| CVE-2026-49798 | 9.3 | 81.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-49800 | 7.8 | 80.3 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulne… |
| CVE-2026-50667 | 7.0 | 79.2 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-50329 | 7.8 | 78.5 | Microsoft | Windows 10 Version 1809 | CWE-416 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-58536 | 7.8 | 78.5 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-50387 | 7.8 | 78.2 | Microsoft | Microsoft Office 365 for Mac | CWE-121 | Windows GDI Elevation of Privilege Vulnerability |
| CVE-2026-50433 | 7.8 | 78.2 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-54114 | 7.8 | 78.2 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54986 | 7.8 | 78.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-49795 | 8.8 | 77.9 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50375 | 7.8 | 76.8 | Microsoft | Windows 10 Version 1809 | CWE-122 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50436 | 7.8 | 76.4 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50688 | 7.8 | 75.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-48359 | 9.6 | 75.3 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-611 | Adobe Experience Manager | Improper Restriction of XML External Entity Refere… |
| CVE-2026-50476 | 7.8 | 74.3 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Network Connections Service Elevation of Privilege Vulnerability |
| CVE-2026-55009 | 7.8 | 73.9 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-502 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-48358 | 9.1 | 71.8 | Adobe | Adobe Commerce | CWE-116 | Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116) |
| CVE-2026-48324 | 9.1 | 70.9 | Adobe | ColdFusion 2025 | CWE-89 | ColdFusion | Improper Neutralization of Special Elements used in an SQL Comma… |
| CVE-2026-62392 | 9.8 | 68.5 | Apache Software Foundation | Apache Kylin | CWE-78 | Apache Kylin: OS Command Injection via Async Query API |
| CVE-2026-54117 | 8.8 | 67.8 | Microsoft | Microsoft SQL Server 2025 (CU 6) | CWE-502 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-54118 | 8.8 | 67.8 | Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | CWE-502 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-55944 | 9.8 | 67.6 | Microsoft | Microsoft Dynamics NAV 2018 | CWE-502 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premis… |
| CVE-2026-57092 | 9.9 | 65.2 | Microsoft | Windows 10 Version 1607 | CWE-416 | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability |
| CVE-2026-50328 | 7.5 | 65.1 | Microsoft | Windows 10 Version 1607 | CWE-20 | Windows Server Update Service (WSUS) Tampering Vulnerability |
| CVE-2026-50652 | 7.5 | 64.2 | Microsoft | Azure Active Directory | CWE-502 | Azure Active Directory Denial of Service Vulnerability |
| CVE-2026-50496 | 7.5 | 63.6 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Network Policy Server SNMP Information Disclosure Vulnerability |
| CVE-2026-50330 | 9.8 | 63.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Remote Desktop Client Elevation of Privilege Vulnerability |
| CVE-2026-57108 | 7.5 | 63.0 | Microsoft | .NET 10.0 | CWE-843 | .NET Denial of Service Vulnerability |
| CVE-2026-56190 | 9.8 | 62.5 | Microsoft | Windows 10 Version 1607 | CWE-908 | Remote Desktop Protocol Remote Code Execution Vulnerability |
| CVE-2026-50304 | 7.5 | 62.2 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50355 | 7.5 | 62.2 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50647 | 7.5 | 62.2 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-835 | Active Directory Federation Server Denial of Service Vulnerability |
| CVE-2026-56186 | 6.5 | 61.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Secure Channel Information Disclosure Vulnerability |
| CVE-2026-54121 | 8.8 | 61.5 | Microsoft | Windows 10 Version 1607 | CWE-285 | Active Directory Certificate Services Elevation of Privilege Vulnerability |
| CVE-2026-14903 | 6.5 | 61.2 | ivanti | Xtraction | CWE-23 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote au… |
| CVE-2026-47302 | 7.5 | 60.8 | Microsoft | .NET 10.0 | CWE-770 | .NET Denial of Service Vulnerability |
| CVE-2026-56170 | 7.5 | 60.2 | Microsoft | .NET 10.0 | CWE-770 | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-15428 | 8.5 | 60.1 | TP-Link Systems Inc. | Archer VX1800v v1 | CWE-78 | OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer … |
| CVE-2026-56159 | 9.8 | 59.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-56196 | 8.8 | 58.5 | Microsoft | Windows Admin Center | CWE-23 | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-54116 | 6.5 | 58.4 | Microsoft | Microsoft SQL Server 2025 (CU 6) | CWE-843 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-57982 | 6.5 | 58.4 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-50646 | 7.8 | 58.3 | Microsoft | .NET 8.0 | CWE-502 | .NET Framework Remote Code Execution Vulnerability |
| CVE-2026-58529 | 7.1 | 58.2 | Microsoft | Windows 11 version 26H1 | CWE-125 | Windows Active Directory Federation Services (ADFS) Information Disclosure Vu… |
| CVE-2026-47295 | 8.8 | 57.4 | Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | CWE-89 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-56197 | 8.8 | 57.4 | Microsoft | Windows Admin Center | CWE-77 | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-47429 | 5.9 | 57.4 | vitest-dev | vitest | CWE-22 | Vitest: Arbitrary file can be read and executed when Vitest UI server is list… |
| CVE-2026-50649 | 7.8 | 57.3 | Microsoft | .NET 8.0 | CWE-502 | .NET Remote Code Execution Vulnerability |
| CVE-2026-56188 | 8.1 | 57.2 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Server Network driver Remote Code Execution Vulnerability |
| CVE-2026-50447 | 9.8 | 57.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-34348 | 6.5 | 56.9 | Microsoft | Windows 10 Version 1809 | CWE-693 | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-48322 | 9.9 | 56.7 | Adobe | ColdFusion 2025 | CWE-94 | ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94) |
| CVE-2026-58277 | 8.8 | 56.5 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-285 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-50682 | 7.1 | 56.4 | Microsoft | Windows 10 Version 21H2 | CWE-125 | Active Directory Denial of Service Vulnerability |
| CVE-2026-58627 | 7.5 | 55.9 | Microsoft | Windows 10 Version 1607 | CWE-400 | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-56642 | 8.8 | 55.8 | Microsoft | Service Fabric | CWE-121 | Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability |
| CVE-2026-50497 | 7.5 | 55.8 | Microsoft | Windows 10 Version 1607 | CWE-193 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-58533 | 7.5 | 55.8 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-58535 | 7.5 | 55.8 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-58539 | 7.5 | 55.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-50376 | 6.5 | 55.8 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-55034 | 8.7 | 55.7 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-56194 | 8.8 | 55.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NFS Server Elevation of Privilege Vulnerability |
| CVE-2026-56647 | 8.8 | 55.2 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerabi… |
| CVE-2026-58626 | 8.8 | 55.2 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2026-55008 | 9.6 | 55.1 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-79 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-15429 | 5.1 | 54.9 | TP-Link Systems Inc. | Archer VX1800v v1 | CWE-93 | Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v |
| CVE-2026-50527 | 7.5 | 54.9 | Microsoft | .NET 10.0 | CWE-121 | .NET Framework Denial of Service Vulnerability |
| CVE-2026-50648 | 7.5 | 54.9 | Microsoft | .NET 10.0 | CWE-770 | .NET Framework Denial of Service Vulnerability |
| CVE-2026-50651 | 7.5 | 54.9 | Microsoft | .NET 10.0 | CWE-770 | .NET Denial of Service Vulnerability |
| CVE-2026-57094 | 8.8 | 54.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-13001 | 9.8 | 54.5 | eteubert | Podlove Podcast Publisher | CWE-20 | Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload vi… |
| CVE-2026-40378 | 7.5 | 54.1 | Microsoft | Windows 10 Version 1607 | CWE-789 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service … |
| CVE-2026-44806 | 7.5 | 54.1 | Microsoft | Windows 10 Version 1607 | CWE-401 | Windows Secure Channel Denial of Service Vulnerability |
| CVE-2026-49787 | 7.5 | 54.1 | Microsoft | Windows 10 Version 1607 | CWE-770 | HTTP.sys Denial of Service Vulnerability |
| CVE-2026-50424 | 7.5 | 54.1 | Microsoft | Windows 11 Version 24H2 | CWE-822 | Windows Domain Controller Denial of Service Vulnerability |
| CVE-2026-50696 | 7.5 | 54.1 | Microsoft | Windows 10 Version 1809 | CWE-122 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
| CVE-2026-54119 | 7.5 | 54.1 | Microsoft | Windows 10 Version 1607 | CWE-835 | Windows Active Directory Denial of Service Vulnerability |
| CVE-2026-57090 | 9.8 | 54.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-45304 | 8.7 | 53.7 | symfony | symfony | CWE-776 | Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-A… |
| CVE-2026-45305 | 8.7 | 53.7 | symfony | symfony | CWE-1333 | Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup()… |
| CVE-2026-57087 | 7.8 | 53.6 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-50695 | 7.5 | 53.4 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-49181 | 9.8 | 53.4 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-49799 | 6.5 | 53.3 | Microsoft | Windows 10 Version 1607 | CWE-400 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service … |
| CVE-2026-56168 | 6.5 | 53.3 | Microsoft | Windows 10 Version 21H2 | CWE-476 | Windows SMB Server Denial of Service Vulnerability |
| CVE-2026-38450 | 9.8 | 53.1 | n/a | n/a | CWE-94 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote atta… |
| CVE-2026-15701 | 8.9 | 53.1 | Totolink | NR1800X | CWE-119 | Totolink NR1800X lighttpd formLogout.htm Form_Logout stack-based overflow |
| CVE-2026-50324 | 5.9 | 53.0 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-835 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-45646 | 7.5 | 52.9 | Microsoft | AspNet.OData | CWE-770 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-49788 | 7.5 | 52.9 | Microsoft | Windows 10 Version 1607 | CWE-770 | HTTP/2 Denial of Service Vulnerability |
| CVE-2026-50368 | 7.5 | 52.9 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50411 | 7.5 | 52.9 | Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-50506 | 7.5 | 52.9 | Microsoft | AspNet.OData | CWE-770 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-50653 | 7.5 | 52.9 | Microsoft | Azure Active Directory | CWE-400 | Azure Active Directory Denial of Service Vulnerability |
| CVE-2026-54983 | 7.5 | 52.9 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Active Directory Federation Services Denial of Service Vulnerability |
| CVE-2026-54108 | 6.5 | 52.8 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-73 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-50429 | 8.2 | 52.6 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-58594 | 9.8 | 52.5 | Microsoft | Windows 10 Version 1607 | CWE-190 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-57102 | 8.8 | 52.5 | Microsoft | Visual Studio Code | CWE-200 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-48561 | 9.6 | 52.4 | Microsoft | Microsoft Edge Copilot for Android | CWE-77 | Microsoft Edge Copilot Remote Code Execution Vulnerability |
| CVE-2026-48564 | 8.8 | 52.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-50366 | 6.5 | 52.1 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows Active Directory Domain Services Denial of Service Vulnerability |
| CVE-2026-57976 | 6.5 | 52.1 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows Active Directory Domain Services Denial of Service Vulnerability |
| CVE-2026-55010 | 9.8 | 51.6 | Microsoft | Minecraft Bedrock Dedicated Server | CWE-122 | Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability |
| CVE-2026-45133 | 8.2 | 51.6 | symfony | symfony | CWE-674 | Symfony: [Yaml] Harden the parser when handling untrusted input |
| CVE-2026-50487 | 9.8 | 51.5 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-50463 | 7.5 | 51.5 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50470 | 7.5 | 51.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Network Policy Server SNMP Information Disclosure Vulnerability |
| CVE-2026-58617 | 9.8 | 51.5 | Microsoft | Microsoft 365 Copilot for iOS | CWE-284 | M365 Copilot for iOS Elevation of Privilege Vulnerability |
| CVE-2026-47303 | 8.8 | 51.5 | Microsoft | .NET 10.0 | CWE-90 | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-50661 | 4.6 | 51.0 | Microsoft | Windows 10 Version 1607 | CWE-693 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-48345 | 8.2 | 50.7 | Adobe | Adobe Animate 2023 | CWE-78 | Animate | Improper Neutralization of Special Elements used in an OS Command (… |
| CVE-2026-50468 | 6.5 | 50.7 | Microsoft | Microsoft SQL Server 2025 (CU 6) | CWE-126 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-59837 | 6.6 | 50.4 | Fortinet | FortiPAM | CWE-121 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through… |
| CVE-2026-40400 | 8.0 | 50.2 | Microsoft | Windows 10 Version 1607 | CWE-23 | Windows PowerShell Remote Code Execution Vulnerability |
| CVE-2026-24227 | 9.8 | 50.0 | NVIDIA | TensorRT | CWE-502 | NVIDIA TensorRT for contains a vulnerability where a user might cause a deser… |
| CVE-2026-50500 | 8.8 | 49.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Netlogon Elevation of Privilege Vulnerability |
| CVE-2026-27690 | 9.1 | 49.7 | SAP_SE | SAP Approuter | CWE-444 | HTTP Request Smuggling in SAP Approuter |
| CVE-2026-48259 | 9.6 | 49.5 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-918 | Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-50369 | 8.8 | 49.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-47301 | 8.8 | 49.4 | Microsoft | Microsoft Configuration Manager | CWE-284 | Configuration Manager Elevation of Privilege Vulnerability |
| CVE-2026-50663 | 8.8 | 49.4 | Microsoft | Age of Empires II: Definitive Edition Game | CWE-23 | Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability |
| CVE-2026-42990 | 9.8 | 49.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | SQL Server ODBC driver Elevation of Privilege Vulnerability |
| CVE-2026-49172 | 9.8 | 49.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows FTP Service Remote Code Execution Vulnerability |
| CVE-2026-47988 | 8.6 | 48.9 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-55005 | 8.8 | 48.8 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-122 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-50694 | 9.8 | 48.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnera… |
| CVE-2026-50432 | 6.5 | 48.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability |
| CVE-2026-50686 | 8.1 | 48.6 | Microsoft | Windows 10 Version 1607 | CWE-843 | Windows OLE Remote Code Execution Vulnerability |
| CVE-2026-55021 | 8.7 | 48.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-56649 | 8.1 | 48.3 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Network File System Remote Code Execution Vulnerability |
| CVE-2026-50445 | 7.5 | 48.3 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-57979 | 7.5 | 48.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-54126 | 6.5 | 48.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-55003 | 6.5 | 48.3 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-49164 | 9.8 | 48.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-55052 | 8.8 | 48.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-862 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-53486 | 9.1 | 47.8 | XhmikosR | decompress | CWE-22 | decompress: Archive extraction can create files and links outside the target … |
| CVE-2026-46633 | 8.7 | 47.8 | twigphp | Twig | CWE-94 | Twig: PHP code injection via `{% use %}` template name |
| CVE-2026-47984 | 8.2 | 47.7 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-50524 | 7.5 | 47.5 | Microsoft | .NET 10.0 | CWE-1287 | .NET Framework Denial of Service Vulnerability |
| CVE-2026-47998 | 5.9 | 47.4 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-55051 | 6.5 | 47.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-918 | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-50380 | 9.6 | 47.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-55054 | 6.5 | 47.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-47994 | 8.7 | 46.9 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-50504 | 7.5 | 46.9 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-15669 | 1.9 | 46.9 | louisho5 | picobot | CWE-77 | louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection |
| CVE-2026-50685 | 7.5 | 46.8 | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-45067 | 6.3 | 46.8 | symfony | symfony | CWE-93 | Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\… |
| CVE-2026-49178 | 8.8 | 46.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-50666 | 8.8 | 46.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Remote Access Elevation of Privilege Vulnerability |
| CVE-2026-55002 | 8.8 | 46.7 | Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | CWE-73 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-50415 | 7.5 | 46.7 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Media Information Disclosure Vulnerability |
| CVE-2026-48068 | 7.5 | 46.7 | grpc | grpc-node | CWE-248 | @grpc/grps-js: A malformed request can cause a server crash |
| CVE-2026-48069 | 7.5 | 46.7 | grpc | grpc-node | CWE-248 | @grpc/grps-js: An incoming malformed compressed message can cause a client or… |
| CVE-2026-50474 | 8.8 | 46.4 | Microsoft | Windows 10 Version 1607 | CWE-416 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-47282 | 6.5 | 46.4 | Microsoft | Visual Studio Code | CWE-200 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-57089 | 9.8 | 46.3 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Executio… |
| CVE-2026-50444 | 8.8 | 46.0 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability |
| CVE-2026-50525 | 7.5 | 46.1 | Microsoft | .NET 10.0 | CWE-770 | .NET Denial of Service Vulnerability |
| CVE-2026-56185 | 6.5 | 46.0 | Microsoft | Windows Admin Center | CWE-94 | Windows Admin Center Information Disclosure Vulnerability |
| CVE-2026-50502 | 8.8 | 45.9 | Microsoft | Windows 10 Version 1607 | CWE-1220 | Windows Event Logging Service Remote Code Execution Vulnerability |
| CVE-2026-58531 | 7.5 | 45.8 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows SMB Elevation of Privilege Vulnerability |
| CVE-2026-45756 | 8.2 | 45.8 | symfony | symfony | CWE-400 | Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match(… |
| CVE-2026-54995 | 9.8 | 45.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vu… |
| CVE-2026-53633 | 9.8 | 44.8 | vitest-dev | vitest | CWE-749 | Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Le… |
| CVE-2026-55033 | 7.8 | 44.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-49855 | 7.5 | 44.6 | tornadoweb | tornado | CWE-409 | tornado AsyncHTTPClient accumulates decompressed chunks without size limit (g… |
| CVE-2026-48001 | 3.7 | 44.2 | Adobe | Adobe Commerce | CWE-200 | Adobe Commerce | Information Exposure (CWE-200) |
| CVE-2026-15427 | 8.6 | 43.5 | TP-Link Systems Inc. | Archer VX1800v v1 | CWE-78 | OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer … |
| CVE-2026-50528 | 8.2 | 43.5 | Microsoft | .NET 10.0 | CWE-302 | .NET Security Feature Bypass Vulnerability |
| CVE-2026-50659 | 6.5 | 43.4 | Microsoft | .NET 10.0 | CWE-116 | .NET Spoofing Vulnerability |
| CVE-2026-55019 | 5.4 | 43.4 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55030 | 5.4 | 43.4 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-15709 | 7.5 | 43.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-409 | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate… |
| CVE-2026-54990 | 8.8 | 43.2 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-48347 | 7.7 | 43.2 | Adobe | Adobe Animate 2023 | CWE-78 | Animate | Improper Neutralization of Special Elements used in an OS Command (… |
| CVE-2026-55023 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55027 | 5.5 | 43.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-3014 | 6.4 | 42.9 | Milestone Systems | XProtect Management Server | CWE-78 | Remote Code Execution by administrative user on the Management Server |
| CVE-2026-50475 | 5.5 | 42.7 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50439 | 9.8 | 42.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability |
| CVE-2026-55047 | 5.5 | 42.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-44747 | 9.9 | 42.5 | SAP_SE | SAP NetWeaver Application Server ABAP | CWE-787 | Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP |
| CVE-2026-55126 | 5.4 | 42.5 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-49488 | 6.5 | 42.4 | Apache Software Foundation | Apache OpenMeetings | CWE-22 | Apache OpenMeetings: Arbitrary File Read |
| CVE-2026-50414 | 8.8 | 42.4 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-48328 | 7.7 | 42.3 | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-47300 | 8.8 | 42.2 | Microsoft | .NET 10.0 | CWE-303 | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-57969 | 8.8 | 42.2 | Microsoft | Azure CycleCloud 8.9.1 | CWE-306 | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-50360 | 8.8 | 42.2 | Microsoft | Windows 10 Version 21H2 | CWE-303 | Windows SMB Server Elevation of Privilege Vulnerability |
| CVE-2026-55035 | 3.3 | 42.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-49476 | 7.5 | 41.9 | facelessuser | soupsieve | CWE-400 | Soup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in sou… |
| CVE-2026-49477 | 7.5 | 41.9 | facelessuser | soupsieve | CWE-400 | Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selecto… |
| CVE-2026-57084 | 5.5 | 41.7 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-48325 | 9.3 | 41.3 | Adobe | ColdFusion 2025 | CWE-306 | ColdFusion | Missing Authentication for Critical Function (CWE-306) |
| CVE-2026-49169 | 8.8 | 41.1 | Microsoft | Windows Server 2025 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-58319 | 9.1 | 41.1 | Apache Software Foundation | Apache Doris | CWE-306 | Apache Doris: Improper Authentication in Frontend HTTP API |
| CVE-2026-59084 | 9.1 | 40.9 | Apache Software Foundation | Apache Tomcat | CWE-1059 | Apache Tomcat: EncryptInterceptor requirements not clearly documented |
| CVE-2026-56169 | 8.8 | 40.9 | Microsoft | Windows Admin Center | CWE-287 | Windows Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-48310 | 8.6 | 40.9 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-22 | Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted … |
| CVE-2026-50460 | 8.1 | 40.9 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50655 | 7.8 | 40.9 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-58546 | 6.5 | 40.7 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-50340 | 8.8 | 40.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50505 | 8.8 | 40.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-15712 | 5.9 | 40.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap… |
| CVE-2026-47296 | 7.5 | 40.4 | Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | CWE-89 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-15764 | 7.5 | 40.2 | Google | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 all… |
| CVE-2026-15765 | 7.5 | 40.2 | Google | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a re… |
| CVE-2026-57083 | 5.5 | 40.3 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Media Photo Codec Information Disclosure Vulnerability |
| CVE-2026-50370 | 8.8 | 40.2 | Microsoft | Windows 10 Version 1607 | CWE-20 | DHCP Server Service Remote Code Execution Vulnerability |
| CVE-2026-55038 | 7.8 | 40.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-50683 | 8.0 | 39.9 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-58528 | 4.6 | 39.9 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-51808 | 9.8 | 39.3 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an atta… |
| CVE-2026-54058 | 8.3 | 39.1 | python-pillow | Pillow | CWE-125 | Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mma… |
| CVE-2026-15695 | 7.4 | 39.1 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro DhcpListClient fromDhcpListClient stack-based overflow |
| CVE-2026-48489 | 8.7 | 39.0 | symfony | symfony | CWE-863 | Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthentic… |
| CVE-2026-50416 | 3.3 | 39.0 | Microsoft | Windows 11 Version 24H2 | CWE-200 | Win32k Information Disclosure Vulnerability |
| CVE-2026-56648 | 7.5 | 39.0 | Microsoft | Windows 10 Version 1607 | CWE-367 | Windows NFS Server Elevation of Privilege Vulnerability |
| CVE-2026-48321 | 9.3 | 38.7 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-49176 | 7.8 | 38.7 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows WalletService Elevation of Privilege Vulnerability |
| CVE-2026-54992 | 7.8 | 38.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability |
| CVE-2026-50338 | 8.2 | 38.6 | Microsoft | Azure Spring Apps | CWE-287 | Azure Spring Apps Elevation of Privilege Vulnerability |
| CVE-2026-15691 | 7.4 | 38.4 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow |
| CVE-2026-15692 | 7.4 | 38.4 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro SafeUrlFilter fromSafeUrlFilter stack-based overflow |
| CVE-2026-15693 | 7.4 | 38.4 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow |
| CVE-2026-15694 | 7.4 | 38.4 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro SetIpBind fromSetIpBind stack-based overflow |
| CVE-2026-15696 | 7.4 | 38.4 | Tenda | BE12 Pro | CWE-119 | Tenda BE12 Pro VirtualSer fromVirtualSer stack-based overflow |
| CVE-2026-44761 | 9.1 | 38.4 | SAP_SE | SAP Commerce Cloud | CWE-1392 | Insecure Sample Credentials in SAP Commerce Cloud |
| CVE-2026-15265 | 9.4 | 38.2 | tenable | tenable_agent | CWE-22 | Tenable Agent Path Traversal Leading to Remote Code Execution |
| CVE-2026-45071 | 8.7 | 38.1 | symfony | symfony | CWE-611 | Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via valid… |
| CVE-2026-55132 | 7.8 | 38.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-415 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-59835 | 8.6 | 38.0 | Fortinet | FortiSandbox | CWE-668 | A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox… |
| CVE-2026-48736 | 6.9 | 38.1 | symfony | symfony | CWE-184 | Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, T… |
| CVE-2026-58595 | 8.1 | 38.0 | Microsoft | Microsoft Bing Search for iOS | CWE-1021 | Microsoft Bing App for IOS Spoofing Vulnerability |
| CVE-2026-50365 | 8.0 | 38.0 | Microsoft | Windows 10 Version 1607 | CWE-287 | Remote Access Management service/API (RPC server) Elevation of Privilege Vuln… |
| CVE-2026-48580 | 5.5 | 38.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55046 | 5.5 | 38.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-50352 | 5.5 | 37.9 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Cryptographic Services Information Disclosure Vulnerability |
| CVE-2026-50389 | 5.5 | 37.9 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50431 | 5.5 | 37.9 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vuln… |
| CVE-2026-50681 | 5.5 | 37.9 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Secure Channel Information Disclosure Vulnerability |
| CVE-2026-56184 | 5.5 | 37.9 | Microsoft | Windows 10 Version 21H2 | CWE-200 | Win32k Information Disclosure Vulnerability |
| CVE-2026-57095 | 7.8 | 37.8 | Microsoft | Windows 10 Version 1607 | CWE-200 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-5270 | 9.8 | 37.5 | CIENA | Navigator NCS | CWE-287 | Authentication Bypass in Navigator and Blue Planet Products |
| CVE-2026-57898 | 9.0 | 37.2 | Eclipse Foundation | Eclipse BaSyx - Java Server SDK | CWE-22 | In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milesto… |
| CVE-2026-45077 | 8.3 | 37.2 | symfony | symfony | CWE-502 | Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:l… |
| CVE-2026-58613 | 7.8 | 37.2 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-48125 | 5.3 | 37.0 | faisalman | ua-parser-js | CWE-400 | UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withCl… |
| CVE-2026-57101 | 6.1 | 36.8 | Microsoft | Visual Studio Code | CWE-79 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-50454 | 7.8 | 36.6 | Microsoft | Windows 11 Version 24H2 | CWE-23 | Windows User Interface Core Elevation of Privilege Vulnerability |
| CVE-2026-50314 | 7.8 | 36.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-50657 | 5.5 | 36.4 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-359 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
| CVE-2026-59197 | 8.2 | 36.3 | python-pillow | Pillow | CWE-190 | Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integ… |
| CVE-2026-50313 | 7.8 | 36.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50347 | 7.8 | 36.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Data.dll Remote Code Execution Vulnerability |
| CVE-2026-50388 | 7.8 | 36.2 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-54124 | 7.8 | 36.2 | Microsoft | Windows 10 Version 21H2 | CWE-122 | Windows Terminal Remote Code Execution Vulnerability |
| CVE-2026-15776 | 8.8 | 35.9 | Google | Chrome | CWE-843 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 a… |
| CVE-2026-15711 | 7.5 | 35.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service… |
| CVE-2026-14902 | 6.1 | 35.8 | ivanti | Xtraction | CWE-601 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote … |
| CVE-2026-15767 | 8.8 | 35.5 | Google | Chrome | CWE-122 | Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.787… |
| CVE-2026-50485 | 5.7 | 35.5 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2026-58608 | 7.5 | 35.4 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Print Spooler Remote Code Execution Vulnerability |
| CVE-2026-59733 | 8.8 | 35.2 | rclone | rclone | CWE-22 | rclone `serve restic --private-repos` authorization bypass: `..` in the URL p… |
| CVE-2026-55028 | 5.5 | 35.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55050 | 5.5 | 35.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-55124 | 5.5 | 35.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-55142 | 5.5 | 35.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-197 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-56192 | 5.5 | 35.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-46634 | 7.7 | 35.0 | twigphp | Twig | CWE-693 | Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synt… |
| CVE-2026-55127 | 7.8 | 34.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45074 | 7.6 | 34.4 | symfony | symfony | CWE-290 | Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-… |
| CVE-2026-55016 | 5.4 | 34.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55020 | 5.4 | 34.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55135 | 5.4 | 34.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-55954 | 9.1 | 34.2 | ueberauth | ueberauth_apple | CWE-290 | Missing ID token claim validation in ueberauth_apple allows account takeover |
| CVE-2025-56361 | 7.5 | 34.2 | n/a | n/a | CWE-617 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip… |
| CVE-2026-55026 | 5.5 | 34.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-45073 | 6.3 | 34.1 | symfony | symfony | CWE-89 | Symfony: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix |
| CVE-2026-62390 | 9.8 | 34.1 | Apache Software Foundation | Apache Kylin | CWE-89 | Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API |
| CVE-2026-50492 | 6.8 | 34.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-45068 | 8.7 | 33.9 | symfony | symfony | CWE-88 | Symfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient … |
| CVE-2026-48351 | 7.5 | 33.9 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-48352 | 7.5 | 33.9 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-10672 | 9.1 | 33.8 | zephyrproject | zephyr | CWE-125 | Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Pac… |
| CVE-2026-46640 | 8.7 | 33.7 | twigphp | Twig | CWE-94 | Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference com… |
| CVE-2026-47290 | 7.8 | 33.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-47642 | 7.8 | 33.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-48334 | 9.3 | 33.2 | Adobe | Illustrator Desktop 2026 | CWE-20 | Illustrator | Improper Input Validation (CWE-20) |
| CVE-2026-59203 | 7.5 | 33.1 | python-pillow | Pillow | CWE-835 | Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop … |
| CVE-2026-47995 | 8.1 | 32.9 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-14645 | 5.1 | 32.9 | Sonatype | Nexus Repository 3 | CWE-918 | Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global C… |
| CVE-2026-56189 | 8.4 | 32.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-46644 | 6.9 | 32.6 | symfony | polyfill | CWE-1289 | symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes … |
| CVE-2026-59204 | 8.7 | 32.5 | python-pillow | Pillow | CWE-770 | Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used… |
| CVE-2026-55024 | 7.8 | 32.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55031 | 7.8 | 32.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-50398 | 7.5 | 32.4 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50462 | 7.8 | 32.4 | Microsoft | Windows 10 Version 1607 | CWE-73 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-15714 | 6.5 | 32.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multip… |
| CVE-2026-52101 | 9.1 | 32.1 | n/a | n/a | CWE-200 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote at… |
| CVE-2026-47767 | 8.3 | 32.1 | symfony | symfony | CWE-436 | Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still S… |
| CVE-2026-42900 | 8.1 | 32.1 | Microsoft | Windows 10 Version 1607 | CWE-362 | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-49796 | 7.8 | 32.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-48295 | 7.5 | 32.0 | Adobe | Content Credentials Rust SDK | CWE-522 | CAI Content Credentials | Insufficiently Protected Credentials (CWE-522) |
| CVE-2026-47428 | 9.6 | 31.9 | vitest-dev | vitest | CWE-79 | Vitest browser mode serves unsanitized otelCarrier query parameter as inline … |
| CVE-2026-15043 | 9.8 | 31.8 | HMBRAND | DBI::SQL::Nano | CWE-480 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and … |
| CVE-2026-60082 | 9.1 | 31.8 | HMBRAND | DBI | CWE-125 | DBI versions before 1.651 for Perl do not enforce statement handle consistenc… |
| CVE-2026-58635 | 7.8 | 31.8 | Microsoft | Windows 10 Version 1809 | CWE-77 | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-50690 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows SMB Information Disclosure Vulnerability |
| CVE-2025-53379 | 7.5 | 31.7 | Fortinet | FortiAuthenticator | CWE-125 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 throu… |
| CVE-2026-59199 | 7.5 | 31.7 | python-pillow | Pillow | CWE-787 | Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed … |
| CVE-2026-59200 | 7.5 | 31.7 | python-pillow | Pillow | CWE-400 | Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() |
| CVE-2026-59205 | 7.5 | 31.7 | python-pillow | Pillow | CWE-787 | Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` vi… |
| CVE-2026-46627 | 7.1 | 31.6 | twigphp | Twig | CWE-400 | Twig: Sandbox resource exhaustion via unbounded `for` / `range()` |
| CVE-2026-49458 | 6.1 | 31.5 | cure53 | DOMPurify | CWE-79 | DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact … |
| CVE-2026-45075 | 8.3 | 31.4 | symfony | symfony | CWE-863 | Symfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[Is… |
| CVE-2026-50377 | 7.8 | 31.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-15766 | 6.5 | 31.3 | Google | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a … |
| CVE-2026-15770 | 6.5 | 31.3 | Google | Chrome | CWE-457 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a re… |
| CVE-2026-55042 | 5.5 | 31.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-55057 | 5.5 | 31.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-56195 | 5.5 | 31.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-15718 | 4.3 | 31.2 | Mozilla | Firefox | CWE-763 | Invalid pointer in the JavaScript: WebAssembly component |
| CVE-2026-54982 | 8.8 | 31.1 | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vu… |
| CVE-2026-50420 | 5.5 | 31.2 | Microsoft | Windows 11 Version 24H2 | CWE-125 | HTTP.sys Information Disclosure Vulnerability |
| CVE-2026-60081 | 7.5 | 31.1 | HMBRAND | DBI::ProfileData | CWE-770 | DBI::ProfileData versions before 1.651 for Perl do not limit the path index |
| CVE-2025-56363 | 7.5 | 30.9 | n/a | n/a | CWE-476 | A null pointer dereference vulnerability exists in the Matter SDK (connectedh… |
| CVE-2026-55022 | 7.8 | 30.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-11944 | 5.3 | 30.8 | OS4ED | openSIS-Classic | CWE-22 | openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment dow… |
| CVE-2026-55011 | 7.8 | 30.5 | Microsoft | Microsoft Malware Protection Engine | CWE-191 | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2026-55012 | 7.8 | 30.5 | Microsoft | Microsoft Malware Protection Engine | CWE-122 | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2026-49807 | 6.2 | 30.5 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows DirectX Information Disclosure Vulnerability |
| CVE-2026-50294 | 6.2 | 30.5 | Microsoft | Windows 10 Version 1607 | CWE-497 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-15738 | 5.8 | 30.4 | Amazon | aws-load-balancer-controller | CWE-653 | Cross-namespace traffic interception via incorrect route precedence ordering … |
| CVE-2026-15773 | 9.6 | 30.3 | Google | Chrome | CWE-416 | Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 al… |
| CVE-2026-50684 | 4.8 | 30.4 | Microsoft | Windows 10 Version 1607 | CWE-79 | Active Directory Federation Server Spoofing Vulnerability |
| CVE-2026-51807 | 9.8 | 30.2 | n/a | n/a | CWE-121 | Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header()… |
| CVE-2026-48327 | 9.0 | 30.2 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-15720 | 8.6 | 30.2 | open5gs | open5gs | CWE-125 | Pre-auth heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler |
| CVE-2026-48252 | 8.6 | 30.2 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-306 | Adobe Experience Manager | Missing Authentication for Critical Function (CWE-… |
| CVE-2026-55032 | 7.8 | 30.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55055 | 7.8 | 30.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55125 | 7.8 | 30.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55128 | 7.8 | 30.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55130 | 7.8 | 30.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-55134 | 7.8 | 30.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-59083 | 9.1 | 30.1 | Apache Software Foundation | Apache Tomcat | CWE-177 | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security cont… |
| CVE-2026-55145 | 7.1 | 30.2 | Microsoft | Microsoft Copilot | CWE-77 | Outlook Copilot Tampering Vulnerability |
| CVE-2026-60114 | 8.7 | 29.9 | Dan-in-CA | SIP | CWE-22 | Sustainable Irrigation Platform 5.2.16 Path Traversal via JSON Backup Restore |
| CVE-2026-49853 | 7.7 | 29.6 | tornadoweb | tornado | CWE-200 | Tornado: Authorization header forwarded across cross-origin redirects in Simp… |
| CVE-2026-50379 | 7.5 | 29.6 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-56193 | 3.3 | 29.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-50453 | 4.6 | 29.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-15700 | 2.0 | 29.4 | n/a | DedeCMS | CWE-22 | DedeCMS Album Publishing Feature zip.class.php ExtractFile path traversal |
| CVE-2025-56365 | 7.5 | 29.3 | n/a | n/a | CWE-617 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip… |
| CVE-2026-58279 | 6.5 | 29.3 | Microsoft | Azure CycleCloud 8.9.1 | CWE-862 | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-55121 | 5.5 | 29.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-50489 | 7.8 | 29.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-57091 | 7.8 | 29.2 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows File History Service Elevation of Privilege Vulnerability |
| CVE-2026-55045 | 8.4 | 29.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-49797 | 7.8 | 29.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50308 | 7.8 | 29.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-47732 | 7.1 | 29.1 | twigphp | Twig | CWE-863 | Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string co… |
| CVE-2026-49804 | 6.6 | 29.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows USB Video Driver Elevation of Privilege Vulnerability |
| CVE-2026-50426 | 6.8 | 29.0 | Microsoft | Windows 10 Version 1607 | CWE-23 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-15715 | 2.1 | 29.0 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System exam.php cross site scripting |
| CVE-2026-58477 | 8.8 | 28.8 | Dan-in-CA | SIP | CWE-915 | Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters |
| CVE-2026-45496 | 5.5 | 28.8 | Microsoft | Visual Studio Code | CWE-22 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-56157 | 5.4 | 28.7 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-284 | Microsoft SharePoint Server Spoofing Vulnerability |