Windows 10 Version 1607 | CWE-1329 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48576 | 7.9 | 60.8 | Microsoft | Windows 10 Version 1607 | CWE-1329 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-34180 | 7.5 | 60.7 | OpenSSL | OpenSSL | CWE-125 | Heap Buffer Over-read in ASN.1 Content Parsing |
| CVE-2026-36723 | 8.8 | 59.9 | n/a | n/a | CWE-22 | An unrestricted file rename vulnerability in the /api/create-user component o… |
| CVE-2026-42766 | 5.9 | 59.8 | OpenSSL | OpenSSL | CWE-476 | Possible NULL Dereference in Password-Based CMS Decryption |
| CVE-2026-47289 | 8.8 | 58.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-49959 | 8.7 | 58.2 | nesquena | hermes-webui | CWE-78 | Hermes WebUI < 0.51.311 RCE via Git Configuration Injection |
| CVE-2026-48560 | 5.4 | 57.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47284 | 6.5 | 57.3 | Microsoft | Visual Studio Code | CWE-200 | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-42903 | 6.5 | 56.8 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows Kerberos Denial of Service Vulnerability |
| CVE-2026-42908 | 7.5 | 55.9 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-45639 | 7.5 | 55.9 | Microsoft | Remote Desktop client for Windows Desktop | CWE-125 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-45504 | 8.8 | 55.0 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-918 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-41098 | 8.4 | 54.6 | Microsoft | Azure Stack Edge | CWE-79 | Azure Stack Edge Spoofing Vulnerability |
| CVE-2026-38615 | 9.8 | 54.1 | n/a | n/a | CWE-78 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. |
| CVE-2026-42907 | 6.5 | 54.1 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-42914 | 5.3 | 53.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Kerberos Denial of Service Vulnerability |
| CVE-2026-47287 | 6.5 | 53.2 | Microsoft | Visual Studio Code | CWE-23 | Visual Studio Code Tampering Vulnerability |
| CVE-2026-40984 | 7.5 | 52.7 | Spring | Micrometer | CWE-400 | Micrometer HTTP server instrumentations DoS vulnerability |
| CVE-2026-47281 | 9.6 | 52.3 | Microsoft | Visual Studio Code | CWE-306 | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-47643 | 9.8 | 52.0 | Microsoft | Azure Stack Edge | CWE-610 | Azure Stack Edge Remote Code Execution Vulnerability |
| CVE-2025-71319 | 8.7 | 51.2 | image-size | image-size | CWE-835 | image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser |
| CVE-2026-49818 | 6.5 | 50.0 | Apache Software Foundation | Apache Airflow Samba provider | CWE-22 | Apache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS o… |
| CVE-2026-45481 | 5.4 | 49.7 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-40376 | 8.1 | 49.0 | Microsoft | Visual Studio Code | CWE-20 | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2016-20064 | 6.9 | 49.0 | myasui | WP Vault | CWE-98 | WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter |
| CVE-2026-47298 | 8.0 | 49.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-285 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-5067 | 9.8 | 47.9 | zephyrproject-rtos | Zephyr | CWE-787 | Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Se… |
| CVE-2017-20248 | 8.7 | 47.8 | Apptha | Apptha Slider Gallery | CWE-22 | WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download |
| CVE-2017-20250 | 8.7 | 47.8 | Apptha | Mac Photo Gallery | CWE-22 | WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download |
| CVE-2026-42974 | 8.1 | 47.7 | Microsoft | Windows 11 version 23H2 | CWE-190 | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2026-42981 | 8.1 | 47.7 | Microsoft | Windows 11 version 23H2 | CWE-191 | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2026-40371 | 8.8 | 47.3 | Microsoft | Microsoft Dynamics 365 (on-premises) version 9.1 | CWE-755 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability |
| CVE-2026-7383 | 8.1 | 47.3 | OpenSSL | OpenSSL | CWE-787 | Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion |
| CVE-2026-45455 | 4.3 | 47.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-40983 | 7.5 | 47.0 | Spring | Micrometer | CWE-400 | Micrometer gRPC server instrumentation DoS vulnerability |
| CVE-2026-45650 | 4.3 | 46.8 | Microsoft | Microsoft Bing Search for Android | CWE-451 | Microsoft Bing Search Spoofing Vulnerability |
| CVE-2026-45445 | 7.5 | 46.0 | OpenSSL | OpenSSL | CWE-325 | AES-OCB IV Ignored on EVP_Cipher() Path |
| CVE-2026-47653 | 8.8 | 46.0 | Microsoft | Windows 10 Version 1607 | CWE-787 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42987 | 8.1 | 45.4 | Microsoft | Windows Server 2012 | CWE-416 | Windows Deployment Services (WDS) Remote Code Execution |
| CVE-2026-9076 | 7.5 | 45.4 | OpenSSL | OpenSSL | CWE-125 | Out-of-Bounds Read in CMS Password-Based Decryption |
| CVE-2026-49955 | 6.9 | 45.3 | nesquena | hermes-webui | CWE-770 | Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options |
| CVE-2026-11788 | 7.5 | 45.1 | Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | CWE-476 | 389-ds-base: 389-ds-base: null pointer dereference in deref control plugin be… |
| CVE-2026-42768 | 3.7 | 45.0 | OpenSSL | OpenSSL | CWE-514 | Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() |
| CVE-2026-30141 | 9.8 | 44.6 | n/a | n/a | CWE-120 | An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in … |
| CVE-2025-10263 | 9.1 | 44.5 | Arm | C1-Ultra | CWE-362 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neove… |
| CVE-2026-47930 | 8.1 | 44.4 | Adobe | ColdFusion | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2017-20251 | 9.3 | 43.9 | Themeisle | Woody Code Snippets | CWE-94 | WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API |
| CVE-2026-47634 | 5.4 | 43.9 | Microsoft | Microsoft SharePoint Server 2019 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-42767 | 5.9 | 43.8 | OpenSSL | OpenSSL | CWE-476 | NULL Pointer Dereference in CRMF EncryptedValue Decryption |
| CVE-2026-45644 | 8.0 | 43.6 | Microsoft | Microsoft Live Share Canvas SDK | CWE-79 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability |
| CVE-2026-48303 | 10.0 | 43.6 | Adobe | Adobe Campaign Classic (ACC) | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-9662 | 8.1 | 43.5 | plasmatizemedia | Recover Exit For WooCommerce | CWE-98 | Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion … |
| CVE-2026-47654 | 7.5 | 43.4 | Microsoft | Windows Server 2016 | CWE-787 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-48563 | 7.5 | 43.4 | Microsoft | Windows 10 Version 1809 | CWE-787 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44803 | 7.8 | 41.9 | Microsoft | Microsoft Excel for Android | CWE-190 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44812 | 7.8 | 41.9 | Microsoft | Microsoft Excel for Android | CWE-190 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-33113 | 6.1 | 41.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45599 | 8.1 | 41.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| CVE-2026-45635 | 8.1 | 41.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| CVE-2026-44822 | 8.2 | 41.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-36726 | 5.3 | 41.2 | n/a | n/a | CWE-22 | An arbitrary file deletion vulnerability in the /api/delete-temp-license/{fil… |
| CVE-2026-41731 | 8.1 | 41.1 | Spring | Spring for Apache Kafka | CWE-502 | In Spring for Apache Kafka, overly broad trusted-package matching in header m… |
| CVE-2026-45453 | 5.4 | 41.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45464 | 5.4 | 41.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45465 | 5.4 | 41.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47636 | 5.4 | 41.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47639 | 5.4 | 41.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-42765 | 7.5 | 41.1 | OpenSSL | OpenSSL | CWE-476 | NULL Dereference in Certificate Verification with OCSP Checking |
| CVE-2026-45462 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45467 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45468 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45479 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45483 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft Office Project Server Spoofing Vulnerability |
| CVE-2026-47637 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47638 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47640 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47641 | 5.4 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-20 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48562 | 4.6 | 40.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2025-52292 | 7.5 | 40.5 | n/a | n/a | CWE-121 | A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP… |
| CVE-2026-47288 | 7.1 | 40.5 | Microsoft | Windows Server 2012 | CWE-190 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution |
| CVE-2026-33582 | 6.5 | 39.3 | Apache Software Foundation | Apache Answer | CWE-434 | Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory… |
| CVE-2026-45583 | 8.1 | 39.0 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-94 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-42913 | 7.5 | 38.9 | Microsoft | Remote Desktop client for Windows Desktop | CWE-362 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2025-52293 | 7.5 | 38.5 | n/a | n/a | CWE-400 | A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_t… |
| CVE-2025-55657 | 7.5 | 38.5 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descr… |
| CVE-2026-44821 | 5.5 | 38.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-9698 | 9.8 | 38.3 | HMBRAND | DBI | CWE-787 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer |
| CVE-2026-42992 | 7.5 | 38.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44799 | 7.5 | 38.1 | Microsoft | Remote Desktop client for Windows Desktop | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44801 | 7.5 | 38.1 | Microsoft | Remote Desktop client for Windows Desktop | CWE-787 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44083 | 8.7 | 38.0 | QNAP Systems Inc. | QuMagie | CWE-639 | QuMagie |
| CVE-2026-42971 | 5.5 | 38.0 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42972 | 5.5 | 38.0 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2026-47960 | 7.4 | 37.8 | Adobe | ColdFusion | CWE-611 | ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (C… |
| CVE-2026-44819 | 7.8 | 37.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-44824 | 7.8 | 37.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45471 | 7.8 | 37.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45475 | 7.8 | 37.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-42770 | 3.7 | 37.7 | OpenSSL | OpenSSL | CWE-325 | FFC-DH Peer Validation Uses Attacker-Supplied q |
| CVE-2026-40128 | 9.0 | 37.7 | SAP_SE | SAP NetWeaver Application Server Java (Web Container) | CWE-35 | Directory Traversal vulnerability in SAP NetWeaver Application Server Java (W… |
| CVE-2026-5068 | 8.8 | 37.5 | zephyrproject-rtos | Zephyr | CWE-787 | bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data |
| CVE-2026-47938 | 10.0 | 37.3 | Adobe | Adobe Campaign Classic (ACC) | CWE-918 | Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-49842 | 7.5 | 37.3 | signalwire | freeswitch | CWE-400 | FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-… |
| CVE-2026-48574 | 7.8 | 37.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Media Remote Code Execution Vulnerability |
| CVE-2026-45503 | 6.5 | 37.0 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-918 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2025-62858 | 5.1 | 37.0 | QNAP Systems Inc. | QTS | CWE-121 | QTS, QuTS hero |
| CVE-2026-46316 | 9.3 | 36.7 | Linux | Linux | CWE-911 | KVM: arm64: vgic-its: Drop the translation cache reference only for the erase… |
| CVE-2026-47292 | 7.8 | 36.6 | Microsoft | Visual Studio Code - MSSQL Extension | CWE-94 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability |
| CVE-2026-42904 | 9.6 | 36.5 | Microsoft | Windows 10 Version 21H2 | CWE-122 | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-45456 | 8.4 | 36.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45458 | 8.4 | 36.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-27671 | 9.8 | 36.4 | SAP_SE | SAP NetWeaver AS ABAP and ABAP Platform | CWE-121 | Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver a… |
| CVE-2026-45485 | 3.3 | 36.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-42993 | 7.5 | 36.2 | Microsoft | Windows 10 Version 21H2 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-46746 | 8.7 | 36.0 | Siemens | SINEC INS | CWE-78 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Upd… |
| CVE-2026-48565 | 7.8 | 36.0 | Microsoft | Windows Narrator Braille | CWE-426 | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-34711 | 7.5 | 35.9 | Adobe | CAI Content Credentials | CWE-190 | CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-44716 | 7.5 | 35.3 | pipecat-ai | pipecat | CWE-22 | Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File … |
| CVE-2026-45595 | 5.4 | 35.3 | Microsoft | Windows 10 Version 1607 | CWE-693 | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-46491 | 8.6 | 35.3 | simplesamlphp | simplesamlphp-module-casserver | CWE-22 | SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ti… |
| CVE-2026-49957 | 6.3 | 35.1 | nesquena | hermes-webui | CWE-22 | Hermes WebUI < 0.51.296 Workspace Boundary Bypass via api/workspace.py |
| CVE-2026-42567 | 5.9 | 35.2 | sveltejs | svelte | CWE-1333 | Svelte: ReDoS in `<svelte:element>` Tag Validation |
| CVE-2026-45649 | 7.1 | 34.9 | Microsoft | Microsoft Excel for Android | CWE-284 | Office for Android Spoofing Vulnerability |
| CVE-2026-49847 | 7.5 | 34.5 | signalwire | freeswitch | CWE-674 | FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON |
| CVE-2026-45655 | 5.3 | 34.4 | Microsoft | Windows 10 Version 1607 | CWE-693 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-45636 | 7.8 | 34.3 | Microsoft | Windows 10 Version 1607 | CWE-20 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-34712 | 7.5 | 33.9 | Adobe | CAI Content Credentials | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-34713 | 7.5 | 33.9 | Adobe | CAI Content Credentials | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-25688 | 6.1 | 33.8 | Apache Software Foundation | Apache Answer | CWE-87 | Apache Answer: XSS in AI Answer Rendering |
| CVE-2026-25699 | 6.1 | 33.8 | Apache Software Foundation | Apache Answer | CWE-359 | Apache Answer: Authorization Bypass in Timeline API |
| CVE-2026-42906 | 5.5 | 33.6 | Microsoft | Windows 10 Version 21H2 | CWE-200 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-42970 | 5.5 | 33.6 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42973 | 5.5 | 33.6 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-45594 | 5.5 | 33.6 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Application Identity (AppID) Information Disclosure Vulnerability |
| CVE-2026-9185 | 7.5 | 33.5 | sixstorage | 6Storage Rentals | CWE-639 | 6Storage Rentals <= 2.22.0 - Unauthenticated Insecure Direct Object Reference… |
| CVE-2026-34031 | 6.5 | 33.6 | Apache Software Foundation | Apache Answer | CWE-434 | Apache Answer: The custom avatar was not properly validated |
| CVE-2026-11618 | 5.5 | 33.3 | DTStack | Taier | CWE-287 | DTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle… |
| CVE-2026-42769 | 5.3 | 33.3 | OpenSSL | OpenSSL | CWE-295 | Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate |
| CVE-2026-41842 | 7.5 | 33.0 | Spring | Spring Framework | CWE-400 | Spring Framework Denial of Service via Versioned Resources in Spring MVC and … |
| CVE-2026-36779 | 7.5 | 32.9 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa… |
| CVE-2026-36783 | 7.5 | 32.9 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa… |
| CVE-2026-36791 | 7.5 | 32.9 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda O3v3 v1.0.0.5 was discovered to cont… |
| CVE-2026-36792 | 7.5 | 32.9 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa… |
| CVE-2026-36793 | 7.5 | 32.9 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa… |
| CVE-2026-36794 | 7.5 | 32.9 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa… |
| CVE-2026-36796 | 7.5 | 32.9 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont… |
| CVE-2026-36797 | 7.5 | 32.9 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont… |
| CVE-2026-36799 | 7.5 | 32.9 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont… |
| CVE-2026-42909 | 7.5 | 32.9 | Microsoft | Remote Desktop client for Windows Desktop | CWE-787 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-9213 | 6.9 | 32.9 | NETGEAR | MR70 | CWE-20 | Insufficient input validation in certain NETGEAR routers |
| CVE-2026-49841 | 9.8 | 32.6 | signalwire | freeswitch | CWE-122 | FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST … |
| CVE-2026-41729 | 8.1 | 32.5 | Spring | Spring Data REST | CWE-917 | Spring Data REST SpEL Injection via Map Key in JSON Patch |
| CVE-2026-42570 | 7.5 | 32.4 | sveltejs | devalue | CWE-770 | Svelte devalue: DoS via sparse array deserialization |
| CVE-2026-45461 | 8.4 | 32.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-42968 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Telephony Server Information Disclosure Vulnerability |
| CVE-2026-42969 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-45491 | 5.5 | 32.0 | Microsoft | .NET 10.0 | CWE-59 | .NET Tampering Vulnerability |
| CVE-2026-48566 | 5.5 | 31.9 | Microsoft | Windows 11 Version 24H2 | CWE-125 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-45490 | 7.8 | 31.5 | Microsoft | .NET 10.0 | CWE-285 | .NET SDK Elevation of Privilege Vulnerability |
| CVE-2026-42915 | 5.5 | 31.4 | Microsoft | Windows 10 Version 21H2 | CWE-131 | Microsoft Windows VMSwitch Denial of Service Vulnerability |
| CVE-2026-45606 | 5.5 | 31.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability |
| CVE-2026-45500 | 6.1 | 30.6 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-79 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-50635 | 8.7 | 30.3 | LimeSurvey | LimeSurvey | CWE-640 | LimeSurvey Password Reset Host Header Injection Discloses Reset Token |
| CVE-2026-44817 | 7.8 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44820 | 7.8 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44823 | 7.8 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-197 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-45457 | 7.8 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45469 | 7.8 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-45486 | 7.8 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45643 | 7.8 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45645 | 7.8 | 30.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-34033 | 5.4 | 30.4 | Apache Software Foundation | Apache Answer | CWE-79 | Apache Answer: HTML Content Injection in Email |
| CVE-2026-53673 | 8.6 | 30.2 | BuddyPress | BuddyPress | CWE-639 | BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter |
| CVE-2026-45459 | 3.3 | 30.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-693 | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2026-45466 | 3.3 | 30.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-36778 | 4.9 | 30.1 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa… |
| CVE-2009-10007 | 9.1 | 30.0 | ETHER | Catalyst::Plugin::Authentication | CWE-384 | Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is suscept… |
| CVE-2026-9750 | 7.1 | 29.9 | MongoDB | MongoDB Server | CWE-617 | Metadata name collision on $-prefixed fields causes post-auth server crash |
| CVE-2026-53674 | 7.1 | 29.8 | BuddyPress | BuddyPress | CWE-943 | BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution |
| CVE-2026-45602 | 9.1 | 29.7 | Microsoft | Windows 10 Version 1607 | CWE-349 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability |
| CVE-2026-36727 | 9.1 | 29.5 | n/a | n/a | CWE-287 | An insecure authentication vulnerability in the /api/social-sign-in endpoint … |
| CVE-2026-45463 | 8.4 | 29.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45472 | 8.4 | 29.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45474 | 8.4 | 29.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-41695 | 7.5 | 29.4 | Spring | Spring Data Commons | CWE-400 | Denial of Service in Spring Data Commons Property Path Resolution |
| CVE-2026-41716 | 7.5 | 29.4 | Spring | Spring Data Commons | CWE-770 | Spring Data web support unbounded negative-result cache keyed on attacker-sup… |
| CVE-2026-45446 | 4.8 | 29.4 | OpenSSL | OpenSSL | CWE-325 | Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes |
| CVE-2026-45634 | 5.5 | 29.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Client Information Disclosure Vulnerability |
| CVE-2026-41850 | 7.5 | 29.1 | Spring | Spring Framework | CWE-407 | Spring Framework Algorithmic Denial of Service via SpEL Expressions |
| CVE-2026-41851 | 7.5 | 29.1 | Spring | Spring Framework | CWE-770 | Spring Framework Denial of Service via Unbounded Cache in SpEL |
| CVE-2026-48288 | 3.5 | 29.1 | Adobe | Adobe Experience Manager | CWE-20 | Adobe Experience Manager | Improper Input Validation (CWE-20) |
| CVE-2026-34691 | 9.3 | 28.9 | Adobe | Adobe Experience Manager Forms JEE | CWE-79 | Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-50636 | 8.7 | 28.9 | LimeSurvey | LimeSurvey | CWE-89 | LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection |
| CVE-2026-45607 | 7.8 | 28.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-3088 | 4.9 | 28.8 | NETGEAR | RBR860 | CWE-787 | Unauthenticated users can disrupt router operation |
| CVE-2026-45460 | 4.7 | 28.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-44805 | 5.5 | 28.7 | Microsoft | Windows Server 2019 | CWE-416 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability |
| CVE-2026-49738 | 2.1 | 28.7 | TYPO3 | TYPO3 CMS | CWE-22 | TYPO3 CMS - Broken Access Control in File Abstraction Layer |
| CVE-2026-45658 | 6.8 | 28.3 | Microsoft | Windows 10 Version 1607 | CWE-284 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-47631 | 5.4 | 28.4 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-79 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-34182 | 9.1 | 28.1 | OpenSSL | OpenSSL | CWE-354 | CMS AuthEnvelopedData Processing May Accept Forged Messages |
| CVE-2026-48569 | 5.5 | 28.1 | Microsoft | Visual Studio Code | CWE-20 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-10731 | 9.3 | 28.0 | Nemon | Nemon Trade Energy | CWE-89 | SQL injection in Nemon products |
| CVE-2026-46325 | 9.8 | 27.8 | Linux | Linux | — | RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE |
| CVE-2026-9742 | 8.2 | 27.7 | MongoDB | MongoDB Server | CWE-1287 | Authenticate command with specific mechanism parameter can trigger server crash |
| CVE-2026-41732 | 8.1 | 27.8 | Spring | Spring for Apache Pulsar | CWE-502 | In Spring for Apache Pulsar, overly broad trusted-package matching in header … |
| CVE-2026-46541 | 7.5 | 27.6 | nimiq | core-rs-albatross | CWE-754 | Nimiq network-libp2p: DHT query poisoning via first-record verification failure |
| CVE-2026-9740 | 8.7 | 27.5 | MongoDB | MongoDB Server | CWE-674 | Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack… |
| CVE-2026-45482 | 8.4 | 27.5 | Microsoft | Microsoft Visual Studio Code CoPilot Chat Extension | CWE-22 | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability |
| CVE-2025-55659 | 6.5 | 27.5 | n/a | n/a | CWE-476 | A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_… |
| CVE-2026-45771 | 7.5 | 27.3 | signalwire | freeswitch | CWE-776 | Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion |
| CVE-2026-47652 | 8.2 | 27.1 | Microsoft | Windows 11 version 23H2 | CWE-122 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-41843 | 5.9 | 27.1 | Spring | Spring Framework | CWE-22 | Spring Framework Path Traversal via Versioned Static Resources in Spring MVC … |
| CVE-2026-45604 | 5.5 | 27.1 | Microsoft | Windows 11 version 23H2 | CWE-125 | Windows Managed Installer Information Disclosure Vulnerability |
| CVE-2026-40404 | 7.8 | 26.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg… |
| CVE-2026-46545 | 7.5 | 26.8 | nimiq | core-rs-albatross | CWE-248 | nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item |
| CVE-2026-45608 | 6.8 | 26.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Client Information Disclosure Vulnerability |
| CVE-2026-32193 | 8.8 | 26.5 | Microsoft | Azure Kubernetes Service | CWE-22 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability |
| CVE-2026-44634 | 8.7 | 26.2 | simpleble | simpleble | CWE-121 | Stack buffer overflows in SimpleBLE |
| CVE-2026-47635 | 8.4 | 26.2 | Microsoft | Microsoft Office LTSC 2024 | CWE-122 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-40988 | 7.5 | 26.0 | Spring | Spring Security | CWE-400 | Unbounded DEFLATE Inflation in SAML 2.0 Service Provider |
| CVE-2026-41721 | 5.9 | 26.0 | Spring | Spring Data Commons | CWE-400 | Spring Data Commons Denial of Service via Data Binding |
| CVE-2026-47912 | 7.8 | 25.8 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-47913 | 7.8 | 25.8 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-47914 | 7.8 | 25.8 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-50511 | 7.8 | 25.8 | Microsoft | Microsoft PC Manager | CWE-59 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-36770 | 7.5 | 25.8 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered … |
| CVE-2026-36771 | 7.5 | 25.8 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa… |
| CVE-2026-36784 | 7.5 | 25.8 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa… |
| CVE-2026-41717 | 8.1 | 25.7 | Spring | Spring Data MongoDB | CWE-917 | Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter… |
| CVE-2026-42828 | 7.8 | 25.4 | Microsoft | Windows 10 Version 1809 | CWE-126 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-42837 | 7.8 | 25.4 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-42916 | 7.8 | 25.4 | Microsoft | Windows 10 Version 1607 | CWE-190 | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-34905 | 6.5 | 25.3 | Apache Software Foundation | Apache Answer | CWE-200 | Apache Answer: Unlisted Questions Accessible via Direct API Access |
| CVE-2026-45476 | 8.2 | 25.2 | Microsoft | Linux kernel - Microsoft MANA Network Driver | CWE-416 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability |
| CVE-2026-24065 | 8.1 | 25.1 | Waves Audio Ltd. | Waves Central | CWE-367 | Local Privilege Escalation via Insecure XPC Client Validation in Waves Centra… |
| CVE-2026-9748 | 7.1 | 25.1 | MongoDB | MongoDB Server | CWE-617 | $_internalConvertBucketIndexStats may crash the mongod server when working on… |
| CVE-2026-0413 | 4.3 | 25.0 | NETGEAR | RBE370 | CWE-121 | Buffer overflow vulnerability in certain NETGEAR Nighthawk routers |
| CVE-2026-26236 | 6.6 | 25.0 | QNAP Systems Inc. | QuMagie | CWE-862 | QuMagie |
| CVE-2026-36719 | 7.5 | 24.9 | n/a | n/a | CWE-200 | An information disclosure vulnerability in the /api/v1/user/info endpoint of … |
| CVE-2026-42573 | 5.3 | 24.7 | sveltejs | svelte | CWE-79 | Svelte: XSS via DOM Clobbering of Internal Framework State |
| CVE-2026-45642 | 3.9 | 24.7 | Microsoft | Windows 10 Version 1607 | CWE-20 | Microsoft Azure Attestation service and Device Health Attestation Service Spo… |
| CVE-2026-44814 | 5.5 | 24.5 | Microsoft | Windows 11 version 26H1 | CWE-122 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-41848 | 7.5 | 24.4 | Spring | Spring Framework | CWE-1333 | Spring Framework Denial of Service via AntPathMatcher |
| CVE-2026-49742 | 7.1 | 24.0 | TYPO3 | TYPO3 CMS | CWE-22 | TYPO3 CMS - Broken Access Control in Media Module |
| CVE-2026-41841 | 5.9 | 24.0 | Spring | Spring Framework | CWE-524 | Spring Framework Information Disclosure via Static Resource Cache in Spring M… |
| CVE-2026-49840 | 9.1 | 23.6 | signalwire | freeswitch | CWE-20 | FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length… |
| CVE-2026-33828 | 7.8 | 23.6 | Microsoft | Windows 10 Version 1607 | CWE-501 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability |
| CVE-2026-45654 | 7.9 | 23.5 | Microsoft | Windows 11 Version 24H2 | CWE-284 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-36800 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont… |
| CVE-2026-36801 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont… |
| CVE-2026-36802 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to cont… |
| CVE-2026-36803 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to cont… |
| CVE-2026-36805 | 7.5 | 23.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont… |
| CVE-2026-36806 | 7.5 | 23.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36807 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36808 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36809 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36810 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36811 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36813 | 7.5 | 23.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36815 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36816 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36817 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c… |
| CVE-2026-36818 | 7.5 | 23.6 | n/a | n/a | CWE-120 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co… |
| CVE-2026-36819 | 7.5 | 23.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co… |
| CVE-2026-36820 | 7.5 | 23.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co… |
| CVE-2026-36821 | 7.5 | 23.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co… |
| CVE-2026-36822 | 7.5 | 23.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co… |
| CVE-2026-36823 | 7.5 | 23.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co… |
| CVE-2026-45501 | 6.1 | 23.5 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-79 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-45641 | 7.8 | 23.3 | Microsoft | Windows 10 Version 21H2 | CWE-125 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-45656 | 7.8 | 23.3 | Microsoft | Windows 10 Version 1607 | CWE-693 | UEFI Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-47915 | 7.8 | 23.3 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-47917 | 7.8 | 23.3 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-9743 | 7.1 | 23.3 | MongoDB | MongoDB server | CWE-476 | Aggregation sub-pipeline null dereference may allow DoS via crafted getMore |
| CVE-2026-41728 | 7.5 | 23.2 | Spring | Spring Data REST | CWE-284 | Spring Data REST JSON Patch bypasses Jackson read-only property protection on… |
| CVE-2026-45588 | 7.9 | 23.0 | Microsoft | Windows 10 Version 1607 | CWE-693 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-47656 | 7.9 | 23.0 | Microsoft | Windows 10 Version 1607 | CWE-693 | Windows Boot Manager Security Feature Bypass Vulnerability |
| CVE-2026-48568 | 7.9 | 23.0 | Microsoft | Windows 10 Version 1607 | CWE-693 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48570 | 7.9 | 23.0 | Microsoft | Windows 10 Version 1607 | CWE-693 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48575 | 7.9 | 23.0 | Microsoft | Windows 10 Version 1607 | CWE-693 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-35188 | 5.0 | 22.8 | OpenSSL | OpenSSL | CWE-415 | Double-free When Checking OCSP Stapled Response |
| CVE-2026-36798 | 6.5 | 22.7 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont… |
| CVE-2026-46411 | 6.5 | 22.7 | halfgaar | FlashMQ | CWE-248 | FlashMQ: Client can trigger uncaught exception on FlashMQ 1.26.1 and older |
| CVE-2026-41007 | 7.5 | 22.5 | Spring | Spring HATEOAS | CWE-770 | Spring HATEOAS heap exhaustion through unbounded internal caching |
| CVE-2026-34693 | 8.0 | 22.3 | Adobe | Adobe Experience Manager Forms JEE | CWE-79 | Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CW… |
| CVE-2026-40409 | 7.8 | 22.3 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg… |
| CVE-2026-9753 | 7.2 | 22.3 | MongoDB | MongoDB Server | CWE-787 | Server crash via malformed binary diff passed to $_internalApplyOplogUpdate. |
| CVE-2026-47918 | 7.8 | 22.2 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-47919 | 7.8 | 22.2 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-44505 | 5.3 | 22.3 | nimiq | core-rs-albatross | CWE-755 | Nimiq network-libp2p: Untrusted peer can wedge DHT |
| CVE-2025-55658 | 6.5 | 22.1 | n/a | n/a | CWE-1077 | GPAC MP4Box v2.4 was discovered to contain a floating point exception in the … |
| CVE-2026-41726 | 6.5 | 22.1 | Spring | Spring for Apache Kafka | CWE-770 | In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled… |
| CVE-2017-20249 | 8.8 | 22.0 | apptha | Apptha Slider Gallery | CWE-89 | WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection |
| CVE-2026-47347 | 5.3 | 22.0 | TYPO3 | TYPO3 CMS | CWE-601 | TYPO3 CMS - Open Redirect in Core Utilities |
| CVE-2026-47924 | 5.5 | 21.8 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-25860 | 5.3 | 21.9 | frankverbeke | OpenClinic GA | CWE-79 | OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler |
| CVE-2026-41092 | 7.8 | 21.6 | Microsoft | Windows 10 Version 1607 | CWE-284 | Microsoft Kinect Elevation of Privilege Vulnerability |
| CVE-2026-42829 | 7.8 | 21.6 | Microsoft | Windows 11 Version 24H2 | CWE-284 | Windows Administrator Protection Secure Feature Bypass Vulnerability |
| CVE-2026-42902 | 7.8 | 21.6 | Microsoft | Microsoft PowerToys | CWE-285 | Microsoft PowerToys Elevation of Privilege Vulnerability |
| CVE-2026-46543 | 5.3 | 21.6 | nimiq | core-rs-albatross | CWE-617 | nimiq-blockchain: Genesis batch set request |
| CVE-2026-11790 | 4.9 | 21.6 | Red Hat | Red Hat Directory Server 11 | CWE-400 | 389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration … |
| CVE-2026-49948 | 8.6 | 21.5 | mem0ai | mem0 | CWE-862 | Mem0 0.2.8 Missing Authorization via POST /configure Endpoint |
| CVE-2026-36724 | 6.5 | 21.4 | n/a | n/a | CWE-400 | An uncaught exception in the /application/job/update/{id} endpoint of Fastapi… |
| CVE-2026-0419 | 4.4 | 21.4 | NETGEAR | JR6150 | CWE-20 | Insufficient input validation vulnerability in NETGEAR JR6150 |
| CVE-2026-42910 | 7.8 | 21.1 | Microsoft | Windows 11 Version 24H2 | CWE-787 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability |
| CVE-2026-42983 | 7.8 | 21.1 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-45592 | 7.8 | 21.1 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability |
| CVE-2026-45593 | 7.8 | 21.1 | Microsoft | Windows 10 Version 1809 | CWE-190 | Windows SDK Elevation of Privilege Vulnerability |
| CVE-2026-45600 | 7.8 | 21.1 | Microsoft | Windows 11 Version 24H2 | CWE-843 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-45605 | 7.8 | 21.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Bluetooth Service Elevation of Privilege Vulnerability |
| CVE-2026-45637 | 7.8 | 21.1 | Microsoft | Windows 10 Version 1809 | CWE-416 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-45638 | 7.8 | 21.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-11620 | 5.5 | 21.0 | TOTOLINK | EX200 | CWE-266 | TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation |
| CVE-2026-49843 | 5.3 | 20.9 | signalwire | freeswitch | CWE-287 | FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` … |
| CVE-2026-11789 | 6.5 | 20.7 | Red Hat | Red Hat Directory Server 11 | CWE-191 | 389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer un… |
| CVE-2026-47939 | 5.4 | 20.7 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47941 | 5.4 | 20.7 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47942 | 5.4 | 20.7 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47943 | 5.4 | 20.7 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47945 | 5.4 | 20.7 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47948 | 5.4 | 20.7 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47970 | 5.4 | 20.7 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-11793 | 4.9 | 20.7 | Red Hat | Red Hat Directory Server 11 | CWE-121 | 389-ds-base: 389-ds-base: stack buffer overflow in checkprefix() algorithm id… |
| CVE-2026-48291 | 7.8 | 20.6 | Adobe | Format Plugins | CWE-122 | Format Plugins | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-48292 | 7.8 | 20.6 | Adobe | Format Plugins | CWE-122 | Format Plugins | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-47923 | 5.5 | 20.5 | Adobe | Acrobat Reader | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-41710 | 5.9 | 20.4 | Spring | Spring Retry | CWE-770 | Cache Exhaustion in Stateful Retries leads to Denial of Service |
| CVE-2026-41711 | 5.9 | 20.4 | Spring | Spring Data Commons | CWE-400 | Potential Denial of Service through crafted Sort Parameters |
| CVE-2026-6445 | 8.7 | 20.4 | Everpure | FlashArray | CWE-939 | A flaw exists in FlashArray Purity where insufficient filtering of certain da… |
| CVE-2026-6444 | 8.6 | 20.4 | Everpure | FlashArray | CWE-639 | A flaw exists in the FlashArray Purity management interface where an authenti… |
| CVE-2026-49475 | 7.5 | 20.3 | signalwire | freeswitch | CWE-20 | FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing |
| CVE-2026-0411 | 4.2 | 20.3 | NETGEAR | RBE970 | CWE-200 | A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi Satellites |
| CVE-2026-47911 | 7.8 | 20.0 | Adobe | Acrobat Reader | CWE-787 | Acrobat Reader | Out-of-bounds Write (CWE-787) |
| CVE-2026-41006 | 7.5 | 20.1 | Spring | Spring HATEOAS | CWE-284 | Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson config… |
| CVE-2026-7486 | 9.8 | 19.9 | Netcad Software Inc. | E-İmar | CWE-89 | SQLi in Netcad's E-İmar |
| CVE-2026-8025 | 9.8 | 19.9 | MOSK Information Technologies Ltd. | CBS Platform | CWE-89 | SQLi in MOSK Informatics' CBS Platform |
| CVE-2026-11616 | 8.8 | 19.9 | stiofansisland | Events Calendar for GeoDirectory | CWE-269 | Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Priv… |
| CVE-2026-41108 | 7.0 | 19.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-8499 | 5.3 | 19.7 | helpfulcrowd | Helpfulcrowd Product Reviews | CWE-843 | Helpfulcrowd Product Reviews <= 1.2.9 - Inccorect Authorization via Type Jugg… |
| CVE-2026-49956 | 7.1 | 19.6 | nesquena | hermes-webui | CWE-862 | Hermes WebUI < 0.51.269 Profile Isolation Bypass via sessions search |
| CVE-2016-20062 | 8.8 | 19.3 | Ollie Armstrong | Simply Poll | CWE-89 | Simply Poll 1.4.1 Plugin for WordPress SQL Injection |
| CVE-2016-20065 | 8.8 | 19.3 | EvWill | Product Catalog 8 | CWE-89 | Product Catalog 8 1.2 Plugin WordPress SQL Injection |
| CVE-2017-20244 | 8.8 | 19.3 | Wow-Company | Wow Forms | CWE-89 | Wow Forms WordPress Plugin 2.1 SQL Injection |
| CVE-2017-20245 | 8.8 | 19.3 | Wow-Company | Wow Viral Signups | CWE-89 | Wow Viral Signups 2.1 WordPress Plugin SQL Injection |
| CVE-2017-20246 | 8.8 | 19.3 | Missilesilo | KittyCatfish | CWE-89 | KittyCatfish 2.2 Plugin for WordPress SQL Injection |
| CVE-2026-9279 | 8.7 | 19.2 | logseq | logseq | CWE-78 | Shell command injection in Logseq |
| CVE-2026-9746 | 7.1 | 19.2 | MongoDB | MongoDB Server | CWE-617 | Server crashes in case of the use of exchange |
| CVE-2026-9747 | 7.1 | 19.2 | MongoDB | MongoDB Server | CWE-617 | Crafted cross-shard merge aggregation crashes MongoDB Server |
| CVE-2026-9749 | 7.1 | 19.2 | MongoDB | MongoDB Server | CWE-617 | Using MaxKey() may crash the server |
| CVE-2026-9752 | 7.1 | 19.2 | MongoDB | MongoDB Server | CWE-476 | GeometryCollection with strict-winding polygon causes server crash during 2ds… |
| CVE-2026-9212 | 5.6 | 19.2 | NETGEAR | LBR1020 | CWE-20 | Insufficient authentication and input validation in certain NETGEAR products |
| CVE-2026-47348 | 5.1 | 19.1 | TYPO3 | TYPO3 CMS | CWE-79 | TYPO3 CMS - Cross-Site Scripting in Indexed Search |
| CVE-2026-36721 | 9.8 | 19.1 | n/a | n/a | CWE-347 | A lack of cryptographic signature verification in the validateAccessToken fun… |
| CVE-2026-41855 | 9.8 | 19.0 | Spring | Spring Framework | CWE-502 | Spring Framework Unsafe Deserialization via Jackson JMS Converters |
| CVE-2026-48578 | 7.9 | 19.0 | Microsoft | Windows 10 Version 1607 | CWE-284 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-44802 | 7.8 | 18.9 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44804 | 7.8 | 18.9 | Microsoft | Windows 11 version 26H1 | CWE-416 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44807 | 7.8 | 18.9 | Microsoft | Windows 11 version 26H1 | CWE-416 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44808 | 7.8 | 18.9 | Microsoft | Windows 11 version 26H1 | CWE-416 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44809 | 7.8 | 18.9 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-44811 | 7.8 | 18.9 | Microsoft | Windows 11 version 26H1 | CWE-416 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44813 | 7.8 | 18.9 | Microsoft | Windows 11 version 26H1 | CWE-416 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-48583 | 7.8 | 18.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-41849 | 7.5 | 18.2 | Spring | Spring Framework | CWE-190 | Spring Framework Denial of Service via Integer Overflow in SpEL Expressions |