| CVE-2026-15771 | 5.3 | 28.7 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome on Windo… |
| CVE-2026-34349 | 5.5 | 28.5 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Media Information Disclosure Vulnerability |
| CVE-2026-50394 | 5.5 | 28.5 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Media Information Disclosure Vulnerability |
| CVE-2026-48801 | 8.7 | 28.3 | markdown-it | linkify-it | CWE-1333 | linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop |
| CVE-2026-58547 | 7.8 | 28.4 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vul… |
| CVE-2026-48000 | 6.1 | 28.4 | Adobe | Adobe Commerce | CWE-601 | Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) |
| CVE-2026-15622 | 5.5 | 28.3 | poco-ai | poco-claw | CWE-285 | poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization |
| CVE-2026-33842 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-34328 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Audio Service Information Disclosure Vulnerability |
| CVE-2026-41087 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50316 | 5.5 | 28.4 | Microsoft | Windows 10 Version 21H2 | CWE-532 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-50334 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50339 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1809 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50350 | 5.5 | 28.4 | Microsoft | Windows 10 Version 21H2 | CWE-200 | Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability |
| CVE-2026-50409 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Overlay Filter Information Disclosure Vulnerability |
| CVE-2026-50430 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50434 | 5.5 | 28.4 | Microsoft | Windows 10 Version 21H2 | CWE-200 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-50442 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50456 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50473 | 5.5 | 28.4 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-50402 | 7.8 | 28.3 | Microsoft | Windows 10 Version 1607 | CWE-126 | NTFS Elevation of Privilege Vulnerability |
| CVE-2026-52837 | 6.9 | 28.3 | alextselegidis | easyappointments | CWE-200 | Easy!Appointments has unauthenticated customer PII disclosure on booking resc… |
| CVE-2026-46639 | 7.1 | 28.2 | twigphp | Twig | CWE-693 | Twig: Sandbox property and method bypass via object-destructuring assignment |
| CVE-2026-50665 | 3.3 | 28.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-11403 | 8.7 | 28.0 | Sonatype | Nexus Repository Manager | CWE-331 | Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Ge… |
| CVE-2026-59884 | 7.5 | 28.0 | pyasn1 | pyasn1 | CWE-400 | pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs |
| CVE-2026-15713 | 5.9 | 27.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-772 | Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of … |
| CVE-2026-55043 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-55120 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-55123 | 7.8 | 27.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-45754 | 6.9 | 27.8 | symfony | symfony | CWE-287 | Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret —… |
| CVE-2026-58647 | 5.4 | 27.9 | Microsoft | Power BI Report Server | CWE-79 | Microsoft PowerBI Report Server Spoofing Vulnerability |
| CVE-2026-50327 | 7.8 | 27.7 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Media Remote Code Execution Vulnerability |
| CVE-2026-50332 | 7.8 | 27.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-47736 | 7.5 | 27.6 | puma | puma | CWE-400 | Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion |
| CVE-2026-59889 | 6.5 | 27.6 | FasterXML | jackson-databind | CWE-863 | jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties o… |
| CVE-2026-49794 | 4.6 | 27.6 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-50408 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-55138 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-47476 | 7.5 | 27.3 | NVIDIA | Triton Inference Server | CWE-400 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-50364 | 7.3 | 27.3 | Microsoft | Windows 10 Version 21H2 | CWE-59 | Windows Backup Service Elevation of Privilege Vulnerability |
| CVE-2026-50680 | 7.8 | 27.1 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-58542 | 7.8 | 27.1 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Media Remote Code Execution Vulnerability |
| CVE-2026-50467 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55018 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55049 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55056 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55129 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55140 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55139 | 3.3 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-42975 | 8.8 | 26.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Bluetooth Port Driver Remote Code Execution |
| CVE-2026-15719 | 5.4 | 26.8 | Mozilla | Firefox | — | Site isolation issue in the DOM: Navigation component |
| CVE-2026-50501 | 7.8 | 26.7 | Microsoft | Windows 11 Version 24H2 | CWE-121 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-58530 | 7.8 | 26.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2025-56362 | 7.5 | 26.8 | n/a | n/a | CWE-617 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip… |
| CVE-2026-50483 | 5.5 | 26.7 | Microsoft | Windows 11 Version 24H2 | CWE-200 | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2026-49854 | 5.3 | 26.7 | tornadoweb | tornado | CWE-126 | Tornado: Out-of-bounds memory access in C extension |
| CVE-2026-50419 | 3.3 | 26.7 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-15702 | 2.1 | 26.7 | n/a | tamagui | CWE-94 | tamagui config.ts updateConfig prototype pollution |
| CVE-2026-50348 | 8.1 | 26.5 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2025-43892 | 4.3 | 26.5 | Fortinet | FortiOS | CWE-126 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, For… |
| CVE-2026-47305 | 7.8 | 26.5 | Microsoft | Microsoft Visual Studio 2022 version 17.12 | CWE-693 | Visual Studio Remote Code Execution Vulnerability |
| CVE-2026-50362 | 7.8 | 26.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-50386 | 7.8 | 26.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50448 | 7.8 | 26.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50461 | 7.8 | 26.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-54993 | 7.8 | 26.4 | Microsoft | Windows 10 Version 1809 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-56156 | 7.8 | 26.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-59885 | 7.5 | 26.4 | pyasn1 | pyasn1 | CWE-400 | pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing… |
| CVE-2026-59886 | 7.5 | 26.4 | pyasn1 | pyasn1 | CWE-400 | pyasn1: Uncontrolled resource consumption when converting decoded REAL values |
| CVE-2026-55122 | 7.1 | 26.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-49978 | 6.3 | 26.3 | cure53 | DOMPurify | CWE-79 | DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <templ… |
| CVE-2026-44745 | 8.1 | 26.0 | SAP_SE | SAP Approuter | CWE-601 | Open Redirect vulnerability in SAP Approuter |
| CVE-2025-56364 | 7.5 | 26.0 | n/a | n/a | CWE-457 | A use of uninitialized value vulnerability exists in the Matter SDK (connecte… |
| CVE-2026-45063 | 9.1 | 25.8 | symfony | symfony | CWE-290 | Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator |
| CVE-2026-36214 | 6.4 | 25.8 | osTicket | osTicket | CWE-79 | osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vul… |
| CVE-2026-15697 | 2.1 | 25.9 | svgdotjs | svg.js | CWE-94 | svgdotjs svg.js npm Package API EventTarget.on prototype pollution |
| CVE-2026-62422 | 9.8 | 25.7 | JetBrains | YouTrack | CWE-306 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025… |
| CVE-2026-9292 | 8.4 | 25.8 | Rockwell Automation | FactoryTalk® DataMosaix™ Private Cloud | CWE-79 | Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Sit… |
| CVE-2026-15703 | 5.5 | 25.7 | SourceCodester | Simple and Nice Shopping Cart Script | CWE-74 | SourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.ph… |
| CVE-2026-50312 | 7.8 | 25.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-50298 | 6.8 | 25.5 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Spaceport.sys Elevation of Privilege Vulnerability |
| CVE-2026-50299 | 6.8 | 25.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Storage Spaces Direct Remote Code Execution Vulnerability |
| CVE-2026-49177 | 5.5 | 25.6 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows TCP/IP Information Disclosure Vulnerability |
| CVE-2026-12583 | 8.1 | 25.4 | Unknown | Newsletters | CWE-502 | Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Cust… |
| CVE-2026-50675 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-49180 | 5.5 | 25.3 | Microsoft | Windows 10 Version 1607 | CWE-59 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
| CVE-2026-15777 | 7.5 | 25.2 | Google | Chrome | CWE-416 | Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowe… |
| CVE-2026-11917 | 7.2 | 25.2 | Rockwell Automation | FactoryTalk ThinManager | CWE-22 | ThinManager® - Path Traversal via API |
| CVE-2026-50374 | 6.8 | 25.1 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-57097 | 6.8 | 24.9 | Microsoft | Windows 10 Version 1607 | CWE-426 | Microsoft XML Security Feature Bypass Vulnerability |
| CVE-2026-12659 | 8.7 | 24.8 | Rockwell Automation | The FLEX 5000® EtherNet/IP Adapter | CWE-415 | Rockwell Automation Flex 5000® Adapter - Denial of Service |
| CVE-2026-51105 | 7.5 | 24.6 | n/a | n/a | CWE-121 | Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote … |
| CVE-2026-15778 | 6.5 | 24.6 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Navigation in Google Chrome pri… |
| CVE-2026-59891 | 9.6 | 24.4 | sigstore | sigstore-js | CWE-522 | Credential confusion in @sigstore/oci can leak registry credentials to an att… |
| CVE-2026-50692 | 8.8 | 24.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-50477 | 7.8 | 24.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50687 | 7.8 | 24.5 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-58534 | 7.8 | 24.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability |
| CVE-2026-50678 | 3.3 | 24.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-58233 | 7.6 | 24.2 | SAP_SE | SAP Change and Transport System Attach Tool (ctsattach) | CWE-502 | Remote Code Execution vulnerability in SAP Change and Transport System Attach… |
| CVE-2026-47632 | 8.8 | 24.0 | Microsoft | Azure Connected Machine Agent | CWE-295 | Azure Connected Machine Agent Elevation of Privilege Vulnerability |
| CVE-2026-58633 | 7.8 | 24.0 | Microsoft | Windows 11 version 26H1 | CWE-416 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-52100 | 7.5 | 24.1 | n/a | n/a | CWE-352 | Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 th… |
| CVE-2026-59198 | 7.5 | 24.0 | python-pillow | Pillow | CWE-125 | Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into … |
| CVE-2026-23573 | 6.1 | 24.0 | Fortinet | FortiOS | CWE-79 | An Improper Neutralization of Input During Web Page Generation ('Cross-site S… |
| CVE-2026-54433 | 10.0 | 23.9 | Roundcube | Webmail | CWE-79 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cr… |
| CVE-2026-8590 | 8.7 | 23.9 | Spotfire | Spotfire Enterprise | — | Spotfire OAuth2 PKCE Bypass for public clients |
| CVE-2026-58609 | 7.8 | 24.0 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-58610 | 7.8 | 24.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2026-50315 | 7.8 | 23.7 | Microsoft | Windows 11 Version 24H2 | CWE-476 | Windows Image Acquisition Elevation of Privilege Vulnerability |
| CVE-2026-50326 | 7.8 | 23.7 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Unified Consent System Elevation of Privilege Vulnerability |
| CVE-2026-50336 | 7.8 | 23.7 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50337 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-704 | Windows Notification Elevation of Privilege Vulnerability |
| CVE-2026-50353 | 7.8 | 23.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50357 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50363 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-50407 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50412 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50417 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-20 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50421 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-843 | Windows Connected User Experiences and Telemetry Elevation of Privilege Vulne… |
| CVE-2026-50422 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50478 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50479 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1809 | CWE-822 | Windows USB Hub Driver Elevation of Privilege Vulnerability |
| CVE-2026-50484 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50493 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1809 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50494 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50679 | 7.8 | 23.7 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows Search Service Elevation of Privilege Vulnerability |
| CVE-2026-54115 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
| CVE-2026-56175 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-56643 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-56644 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-56650 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Network File System Elevation of Privilege Vulnerability |
| CVE-2026-57096 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulne… |
| CVE-2026-57968 | 7.8 | 23.8 | Microsoft | Windows Subsystem for Linux (WSL2) | CWE-126 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58532 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58537 | 7.8 | 23.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnera… |
| CVE-2026-58538 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Bluetooth Service Elevation of Privilege Vulnerability |
| CVE-2026-11802 | 5.3 | 23.8 | themelooks | FoodBook Lite – Online Food Ordering System | CWE-862 | FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Regist… |
| CVE-2026-54572 | 8.8 | 23.6 | rclone | rclone | CWE-59 | rclone: Unvalidated symlink target in local `--links` — arbitrary file write … |
| CVE-2026-47477 | 7.5 | 23.4 | NVIDIA | Triton Inference Server | CWE-121 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-54988 | 6.1 | 23.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-56451 | 10.0 | 23.1 | Siemens | Opcenter X | CWE-347 | A vulnerability has been identified in Opcenter X (All versions < V2604). Aff… |
| CVE-2026-58229 | 8.2 | 23.1 | elixir-mint | mint | CWE-770 | Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint cau… |
| CVE-2026-49168 | 6.8 | 23.1 | Microsoft | Windows 10 Version 1607 | CWE-190 | Storage Spaces Direct Elevation of Privilege Vulnerability |
| CVE-2026-50668 | 6.8 | 23.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-54132 | 6.8 | 23.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-59246 | 6.3 | 23.1 | elixir-mint | mint | CWE-770 | Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size c… |
| CVE-2026-50428 | 5.5 | 23.0 | Microsoft | Windows 11 version 26H1 | CWE-125 | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclo… |
| CVE-2026-10577 | 10.0 | 23.0 | Rockwell Auotmation | 1715 EtherNet/IP Communications Module | CWE-306 | Rockwell Automation 1715 Redundant IO – Access Control Vulnerability |
| CVE-2025-11698 | 9.2 | 22.9 | Rockwell Automation | CompactLogix® 5380 Recovery Image Compact GuardLogix® 5380 Recovery Image CompactLogix® 5480 Recovery Image ControlLogix® 5580 Recovery Image GuardLogix® 5580 Recovery Image | CWE-120 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer … |
| CVE-2025-12011 | 9.2 | 22.9 | Rockwell Automation | CompactLogix® 5370 Compact GuardLogix® 5370 ControlLogix® 5570 GuardLogix® 5570 | CWE-120 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer … |
| CVE-2025-12012 | 9.2 | 22.9 | Rockwell Automation | CompactLogix® 5370 Compact GuardLogix® 5370 ControlLogix® 5570 GuardLogix® 5570 | CWE-120 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer … |
| CVE-2026-50301 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-50471 | 7.8 | 22.9 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-54131 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55017 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-55025 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55029 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55036 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55037 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55039 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55041 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55044 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55048 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55053 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55058 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55131 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55133 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft OneNote Remote Code Execution Vulnerability |
| CVE-2026-55136 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55137 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55141 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55899 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55947 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55948 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-55949 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-49459 | 6.1 | 23.0 | cure53 | DOMPurify | CWE-79 | DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, al… |
| CVE-2026-10051 | 6.9 | 22.8 | Eclipse Foundation | Eclipse Jetty | CWE-200 | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to… |
| CVE-2026-46629 | 5.3 | 22.8 | twigphp | Twig | CWE-770 | Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-co… |
| CVE-2026-48038 | 5.3 | 22.7 | hapijs | joi | CWE-248 | joi: Uncaught RangeError on deeply nested input through recursive `link()` sc… |
| CVE-2026-54128 | 8.4 | 22.6 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DHCP Client Remote Code Execution Vulnerability |
| CVE-2026-47478 | 7.5 | 22.6 | NVIDIA | Triton Inference Server | CWE-910 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-55898 | 7.1 | 22.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-40422 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-49801 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows SMB Information Disclosure Vulnerability |
| CVE-2026-50300 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-50341 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-50383 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1809 | CWE-126 | Windows Print Spooler Information Disclosure Vulnerability |
| CVE-2026-50401 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
| CVE-2026-50437 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-50455 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-908 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
| CVE-2026-54997 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows SMB Information Disclosure Vulnerability |
| CVE-2026-50310 | 4.7 | 22.3 | Microsoft | Windows 10 Version 1809 | CWE-190 | Windows Human Interface Device Information Disclosure Vulnerability |
| CVE-2026-45066 | 2.3 | 22.3 | symfony | symfony | CWE-184 | Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Pa… |
| CVE-2026-47971 | 7.8 | 22.3 | Adobe | Adobe Media Encoder | CWE-121 | Media Encoder | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-48269 | 7.8 | 22.3 | Adobe | Premiere | CWE-122 | Premiere Pro | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-15752 | 5.5 | 22.2 | zhinianboke | xianyu-auto-reply | CWE-862 | zhinianboke xianyu-auto-reply Backend User Endpoint users authorization |
| CVE-2026-46635 | 5.3 | 22.2 | twigphp | Twig | CWE-863 | Twig: Sandbox property allowlist bypass via the `column` filter (array_column… |
| CVE-2026-50390 | 7.8 | 22.2 | Microsoft | Windows 10 Version 1607 | CWE-843 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-48329 | 2.7 | 22.2 | Adobe | ColdFusion 2025 | CWE-613 | ColdFusion | Insufficient Session Expiration (CWE-613) |
| CVE-2026-12511 | 8.1 | 22.0 | Unknown | AI Engine | — | AI Engine < 3.5.5 - Editor+ Arbitrary File Write via Path Traversal |
| CVE-2026-15769 | 8.3 | 21.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Linux Toolkit Theming in Google… |
| CVE-2026-15626 | 2.1 | 22.0 | nextlevelbuilder | GoClaw | CWE-22 | nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile pat… |
| CVE-2026-36035 | 6.5 | 21.8 | n/a | n/a | CWE-284 | Incorrect access control in the /api/License/deactivateOffline endpoint of CA… |
| CVE-2026-45064 | 2.3 | 21.8 | symfony | symfony | CWE-451 | Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters →… |
| CVE-2026-45753 | 2.1 | 21.8 | symfony | symfony | CWE-79 | Symfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/c… |
| CVE-2026-12523 | 7.5 | 21.7 | Cloudflare | quiche | CWE-400 | Resource exhaustion in quiche HTTP/3 and QPACK layers |
| CVE-2026-45070 | 6.3 | 21.8 | symfony | symfony | CWE-93 | Symfony: Email Header Injection via Non-Token Characters in Mime Parameter Names |
| CVE-2026-54999 | 8.8 | 21.6 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-50650 | 7.8 | 21.5 | Microsoft | .NET 8.0 | CWE-94 | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-58541 | 7.8 | 21.4 | Microsoft | Windows 10 Version 1607 | CWE-843 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-58631 | 7.8 | 21.4 | Microsoft | Windows Admin Center | CWE-285 | Windows Admin Center (WAC) Remote Code Execution Vulnerability |
| CVE-2026-58632 | 7.8 | 21.4 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
| CVE-2026-58634 | 7.8 | 21.4 | Microsoft | Windows 11 version 26H1 | CWE-416 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2025-62826 | 4.3 | 21.4 | Fortinet | FortiPAM | CWE-113 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response … |
| CVE-2026-15677 | 5.5 | 21.3 | code-projects | Online Job Portal | CWE-284 | code-projects Online Job Portal JobSeekerInsert.php unrestricted upload |
| CVE-2026-62393 | 4.3 | 21.2 | Apache Software Foundation | Apache Kylin | CWE-280 | Apache Kylin: Improper authorization in job information retrieval |
| CVE-2026-15629 | 2.1 | 21.3 | louisho5 | picobot | CWE-59 | louisho5 picobot Workspace filesystem.go GetSkill link following |
| CVE-2026-12707 | 7.5 | 21.1 | Cloudflare | quiche | CWE-770 | Unbounded path event queue growth in quiche via peer-driven source connection… |
| CVE-2026-50381 | 5.5 | 21.0 | Microsoft | Windows 10 Version 21H2 | CWE-843 | Composite Image File System driver (cimfs.sys) Information Disclosure Vulnera… |
| CVE-2026-50697 | 7.8 | 20.9 | Microsoft | Windows 10 Version 1607 | CWE-200 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-54122 | 8.4 | 20.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-58618 | 7.8 | 20.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-15416 | 8.9 | 20.5 | argoproj | argo-helm | CWE-306 | Argo-cd: argo cd unauthenticated remote code execution in repo-server via gen… |
| CVE-2026-50495 | 5.5 | 20.6 | Microsoft | Windows 10 Version 1809 | CWE-284 | DNS Client Tampering Vulnerability |
| CVE-2026-15625 | 2.1 | 20.4 | nextlevelbuilder | GoClaw | CWE-183 | nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand inc… |
| CVE-2026-15768 | 6.5 | 20.3 | Google | Chrome | CWE-346 | Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 1… |
| CVE-2026-15775 | 6.5 | 20.3 | Google | Chrome | CWE-346 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 a… |
| CVE-2026-49791 | 7.8 | 20.3 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulne… |
| CVE-2026-50335 | 7.8 | 20.2 | Microsoft | Windows 10 Version 1809 | CWE-284 | Windows Operating Systems Elevation of Privilege Vulnerability |
| CVE-2026-50344 | 7.8 | 20.2 | Microsoft | Windows 10 Version 1607 | CWE-285 | Windows OLE Elevation of Privilege Vulnerability |
| CVE-2026-50346 | 7.8 | 20.2 | Microsoft | Windows 10 Version 1607 | CWE-285 | Netlogon RPC Elevation of Privilege Vulnerability |
| CVE-2026-50373 | 7.8 | 20.2 | Microsoft | Windows 10 Version 1809 | CWE-284 | Windows Search Service Elevation of Privilege Vulnerability |
| CVE-2026-50391 | 7.8 | 20.2 | Microsoft | Windows 10 Version 1607 | CWE-269 | Windows Group Policy Elevation of Privilege Vulnerability |
| CVE-2026-57088 | 7.8 | 20.2 | Microsoft | Windows 10 Version 1809 | CWE-284 | Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability |
| CVE-2026-58540 | 7.8 | 20.2 | Microsoft | Windows 10 Version 1607 | CWE-285 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-47479 | 7.5 | 20.3 | NVIDIA | Triton Inference Server | CWE-400 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-47480 | 7.5 | 20.3 | NVIDIA | Triton Inference Server | CWE-248 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-47482 | 7.5 | 20.3 | NVIDIA | Triton Inference Server | CWE-401 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-58614 | 5.5 | 20.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Kernel Security Feature Bypass Vulnerability |
| CVE-2026-50438 | 8.8 | 20.1 | Microsoft | Microsoft PC Manager | CWE-59 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-49789 | 7.8 | 20.1 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62642 | 6.5 | 20.1 | Roundcube | Webmail | CWE-835 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop w… |
| CVE-2026-15389 | 8.7 | 19.9 | Sesame Time | Sesame Time | CWE-639 | Inadequate access control in Sesame Time session management |
| CVE-2026-15772 | 8.3 | 19.9 | Google | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 all… |
| CVE-2026-15774 | 8.3 | 19.9 | Google | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a rem… |
| CVE-2026-5269 | 9.8 | 19.8 | CIENA | Navigator NCS | CWE-1393 | Navigator NCS and MCP System Accounts with Default Passwords |
| CVE-2026-57085 | 3.3 | 19.7 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Print Spooler Information Disclosure Vulnerability |
| CVE-2026-50469 | 7.8 | 19.3 | Microsoft | Windows 10 Version 1809 | CWE-59 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-47423 | 8.2 | 19.2 | cure53 | DOMPurify | CWE-79 | DOMPurify XSS via `selectedcontent` re-clone |
| CVE-2026-48805 | 5.3 | 19.2 | twigphp | Twig | CWE-693 | Twig: Sandbox state regression in deprecated internal wrappers in `src/Resour… |
| CVE-2026-50382 | 8.8 | 19.1 | Microsoft | Windows 10 Version 1809 | CWE-822 | DirectX Graphics Kernel Remote Code Execution Vulnerability |
| CVE-2026-42982 | 7.8 | 19.2 | Microsoft | Windows 10 Version 1607 | CWE-1288 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-15690 | 1.3 | 19.1 | n/a | open62541 | CWE-404 | open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null … |
| CVE-2026-48761 | 5.3 | 19.0 | symfony | symfony | CWE-79 | Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object… |
| CVE-2026-15736 | 8.3 | 18.9 | Snowflake | Snowflake SQLAlchemy | CWE-73 | Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowfla… |
| CVE-2026-58636 | 7.8 | 18.9 | Microsoft | Microsoft PC Manager | CWE-59 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-48784 | 5.1 | 18.9 | symfony | symfony | CWE-172 | Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or… |
| CVE-2025-62675 | 4.3 | 18.9 | Fortinet | FortiOS | CWE-113 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response … |
| CVE-2026-49184 | 7.8 | 18.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-46638 | 6.0 | 18.4 | twigphp | Twig | CWE-693 | Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates … |
| CVE-2026-14646 | 4.9 | 18.5 | Sonatype | Nexus Repository 3 | CWE-918 | Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect |
| CVE-2026-14504 | 8.2 | 18.4 | Sonatype | Nexus Repository 3 | CWE-862 | Nexus Repository 3 - Authorization Bypass in Component Upload API |
| CVE-2026-44752 | 8.2 | 18.3 | SAP_SE | SAP NetWeaver Application Server Java(Configuration Wizard) | CWE-79 | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server … |
| CVE-2026-24233 | 8.4 | 18.2 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpi… |
| CVE-2026-15675 | 5.5 | 18.2 | code-projects | Online Job Portal | CWE-74 | code-projects Online Job Portal EditUser.php sql injection |
| CVE-2026-15676 | 5.5 | 18.2 | code-projects | Online Job Portal | CWE-74 | code-projects Online Job Portal DeleteUser.php sql injection |
| CVE-2026-15698 | 2.1 | 18.1 | kofrasa | mingo | CWE-94 | kofrasa mingo Update API updateMany prototype pollution |
| CVE-2026-50498 | 7.8 | 18.0 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg… |
| CVE-2026-58478 | 6.3 | 17.9 | Dan-in-CA | SIP | CWE-918 | Sustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL |
| CVE-2026-45065 | 2.3 | 17.9 | symfony | symfony | CWE-185 | Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternati… |
| CVE-2026-15753 | 2.1 | 18.0 | zhinianboke | xianyu-auto-reply | CWE-650 | zhinianboke xianyu-auto-reply review approve trusting http permission methods… |
| CVE-2026-50358 | 7.8 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50359 | 7.8 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Microsoft XML Core Services Elevation of Privilege Vulnerability |
| CVE-2026-50406 | 7.8 | 17.8 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Backup Engine Elevation of Privilege Vulnerability |
| CVE-2026-50490 | 7.8 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-50491 | 7.8 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability |
| CVE-2026-50674 | 7.8 | 17.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-56187 | 7.8 | 17.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-57093 | 7.8 | 17.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-62644 | 9.8 | 17.7 | Roundcube | Webmail | CWE-290 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugi… |
| CVE-2026-50452 | 8.1 | 17.7 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-48760 | 5.3 | 17.7 | symfony | symfony | CWE-451 | Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded … |
| CVE-2026-49790 | 7.8 | 17.6 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg… |
| CVE-2026-50482 | 7.8 | 17.6 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-48338 | 6.8 | 17.6 | Adobe | ColdFusion 2025 | CWE-22 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Pa… |
| CVE-2026-47481 | 6.5 | 17.6 | NVIDIA | Triton Inference Server | CWE-288 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-49783 | 7.8 | 17.5 | Microsoft | Windows 10 Version 1607 | CWE-358 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-49792 | 7.8 | 17.5 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-49793 | 7.8 | 17.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-50293 | 7.8 | 17.5 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Internal Task Bar Elevation of Privilege Vulnerability |
| CVE-2026-50318 | 7.8 | 17.5 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-15699 | 2.1 | 17.3 | spencermountain | compromise | CWE-94 | spencermountain compromise Public Root API extend.js nlp.extend prototype pol… |
| CVE-2026-15747 | 9.1 | 17.2 | SRI | Mojolicious | CWE-204 | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable represent… |
| CVE-2026-9341 | 4.3 | 17.3 | kodezen | Academy LMS | CWE-639 | Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Ref… |
| CVE-2026-50520 | 8.4 | 17.1 | Microsoft | Visual Studio Code | CWE-77 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-9140 | 8.7 | 17.0 | Rockwell Automation | 1718-AENTR/1719-AENTR | CWE-770 | 1718-AENTR/1719-AENTR - Denial of Service |
| CVE-2026-10573 | 8.7 | 17.0 | Rockwell Automation | 1734 POINT I/O | CWE-770 | 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object |
| CVE-2026-50130 | 8.8 | 16.9 | pi-hole | pi-hole | CWE-282 | Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/piho… |
| CVE-2026-49167 | 7.8 | 16.9 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2024-7708 | 7.5 | 16.8 | Eclipse Foundation | Eclipse Jetty | CWE-400 | For requests that have a body, but reading the body may end up in reading 0 b… |
| CVE-2026-62641 | 6.5 | 16.9 | Roundcube | Webmail | CWE-770 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder w… |
| CVE-2026-11390 | 6.4 | 16.9 | blazethemes | News Kit Addons For Elementor | CWE-79 | News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored … |
| CVE-2026-15619 | 2.1 | 16.9 | mosaxiv | clawlet | CWE-918 | mosaxiv clawlet IPv4 tool_web_fetch.go web_fetch server-side request forgery |
| CVE-2026-61520 | 6.3 | 16.7 | SimpleMachines | SMF | CWE-918 | Simple Machines Forum SSRF via image proxy |
| CVE-2026-12478 | 4.8 | 16.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup webs… |
| CVE-2026-59888 | 6.5 | 16.2 | FasterXML | jackson-databind | CWE-915 | jackson-databind: @JsonIgnore on a Record property is bypassed with a Propert… |
| CVE-2026-55000 | 6.4 | 16.3 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-62643 | 10.0 | 16.2 | Roundcube | Webmail | CWE-918 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Casca… |
| CVE-2026-50372 | 7.0 | 16.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability |
| CVE-2026-56173 | 7.0 | 16.1 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows WebView Elevation of Privilege Vulnerability |
| CVE-2026-56183 | 7.0 | 16.1 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-15627 | 2.1 | 16.2 | nextlevelbuilder | GoClaw | CWE-200 | nextlevelbuilder GoClaw tool.go handleNavigate information disclosure |
| CVE-2026-50413 | 7.8 | 15.9 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-49165 | 7.1 | 15.7 | Microsoft | Windows 10 Version 1607 | CWE-908 | Microsoft Windows App Store Information Disclosure Vulnerability |
| CVE-2026-45363 | 9.1 | 15.6 | jwt | ruby-jwt | CWE-287 | `jwt` (Ruby gem) - empty-key HMAC bypass |
| CVE-2026-54127 | 8.4 | 15.5 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-50311 | 7.8 | 15.6 | Microsoft | Windows 10 Version 1607 | CWE-284 | Windows Server Elevation of Privilege Vulnerability |
| CVE-2026-58640 | 7.8 | 15.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-58545 | 5.5 | 15.4 | Microsoft | Windows 10 Version 1607 | CWE-284 | Windows Kernel Security Feature Bypass Vulnerability |
| CVE-2026-49166 | 7.8 | 15.3 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Print Configuration Elevation of Privilege Vulnerability |
| CVE-2026-49173 | 7.8 | 15.3 | Microsoft | Windows 11 version 26H1 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-49175 | 7.8 | 15.3 | Microsoft | Windows 10 Version 21H2 | CWE-122 | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-50306 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-50309 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-50331 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Application Model Core API Elevation of Privilege Vulnerability |
| CVE-2026-50367 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1809 | CWE-118 | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-50399 | 7.8 | 15.3 | Microsoft | Windows 10 Version 21H2 | CWE-125 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50400 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-50425 | 7.8 | 15.3 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Internal System User Profile Elevation of Privilege Vulnerability |
| CVE-2026-50435 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2026-50441 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-822 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
| CVE-2026-50466 | 7.8 | 15.3 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50480 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulne… |
| CVE-2026-50486 | 7.8 | 15.3 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50499 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2026-50670 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1809 | CWE-20 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54109 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
| CVE-2026-54987 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2026-55004 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows Print Configuration Elevation of Privilege Vulnerability |
| CVE-2026-56176 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-56182 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-50354 | 7.1 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-48808 | 6.0 | 15.2 | twigphp | Twig | CWE-693 | Twig: Sandbox property allowlist bypass via the `column` filter under `Source… |
| CVE-2026-47979 | 5.5 | 15.2 | Adobe | Adobe Media Encoder | CWE-125 | Media Encoder | Out-of-bounds Read (CWE-125) |
| CVE-2026-50677 | 7.8 | 15.1 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50689 | 7.8 | 15.1 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Clipboard Server Elevation of Privilege Vulnerability |
| CVE-2026-45755 | 6.9 | 15.1 | symfony | symfony | CWE-306 | Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMA… |
| CVE-2026-47212 | 6.9 | 15.1 | symfony | symfony | CWE-306 | Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature… |
| CVE-2026-12482 | 6.5 | 15.1 | keras-team | keras-team/keras | CWE-22 | Path Traversal via Symlink Name Validation Bypass in keras-team/keras |
| CVE-2026-45069 | 8.8 | 14.9 | symfony | symfony | CWE-345 | Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims |
| CVE-2026-56181 | 8.3 | 14.9 | Microsoft | Windows 11 Version 24H2 | CWE-346 | Windows Network Address Translation (NAT) Spoofing Vulnerability |
| CVE-2026-13699 | 6.5 | 15.0 | Eclipse Foundation | Eclipse KUKSA - Databroker | CWE-20 | Databroker 0.6.1 PublishValue missing data_point panic |
| CVE-2026-50302 | 6.5 | 14.8 | Microsoft | Windows 10 Version 21H2 | CWE-295 | Windows Cryptographic Services Security Feature Bypass Vulnerability |
| CVE-2026-50526 | 5.5 | 14.9 | Microsoft | .NET 10.0 | CWE-59 | .NET Tampering Vulnerability |
| CVE-2026-47976 | 7.8 | 14.7 | Adobe | Adobe Media Encoder | CWE-787 | Media Encoder | Out-of-bounds Write (CWE-787) |
| CVE-2026-60118 | 6.9 | 14.6 | HiEventsDev | Hi.Events | CWE-862 | Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint |
| CVE-2026-48806 | 7.1 | 14.5 | twigphp | Twig | CWE-693 | Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys |
| CVE-2026-50510 | 7.8 | 14.4 | Microsoft | GitHub Copilot Plugin for JetBrains IDEs | CWE-641 | GitHub Copilot Remote Code Execution Vulnerability |
| CVE-2026-50488 | 7.8 | 14.3 | Microsoft | Windows 11 Version 24H2 | CWE-77 | Clipboard User Service Elevation of Privilege Vulnerability |
| CVE-2026-45072 | 2.0 | 14.3 | symfony | symfony | CWE-79 | Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped N… |
| CVE-2026-58544 | 7.0 | 13.9 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Management Services Elevation of Privilege Vulnerability |
| CVE-2026-58619 | 7.0 | 13.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-58629 | 7.0 | 13.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-58637 | 7.0 | 13.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Client-Side Caching Elevation of Privilege Vulnerability |
| CVE-2026-58638 | 5.5 | 13.9 | Microsoft | Windows 10 Version 1809 | CWE-325 | Windows Boot Loader Security Feature Bypass Vulnerability |
| CVE-2026-58476 | 7.0 | 13.8 | Dan-in-CA | SIP | CWE-352 | Sustainable Irrigation Platform 5.2.16 CSRF via Administrative GET Requests |
| CVE-2026-8384 | 5.3 | 13.8 | Eclipse Foundation | Eclipse Jetty | CWE-647 | In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt resu… |
| CVE-2026-15620 | 2.1 | 13.8 | mosaxiv | clawlet | CWE-918 | mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery |
| CVE-2026-15668 | 2.1 | 13.8 | louisho5 | picobot | CWE-918 | louisho5 picobot web Tool web.go WebTool.Execute server-side request forgery |
| CVE-2026-15750 | 2.1 | 13.6 | mastergo-design | mastergo-magic-mcp | CWE-918 | mastergo-design mastergo-magic-mcp mcp__getComponentLink get-component-link.t… |
| CVE-2026-47472 | 7.8 | 13.5 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communicati… |
| CVE-2026-59839 | 5.5 | 13.4 | Fortinet | FortiProxy | CWE-22 | A improper limitation of a pathname to a restricted directory ('path traversa… |
| CVE-2026-58601 | 7.8 | 13.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
| CVE-2026-58602 | 7.8 | 13.2 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-14852 | 5.2 | 13.0 | Checkmk GmbH | Checkmk | CWE-78 | mk_sap_hana: Privilege escalation via crafted sapstartsrv process name |
| CVE-2026-50451 | 7.8 | 12.9 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulne… |
| CVE-2026-54432 | 4.7 | 12.9 | Roundcube | Webmail | CWE-79 | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Si… |
| CVE-2026-15643 | 9.2 | 12.8 | AWS | awslabs.healthlake-mcp-server | CWE-918 | AWS HealthLake MCP Server SSRF via Pagination URL |
| CVE-2026-50392 | 7.0 | 12.7 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-24220 | 6.4 | 12.7 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen s… |
| CVE-2026-44753 | 3.7 | 12.7 | SAP_SE | SAP HANA Extended Application Services classic model (User Self Service) | CWE-204 | Information Disclosure vulnerability in SAP HANA Extended Application Service… |
| CVE-2026-15628 | 2.1 | 12.6 | zhayujie | chatgpt-on-wechat CowAgent | CWE-918 | zhayujie chatgpt-on-wechat CowAgent Vision Tool vision.py Vision._download_to… |
| CVE-2026-50295 | 5.5 | 12.4 | Microsoft | Windows 11 Version 24H2 | CWE-269 | Windows Zero Trust DNS Security Feature Bypass Vulnerability |
| CVE-2026-47304 | 9.8 | 12.3 | Microsoft | .NET 10.0 | CWE-345 | .NET Security Feature Bypass Vulnerability |
| CVE-2026-49171 | 7.8 | 12.3 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Speech Runtime Elevation of Privilege Vulnerability |
| CVE-2026-47471 | 7.5 | 12.2 | NVIDIA | TensorRT-LLM | CWE-122 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deser… |
| CVE-2026-48807 | 7.1 | 12.2 | twigphp | Twig | CWE-693 | Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `r… |
| CVE-2026-50342 | 8.8 | 12.0 | Microsoft | Windows 11 Version 24H2 | CWE-284 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-48581 | 7.8 | 12.0 | Microsoft | Microsoft Surface Go | CWE-1220 | Surface Broker SDMA Elevation of Privilege Vulnerability |
| CVE-2026-50333 | 7.8 | 12.0 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Spaceport.sys Elevation of Privilege Vulnerability |
| CVE-2026-50405 | 7.8 | 12.0 | Microsoft | Windows 10 Version 1607 | CWE-1220 | Windows Filtering Platform Elevation of Privilege Vulnerability |
| CVE-2026-55001 | 7.8 | 12.0 | Microsoft | Windows 10 Version 1607 | CWE-295 | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2026-55006 | 7.8 | 12.1 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-1220 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-55014 | 7.8 | 12.0 | Microsoft | Windows Remote Help | CWE-284 | Windows Remote Help Defense Elevation of Privilege Vulnerability |
| CVE-2026-57107 | 7.8 | 12.0 | Microsoft | Windows Admin Center | CWE-287 | Windows Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-50465 | 7.1 | 12.1 | Microsoft | Windows 11 Version 24H2 | CWE-284 | Windows DNS Client Tampering Vulnerability |
| CVE-2026-48571 | 7.0 | 11.9 | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-50323 | 7.0 | 11.9 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-58475 | 5.3 | 12.1 | Dan-in-CA | SIP | CWE-79 | Sustainable Irrigation Platform 5.2.16 Stored XSS via Program Name |
| CVE-2026-54129 | 7.8 | 11.9 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-15641 | 7.1 | 11.9 | Devolutions | Server | CWE-863 | Improper authorization in the access request status endpoint in Devolutions S… |
| CVE-2026-50297 | 7.0 | 11.9 | Microsoft | Windows 10 Version 1607 | CWE-284 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-50325 | 7.0 | 11.9 | Microsoft | Windows 10 Version 1607 | CWE-284 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-59732 | 5.0 | 11.8 | rclone | rclone | CWE-22 | rclone archive extract allows S3 destination prefix escape via crafted archiv… |
| CVE-2026-49981 | 6.0 | 11.8 | twigphp | Twig | CWE-693 | Twig: Sandbox filter, tag and function allow-list bypass when sandbox state c… |
| CVE-2026-15624 | 2.1 | 11.4 | nextlevelbuilder | GoClaw | CWE-918 | nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDown… |
| CVE-2026-15183 | 9.2 | 11.2 | Snowflake | Snowflake Spark Connector | CWE-89 | Input Validation Vulnerabilities in Snowflake Spark Connector |
| CVE-2026-12588 | 6.0 | 11.2 | Trellix | Trellix HX Console | CWE-409 | An attacker with access to an HX 10.0.0 and previous versions, may send speci… |
| CVE-2026-62655 | 5.7 | 11.1 | NETGEAR | RBR860 | CWE-121 | A DoS vulnerability due to stack overflow exists in certain NETGEAR Orbi models |
| CVE-2026-9561 | 8.8 | 10.7 | Eclipse Foundation | Eclipse Kura | CWE-345 | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-Fo… |
| CVE-2026-15757 | 6.3 | 10.6 | NETGEAR | DGND3700v1 | CWE-20 | Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router |
| CVE-2026-34346 | 5.5 | 10.5 | Microsoft | Windows 10 Version 1607 | CWE-319 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerab… |
| CVE-2026-50303 | 5.5 | 10.5 | Microsoft | Windows 10 Version 1809 | CWE-1240 | Windows Key Guard Security Feature Bypass Vulnerability |
| CVE-2026-50307 | 7.8 | 10.2 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-50393 | 7.8 | 10.2 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-50396 | 7.8 | 10.2 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-54989 | 7.8 | 10.2 | Microsoft | Windows 10 Version 1607 | CWE-416 | Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnera… |
| CVE-2026-15672 | 2.1 | 10.2 | itsourcecode | Electronic Judging System | CWE-74 | itsourcecode Electronic Judging System add_judges.php sql injection |
| CVE-2026-50673 | 7.8 | 10.1 | Microsoft | Windows 10 Version 1607 | CWE-367 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-49162 | 7.0 | 10.0 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50296 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1607 | CWE-416 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50317 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Operating Systems Elevation of Privilege Vulnerability |
| CVE-2026-50378 | 7.0 | 10.1 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Key Guard Elevation of Privilege Vulnerability |
| CVE-2026-50397 | 7.0 | 10.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50410 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50449 | 7.0 | 10.0 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50676 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-58527 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-42447 | 5.0 | 10.0 | skylot | jadx | CWE-79 | jadx: HTML Injection in Summary panel |
| CVE-2026-15678 | 2.0 | 10.0 | code-projects | Online Job Portal | CWE-79 | code-projects Online Job Portal DetailJob.php cross site scripting |
| CVE-2026-49174 | 6.1 | 9.9 | Microsoft | Windows 10 Version 1809 | CWE-306 | DNS Client Tampering Vulnerability |
| CVE-2026-48350 | 8.6 | 9.8 | Adobe | Adobe Animate 2023 | CWE-22 | Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path … |
| CVE-2026-50459 | 7.8 | 9.8 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-7640 | 6.4 | 9.8 | aguilatechnologies | WP Customer Area | CWE-79 | WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Sc… |
| CVE-2026-48747 | 6.3 | 9.8 | symfony | symfony | CWE-347 | Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Req… |
| CVE-2026-44769 | 5.5 | 9.8 | SAP_SE | SAP S/4HANA Project Management (PPM-PRO) | CWE-89 | SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO) |
| CVE-2026-47969 | 5.5 | 9.8 | Adobe | Audition | CWE-125 | Audition | Out-of-bounds Read (CWE-125) |
| CVE-2026-48270 | 7.8 | 9.6 | Adobe | Premiere | CWE-787 | Premiere Pro | Out-of-bounds Write (CWE-787) |
| CVE-2026-50418 | 6.1 | 9.7 | Microsoft | Windows 11 Version 24H2 | CWE-284 | Windows System Secure Feature Bypass Vulnerability |
| CVE-2026-48758 | 5.4 | 9.7 | sigstore | sigstore-js | CWE-347 | sigstore-js: DSSE payloadType type-binding failure |
| CVE-2026-6790 | 5.3 | 9.7 | Eclipse Foundation | Eclipse Jetty | CWE-20 | In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict … |
| CVE-2026-62659 | 4.3 | 9.5 | NETGEAR | WAX333 | CWE-20 | Authenticated users can make unauthorized changes on NETGEAR WAX333 Access Po… |
| CVE-2026-62658 | 4.7 | 9.3 | NETGEAR | RAX43 | CWE-20 | Post-authentication Command Injection Vulnerability in certain Nighthawk RAX … |
| CVE-2026-48349 | 8.1 | 9.2 | Adobe | Adobe Animate 2023 | CWE-863 | Animate | Incorrect Authorization (CWE-863) |
| CVE-2026-15637 | 7.5 | 9.2 | Devolutions | Server | CWE-639 | Improper authorization in the PAM SSH key and certificate retrieval endpoints… |
| CVE-2026-47967 | 7.8 | 8.8 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-47968 | 7.8 | 8.8 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-50458 | 7.8 | 8.7 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50322 | 7.0 | 8.8 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50345 | 7.0 | 8.8 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50371 | 7.0 | 8.8 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerab… |
| CVE-2026-50503 | 7.0 | 8.8 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50658 | 7.0 | 8.8 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-367 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
| CVE-2026-12606 | 6.3 | 8.7 | Eclipse Foundation | Eclipse GlassFish | CWE-444 | Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer s… |
| CVE-2026-48339 | 7.8 | 8.7 | Adobe | Adobe Bridge | CWE-122 | Bridge | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-59840 | 4.3 | 8.7 | Fortinet | FortiOS | CWE-126 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, For… |
| CVE-2026-48346 | 7.9 | 8.6 | Adobe | Adobe Animate 2023 | CWE-426 | Animate | Untrusted Search Path (CWE-426) |
| CVE-2026-52840 | 2.7 | 8.5 | alextselegidis | easyappointments | CWE-918 | Easy!Appointments has server-side request forgery in CalDAV connection test t… |
| CVE-2026-55651 | 7.1 | 8.4 | alextselegidis | easyappointments | CWE-200 | Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Expo… |
| CVE-2026-50385 | 8.8 | 8.3 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50305 | 7.8 | 8.3 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50361 | 7.8 | 8.3 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-50427 | 7.8 | 8.3 | Microsoft | Windows 10 Version 1809 | CWE-362 | Content Delivery Manager Elevation of Privilege Vulnerability |
| CVE-2026-50457 | 7.8 | 8.3 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-54125 | 7.8 | 8.3 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-52838 | 2.6 | 8.3 | alextselegidis | easyappointments | CWE-79 | Easy!Appointments disable_booking_message rendered as raw HTML on public book… |
| CVE-2026-48371 | 5.4 | 8.1 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-58628 | 7.8 | 8.0 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Wireless Network Manager Elevation of Privilege Vulnerability |
| CVE-2026-44767 | 6.1 | 8.0 | SAP_SE | @ui5/webcomponents-base | CWE-79 | Allowlist Bypass in setThemeRoot() Enables Cross-Origin CSS Injection |
| CVE-2026-11567 | 5.9 | 8.0 | Unknown | SureForms | — | SureForms < 2.11.1 - Unauthenticated Payment Amount Bypass |
| CVE-2026-48365 | 7.8 | 7.9 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-48368 | 7.8 | 7.9 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-8085 | 7.0 | 7.9 | Rockwell Automation | Arena® Simulation | CWE-787 | Rockwell Automation Arena® - Memory Corruption Vulnerability |
| CVE-2026-8312 | 7.0 | 7.9 | Rockwell Auotmation | Arena® Simulation | CWE-787 | Rockwell Automation Arena® - Memory Corruption Vulnerability |
| CVE-2026-8313 | 7.0 | 7.9 | Rockwell Automation | Arena® Simulation | CWE-787 | Rockwell Automation Arena® - Memory Corruption Vulnerability |
| CVE-2026-8314 | 7.0 | 7.9 | Rockwell Automation | Arena® Simulation | CWE-787 | Rockwell Automation Arena® - Memory Corruption Vulnerability |
| CVE-2026-9653 | 8.7 | 7.6 | Rockwell Automation | 1756-EN2, 1756-EN3 | CWE-354 | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID |
| CVE-2026-48290 | 8.2 | 7.6 | Adobe | Content Credentials Rust SDK | CWE-918 | CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-47737 | 7.5 | 7.6 | puma | puma | CWE-290 | Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connec… |
| CVE-2026-46637 | 5.1 | 7.3 | twigphp | Twig | CWE-79 | Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => [… |
| CVE-2026-15305 | 6.3 | 7.1 | TYPO3 | TYPO3 CMS | CWE-351 | TYPO3 CMS - Unrestricted File Upload in Form Framework |
| CVE-2026-44759 | 6.1 | 6.9 | SAP_SE | SAP NetWeaver Enterprise Portal | CWE-79 | Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal |
| CVE-2026-44771 | 4.3 | 6.9 | SAP_SE | SAP S/4HANA (Draft operation) | CWE-862 | Missing Authorization check in SAP S/4HANA (Draft operation) |
| CVE-2026-58543 | 6.3 | 6.9 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Universal Print Management Service Elevation of Privilege Vulnerability |
| CVE-2026-60119 | 5.1 | 6.8 | HiEventsDev | Hi.Events | CWE-862 | Hi.Events < 1.11.0 XSS via Event Title JSON.stringify Injection |
| CVE-2026-48340 | 7.8 | 6.8 | Adobe | Adobe Bridge | CWE-822 | Bridge | Untrusted Pointer Dereference (CWE-822) |
| CVE-2026-48342 | 7.8 | 6.7 | Adobe | Adobe Bridge | CWE-190 | Bridge | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-12988 | 6.4 | 6.6 | Unknown | WP 2FA | CWE-862 | WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding |
| CVE-2026-46628 | 5.1 | 6.7 | twigphp | Twig | CWE-116 | Twig: The `spaceless` filter implicitly marks its output as safe |
| CVE-2026-47730 | 5.1 | 6.7 | twigphp | Twig | CWE-79 | Twig: XSS in profiler HtmlDumper via unescaped template and profile names |
| CVE-2026-56178 | 7.0 | 6.5 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-367 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
| CVE-2026-48253 | 5.4 | 6.5 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48254 | 5.4 | 6.5 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48255 | 5.4 | 6.5 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48257 | 5.4 | 6.5 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48260 | 5.4 | 6.5 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48261 | 5.4 | 6.5 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48262 | 5.4 | 6.5 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-44770 | 4.3 | 6.5 | SAP_SE | SAP S/4 HANA (Create Single Payment) | CWE-862 | Missing Authorization check in SAP S/4 HANA (Create Single Payment) |
| CVE-2026-24268 | 7.8 | 6.4 | NVIDIA | TensorRT | CWE-122 | NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap… |
| CVE-2026-48263 | 5.4 | 6.4 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48355 | 5.4 | 6.4 | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48309 | 7.8 | 6.3 | Adobe | Audition | CWE-787 | Audition | Out-of-bounds Write (CWE-787) |
| CVE-2026-48348 | 7.7 | 6.3 | Adobe | Adobe Animate 2023 | CWE-863 | Animate | Incorrect Authorization (CWE-863) |
| CVE-2026-53566 | 6.8 | 6.4 | Citrix | Citrix Secure Access Client for Windows | CWE-125 | Out-of-bounds memory read |
| CVE-2026-11563 | 9.6 | 6.1 | Unknown | Word Count and Social Shares | — | Word Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via… |
| CVE-2026-44768 | 4.1 | 6.1 | SAP_SE | SAP CRM (WebClient UI) | CWE-15 | Security misconfiguration in SAP CRM (WebClient UI) |
| CVE-2026-55144 | 7.1 | 6.1 | Microsoft | Windows 11 Version 24H2 | CWE-325 | Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability |
| CVE-2026-48572 | 7.0 | 6.0 | Microsoft | Windows 11 version 23H2 | CWE-362 | Windows App Package Installer Elevation of Privilege Vulnerability |
| CVE-2026-57973 | 4.7 | 6.0 | Microsoft | Windows Subsystem for Linux (WSL2) | CWE-367 | Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability |
| CVE-2026-15392 | 7.7 | 5.9 | HMBRAND | DBD::File | CWE-22 | DBD::File versions before 1.651 for Perl do not ensure the table file is not … |
| CVE-2026-54429 | 6.0 | 6.0 | Siemens | SIMATIC S7-PLCSIM Advanced | CWE-770 | A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versio… |
| CVE-2026-62656 | 5.4 | 6.0 | NETGEAR | RAXE450 | CWE-20 | Post-authenticated command injection vulnerability found in certain NETGEAR R… |
| CVE-2026-15058 | 3.1 | 5.9 | Devolutions | Server | CWE-639 | Improper authorization in the secure messages deletion endpoint in Devolution… |
| CVE-2026-48275 | 8.6 | 5.8 | Adobe | Illustrator Desktop 2026 | CWE-426 | Illustrator | Untrusted Search Path (CWE-426) |
| CVE-2026-48312 | 6.8 | 5.5 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-0487 | 8.4 | 5.4 | SAP_SE | SAProuter on Microsoft Windows | CWE-427 | DLL Hijacking vulnerability in SAProuter on Microsoft Windows |
| CVE-2026-15076 | 8.2 | 5.4 | Eclipse Foundation | Eclipse Vert.x | CWE-346 | In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), t… |
| CVE-2026-48353 | 5.5 | 5.1 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-50321 | 7.0 | 5.0 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows USB Driver Elevation of Privilege Vulnerability |
| CVE-2026-50440 | 7.0 | 5.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Audio Service Elevation of Privilege Vulnerability |
| CVE-2026-54107 | 7.0 | 5.0 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54991 | 7.0 | 5.0 | Microsoft | Windows 11 Version 24H2 | CWE-125 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-48296 | 6.2 | 5.1 | Adobe | Content Credentials Rust SDK | CWE-191 | CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
| CVE-2026-48302 | 6.2 | 5.1 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-44800 | 7.8 | 4.9 | Microsoft | Windows 11 version 23H2 | CWE-362 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-49808 | 7.8 | 5.0 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-49183 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Clipboard Server Elevation of Privilege Vulnerability |
| CVE-2026-49784 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1607 | CWE-362 | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-49802 | 7.0 | 4.9 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-49803 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows AppX Deployment Extensions Elevation of Privilege Vulnerability |
| CVE-2026-49806 | 7.0 | 4.9 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-50356 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1607 | CWE-362 | Microsoft Windows App Store Elevation of Privilege Vulnerability |
| CVE-2026-50384 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Clip Service Elevation of Privilege Vulnerability |
| CVE-2026-50403 | 7.0 | 4.9 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Runtime Elevation of Privilege Vulnerability |
| CVE-2026-50404 | 7.0 | 4.9 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Media Elevation of Privilege Vulnerability |
| CVE-2026-50450 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Network Connections Service Elevation of Privilege Vulnerability |
| CVE-2026-50669 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Telephony Server Elevation of Privilege Vulnerability |
| CVE-2026-50672 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-54111 | 7.0 | 4.9 | Microsoft | Windows 11 Version 24H2 | CWE-125 | Universal Print Management Service Elevation of Privilege Vulnerability |
| CVE-2026-54112 | 7.0 | 4.9 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-54996 | 7.0 | 4.9 | Microsoft | Windows 11 Version 24H2 | CWE-125 | Windows USB Print Driver Elevation of Privilege Vulnerability |
| CVE-2026-48298 | 6.2 | 5.0 | Adobe | Content Credentials Rust SDK | CWE-191 | CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
| CVE-2026-48354 | 6.2 | 5.0 | Adobe | Content Credentials Rust SDK | CWE-190 | CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-48357 | 6.2 | 5.0 | Adobe | Content Credentials Rust SDK | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-21840 | 3.1 | 5.0 | HCLSoftware | HCL BigFix Platform | CWE-208 | HCL BigFix Platform is affected by a user enumeration vulnerability |
| CVE-2026-53565 | 8.5 | 4.9 | Citrix | Secure Access Client for Windows | CWE-269 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privil… |
| CVE-2026-42049 | 8.4 | 4.8 | skylot | jadx | CWE-94 | jadx: RCE Via Groovy Code Injection in Gradle Export |
| CVE-2026-24238 | 7.8 | 4.8 | NVIDIA | TensorRT | CWE-129 | NVIDIA TensorRT for contains a vulnerability where an attacker might cause an… |
| CVE-2026-24272 | 7.8 | 4.8 | NVIDIA | TensorRT | CWE-122 | NVIDIA TensorRT contains a vulnerability where an attacker might cause an ove… |
| CVE-2026-48341 | 7.8 | 4.6 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-48366 | 7.8 | 4.6 | Adobe | Adobe Media Encoder | CWE-787 | Media Encoder | Out-of-bounds Write (CWE-787) |
| CVE-2026-48367 | 7.8 | 4.6 | Adobe | After Effects | CWE-787 | After Effects | Out-of-bounds Write (CWE-787) |
| CVE-2026-48274 | 7.8 | 4.6 | Adobe | After Effects | CWE-787 | After Effects | Out-of-bounds Write (CWE-787) |
| CVE-2026-48311 | 7.8 | 4.6 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-48343 | 7.8 | 4.6 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-48369 | 7.8 | 4.6 | Adobe | Premiere | CWE-787 | Premiere Pro | Out-of-bounds Write (CWE-787) |
| CVE-2026-48370 | 7.8 | 4.6 | Adobe | Adobe Media Encoder | CWE-787 | Media Encoder | Out-of-bounds Write (CWE-787) |
| CVE-2026-58526 | 7.8 | 4.5 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-59841 | 7.5 | 4.5 | Fortinet | FortiSIEMWindowsAgent | CWE-923 | A improper restriction of communication channel to intended endpoints vulnera… |
| CVE-2026-48308 | 5.9 | 4.4 | Adobe | Premiere | CWE-20 | Premiere Pro | Improper Input Validation (CWE-20) |
| CVE-2026-7494 | 5.3 | 4.3 | Sonatype | Nexus Repository | CWE-918 | Nexus Repository - SSRF in SSL Certificate Retrieval |
| CVE-2026-52839 | 3.3 | 4.3 | alextselegidis | easyappointments | CWE-639 | Easy!Appointments appointments/store and appointments/update allow cross-prov… |
| CVE-2026-15075 | 8.2 | 4.2 | Eclipse Foundation | Eclipse Vert.x | CWE-200 | In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 … |
| CVE-2026-48815 | 7.5 | 4.1 | sigstore | sigstore-js | CWE-347 | sigstore-js: `certificateOIDs` verification constraints are silently dropped … |
| CVE-2026-44760 | 4.7 | 4.0 | SAP_SE | SAP NetWeaver Application Server ABAP (applications based on Business Server Pages) | CWE-79 | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server … |
| CVE-2026-9636 | 8.2 | 3.8 | Rockwell Automation | ControlLogix® 5580, CompactLogix® 5380, GuardLogix® 5580, Compact GuardLogix® 5380, 1756-EN4TR | CWE-299 | Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communic… |
| CVE-2026-15621 | 4.8 | 3.8 | mosaxiv | clawlet | CWE-59 | mosaxiv clawlet File Tools fs_ops.go edit_file link following |
| CVE-2026-15749 | 1.9 | 3.8 | mastergo-design | mastergo-magic-mcp | CWE-22 | mastergo-design mastergo-magic-mcp mcp__C2d get-c2d.ts execute path traversal |
| CVE-2026-15751 | 1.9 | 3.8 | mastergo-design | mastergo-magic-mcp | CWE-22 | mastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workf… |
| CVE-2026-48287 | 7.4 | 3.7 | Adobe | Content Credentials Rust SDK | CWE-426 | CAI Content Credentials | Untrusted Search Path (CWE-426) |
| CVE-2026-48335 | 7.8 | 3.7 | Adobe | Illustrator Desktop 2026 | CWE-787 | Illustrator | Out-of-bounds Write (CWE-787) |
| CVE-2026-48336 | 7.8 | 3.7 | Adobe | Illustrator Desktop 2026 | CWE-787 | Illustrator | Out-of-bounds Write (CWE-787) |
| CVE-2026-48337 | 7.8 | 3.7 | Adobe | Illustrator Desktop 2026 | CWE-787 | Illustrator | Out-of-bounds Write (CWE-787) |
| CVE-2026-24259 | 6.4 | 3.7 | NVIDIA | TensorRT-LLM | CWE-306 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker coul… |
| CVE-2026-48272 | 7.8 | 3.5 | Adobe | Creative Cloud Desktop | CWE-427 | Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-54684 | 7.0 | 3.3 | skylot | jadx | CWE-22 | jadx: XAPK archive entries with absolute paths can plant drop-in plugins and … |
| CVE-2025-15665 | 5.4 | 3.3 | Unknown | Ultimate Before After Image Slider & Gallery | — | BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field |
| CVE-2026-47473 | 7.4 | 2.9 | NVIDIA | TensorRT-LLM | CWE-123 | NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a … |
| CVE-2026-59674 | 7.1 | 3.0 | SUSE | openSUSE Tumbleweed | CWE-61 | LPE from suricata user to root due to chown in %post in suricata packaging |
| CVE-2026-52841 | 3.1 | 3.0 | alextselegidis | easyappointments | CWE-639 | Easy!Appointments: Authorization bypass in Google OAuth provider binding lets… |
| CVE-2026-59836 | 9.8 | 2.7 | Fortinet | FortiClientEMS | CWE-295 | A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.… |
| CVE-2026-48816 | 6.5 | 2.5 | sigstore | sigstore-js | CWE-345 | sigstore-js: Insufficient Verification of Data Authenticity |
| CVE-2026-24229 | 7.3 | 2.3 | NVIDIA | TensorRT-LLM | CWE-306 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated o… |
| CVE-2026-10669 | 7.8 | 2.2 | zephyrproject | zephyr | CWE-190 | Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypas… |
| CVE-2026-4017 | 7.4 | 2.1 | BlackBerry Ltd | QNX Software Development Platform | CWE-121 | Buffer overflow in the QNX Neutrino kernel impacts versions of the QNX Softwa… |
| CVE-2026-24271 | 6.2 | 2.2 | NVIDIA | TensorRT-LLM | CWE-770 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inferen… |
| CVE-2026-47470 | 6.2 | 2.2 | NVIDIA | TensorRT-LLM | CWE-20 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC ser… |
| CVE-2026-47475 | 6.2 | 2.2 | NVIDIA | TensorRT-LLM | CWE-617 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inferen… |
| CVE-2026-24226 | 6.3 | 2.1 | NVIDIA | TensorRT-LLM | CWE-829 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker coul… |
| CVE-2026-15642 | 3.3 | 1.8 | Devolutions | Server | CWE-200 | Insertion of sensitive information into a file in the Recovery Kit response f… |
| CVE-2026-10714 | 8.8 | 1.7 | Rockwell Automation | FactoryTalk® Services Platform | CWE-1390 | Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication… |
| CVE-2026-24234 | 6.8 | 1.7 | NVIDIA | TensorRT-LLM | CWE-918 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal medi… |
| CVE-2025-40945 | 8.5 | 1.6 | Siemens | COMOS V10.4.5 | CWE-426 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.… |
| CVE-2026-0515 | 6.2 | 1.6 | BlackBerry Ltd | QNX Software Development Platform | CWE-233 | Insufficient parameter validation in the QNX Neutrino kernel impacts versions… |
| CVE-2026-9127 | 7.3 | 1.5 | Rockwell Automation | Studio 5000 Logix Designer | CWE-863 | Studio 5000 Logix Designer® – Multiple Vulnerabilities |
| CVE-2026-6851 | 7.0 | 1.4 | Bitdefender | Total Security | CWE-59 | Improper link resolution before file access in Bitdefender Total Security via… |
| CVE-2026-9108 | 5.4 | 1.4 | Rockwell Automation | Studio 5000 Logix Designer | CWE-22 | Studio 5000 Logix Designer® – Multiple Vulnerabilities |
| CVE-2026-10671 | 7.1 | 1.4 | zephyrproject | zephyr | CWE-1188 | User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queu… |