| CVE-2026-61929 | 7.0 | 72.9 | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-65788 | 7.0 | 72.9 | Microsoft | Windows 11 version 23H2 | CWE-416 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-62766 | 7.0 | 72.5 | Microsoft | Windows 11 Version 24H2 | CWE-415 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-63514 | 8.8 | 72.4 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65658 | 8.8 | 69.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-65663 | 8.8 | 69.9 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-63516 | 6.5 | 69.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-502 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-73034 | 9.3 | 68.8 | eosphoros-ai | DB-GPT | CWE-22 | DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header |
| CVE-2026-62912 | 6.5 | 68.3 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-502 | Microsoft Exchange Server Denial of Service Vulnerability |
| CVE-2026-59132 | 7.5 | 68.2 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-63520 | 8.1 | 68.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-20 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-70321 | 8.8 | 67.0 | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-502 | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-66148 | 6.3 | 64.7 | SonicWall | GMS | CWE-94 | An authenticated command injection vulnerability was identified in GMS Comman… |
| CVE-2026-54113 | 7.5 | 63.6 | Microsoft | Windows 10 Version 1607 | CWE-770 | Remote Procedure Call Denial of Service Vulnerability |
| CVE-2026-62898 | 7.5 | 63.2 | Microsoft | .NET 10.0 | CWE-416 | Microsoft QUIC Information Disclosure Vulnerability |
| CVE-2026-62901 | 7.5 | 61.7 | Microsoft | .NET 10.0 | CWE-606 | .NET Denial of Service Vulnerability |
| CVE-2026-11739 | 4.9 | 61.5 | NETGEAR | MR60 | CWE-78 | Command injection vulnerability in some NETGEAR Nighthawk devices |
| CVE-2026-66147 | 9.4 | 61.4 | SonicWall | GMS | CWE-94 | An unauthenticated command injection vulnerability was identified in the GMS … |
| CVE-2026-59138 | 6.5 | 61.2 | Microsoft | Windows 10 Version 1607 | CWE-476 | Microsoft Remote Registry Service Denial of Service Vulnerability |
| CVE-2026-61345 | 6.5 | 61.2 | Microsoft | Windows 10 Version 1607 | CWE-476 | Microsoft Remote Registry Service Denial of Service Vulnerability |
| CVE-2026-16053 | 8.5 | 59.6 | Zohocorp | ManageEngine M365 Manager Plus | CWE-23 | Path Traversal |
| CVE-2026-64921 | 8.8 | 59.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-306 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-45618 | 10.0 | 58.5 | harttle | liquidjs | CWE-94 | LiquidJS is Vulnerable to Remote Code Execution |
| CVE-2026-62818 | 8.8 | 58.4 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution V… |
| CVE-2026-62702 | 8.6 | 58.1 | Microsoft | Windows 10 Version 21H2 | CWE-476 | Windows Graphics Kernel Denial of Service Vulnerability |
| CVE-2026-47299 | 7.2 | 58.0 | Microsoft | Azure Monitor Agent Linux Extension | CWE-77 | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2026-59133 | 8.8 | 57.4 | Microsoft | Windows App Client for Windows Desktop | CWE-250 | Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulner… |
| CVE-2026-62815 | 9.8 | 57.2 | Microsoft | Windows 11 version 23H2 | CWE-416 | Microsoft QUIC Remote Code Execution Vulnerability |
| CVE-2026-62784 | 8.8 | 57.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vuln… |
| CVE-2026-62800 | 8.8 | 57.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-65815 | 8.8 | 57.0 | Microsoft | Microsoft Dynamics 365 (on-premises) version 9.1 | CWE-502 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-62878 | 9.8 | 56.3 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2025-31114 | 9.3 | 56.0 | lllyasviel | Fooocus | CWE-95 | Fooocus webui vulnerable to Remote Code Execution |
| CVE-2026-18129 | 8.1 | 55.8 | Ivanti | Endpoint Manager | CWE-295 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoin… |
| CVE-2026-61918 | 7.5 | 55.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-62782 | 7.5 | 55.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-47285 | 6.5 | 55.8 | Microsoft | Visual Studio Code | CWE-77 | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-62837 | 6.5 | 55.5 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-23 | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2026-5917 | 9.4 | 55.5 | libgit2 | libgit2 | CWE-78 | libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend |
| CVE-2026-65681 | 7.5 | 55.3 | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows iSCSI Target Service Denial of Service Vulnerability |
| CVE-2026-70327 | 6.5 | 55.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70328 | 6.5 | 55.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-58639 | 6.5 | 54.7 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-918 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-19091 | 8.1 | 54.5 | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | CWE-22 | GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion… |
| CVE-2026-61924 | 7.5 | 54.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-61921 | 6.5 | 54.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-11814 | 4.9 | 54.4 | NETGEAR | BE9300 | CWE-295 | Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers |
| CVE-2026-62785 | 8.8 | 54.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vu… |
| CVE-2026-73218 | 7.7 | 54.2 | cursor | cursor | CWE-269 | Cursor: Sandbox escape via launching privileged containers |
| CVE-2026-49179 | 8.8 | 54.0 | Microsoft | Windows 10 Version 1607 | CWE-77 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-48385 | 7.7 | 53.6 | Adobe | ColdFusion 2025 | CWE-78 | ColdFusion | Improper Neutralization of Special Elements used in an OS Comman… |
| CVE-2026-57104 | 9.6 | 53.3 | Microsoft | Azure Storage Explorer | CWE-79 | Azure Storage Explorer Elevation of Privilege Vulnerability |
| CVE-2026-58612 | 7.5 | 53.1 | Microsoft | PowerShell 7.4 | CWE-918 | PowerShell Information Disclosure Vulnerability |
| CVE-2026-18125 | 7.5 | 52.8 | Ivanti | Endpoint Manager | CWE-125 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version … |
| CVE-2026-50516 | 9.4 | 52.8 | Microsoft | Azure Kubernetes Service | CWE-306 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2026-40375 | 6.5 | 52.6 | Microsoft | Microsoft Dynamics 365 Business Central 2024 Release Wave 2 | CWE-862 | Microsoft Dynamics Business Central Information Disclosure Vulnerability |
| CVE-2026-62902 | 6.5 | 52.4 | Microsoft | .NET 8.0 | CWE-829 | .NET Information Disclosure Vulnerability |
| CVE-2026-70337 | 8.8 | 52.2 | Microsoft | PowerShell 7.4 | CWE-23 | Microsoft PowerShell Remote Code Execution Vulnerability |
| CVE-2026-65660 | 6.5 | 51.7 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-94 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-70306 | 9.3 | 51.4 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-62827 | 8.8 | 51.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-287 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-69223 | 9.1 | 51.2 | Apache Software Foundation | Apache Allura | CWE-918 | Apache Allura: Server-side request forgery |
| CVE-2026-58231 | 10.0 | 51.1 | SAP_SE | SAP Commerce Cloud (Data Hub Adapter) | CWE-94 | Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) |
| CVE-2026-62911 | 8.0 | 50.8 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-294 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-62792 | 8.1 | 50.5 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-62899 | 5.9 | 50.4 | Microsoft | .NET 10.0 | CWE-444 | .NET Security Feature Bypass Vulnerability |
| CVE-2026-72713 | 8.7 | 50.2 | OpenBMB | XAgent | CWE-22 | XAgent Path Traversal Arbitrary File Read via /workspace/file |
| CVE-2026-70324 | 8.8 | 50.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-918 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-48386 | 7.5 | 50.0 | Adobe | ColdFusion 2025 | CWE-327 | ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327) |
| CVE-2026-59113 | 8.8 | 50.0 | Microsoft | Visual Studio Code | CWE-862 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-72538 | 8.8 | 49.9 | PrefectHQ | Prefect | CWE-88 | PrefectHQ Prefect - Argument Injection |
| CVE-2026-48384 | 4.9 | 49.8 | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-68819 | 7.5 | 49.6 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Network File System Denial of Service Vulnerability |
| CVE-2026-66301 | 6.5 | 49.5 | Microsoft | Microsoft Dynamics 365 (on-premises) version 9.1 | CWE-200 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2026-62910 | 8.8 | 49.4 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-99 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-72551 | 8.8 | 48.9 | Apioo | Fusio | CWE-78 | Apioo Fusio - Remote Code Execution |
| CVE-2026-72556 | 8.8 | 48.9 | ZoneMinder | ZoneMinder | CWE-78 | ZoneMinder ZoneMinder - Remote Code Execution |
| CVE-2026-62790 | 8.8 | 48.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2026-65769 | 7.5 | 48.7 | Microsoft | Microsoft Teams for iOS | CWE-200 | Microsoft Teams iOS Information Disclosure Vulnerability |
| CVE-2026-72748 | 6.9 | 48.7 | WWBN | AVideo | CWE-306 | AVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.php |
| CVE-2026-58115 | 10.0 | 48.4 | Siemens | SIMATIC IoT2050 Advanced | CWE-306 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA0… |
| CVE-2026-65794 | 6.5 | 48.3 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-65813 | 8.8 | 48.2 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-918 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-71398 | 10.0 | 47.7 | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-70329 | 8.8 | 47.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2026-48413 | 8.7 | 47.2 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-62839 | 6.5 | 47.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-522 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-61363 | 8.1 | 47.1 | Microsoft | Windows 10 Version 1607 | CWE-20 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-59134 | 8.1 | 47.0 | Microsoft | Windows 10 Version 1607 | CWE-20 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-13457 | 7.5 | 47.0 | instawp | InstaWP Connect – 1-click WP Staging & Migration | CWE-434 | InstaWP Connect <= 0.1.3.6 - Unauthenticated Cryptographic Key Disclosure |
| CVE-2026-62822 | 8.8 | 46.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows GDI+ Remote Code Execution Vulnerability |
| CVE-2026-62913 | 8.8 | 46.8 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-122 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-48440 | 8.1 | 46.7 | Adobe | ColdFusion 2025 | CWE-122 | ColdFusion | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-62824 | 8.8 | 46.5 | Microsoft | Windows 10 Version 1607 | CWE-121 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-65768 | 9.8 | 46.4 | Microsoft | Microsoft Teams for Android | CWE-22 | Microsoft Teams Remote Code Execution Vulnerability |
| CVE-2026-62882 | 4.3 | 45.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-522 | Microsoft Outlook Spoofing Vulnerability |
| CVE-2026-62795 | 8.8 | 45.6 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vu… |
| CVE-2026-70336 | 8.8 | 45.6 | Microsoft | Visual Studio Code | CWE-94 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-70340 | 8.8 | 45.4 | Microsoft | Azure CycleCloud 8.9.1 | CWE-862 | Azure CycleCloud Elevation of Privilege Vulnerability |
| CVE-2026-65791 | 9.8 | 45.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-21273 | 8.7 | 45.1 | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-57105 | 5.4 | 45.0 | Microsoft | Microsoft SharePoint Server 2019 | CWE-79 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-62819 | 8.1 | 44.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulner… |
| CVE-2026-65806 | 6.5 | 44.8 | Microsoft | Azure CycleCloud 8.9.2 | CWE-862 | Azure CycleCloud Information Disclosure Vulnerability |
| CVE-2026-70326 | 8.8 | 44.8 | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-918 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-48375 | 6.5 | 44.8 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-62750 | 6.5 | 44.7 | Microsoft | Windows 10 Version 1607 | CWE-187 | Windows HTTP Protocol Stack Tampering Vulnerability |
| CVE-2026-27302 | 10.0 | 44.6 | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-62889 | 8.1 | 44.0 | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnera… |
| CVE-2026-17061 | 10.0 | 43.8 | Dassault Systèmes | SIMULIA Execution Engine | CWE-502 | Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine f… |
| CVE-2026-62817 | 8.8 | 43.8 | Microsoft | Windows 10 Version 1809 | CWE-787 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-13716 | 9.1 | 43.8 | Arcadia Technology, LLC | Crafty Controller | CWE-35 | Path Traversal: '.../...//' in Crafty Controller |
| CVE-2026-62900 | 5.9 | 43.3 | Microsoft | .NET 10.0 | CWE-212 | .NET Information Disclosure Vulnerability |
| CVE-2026-65679 | 8.1 | 43.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-63512 | 6.5 | 43.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-863 | Microsoft SharePoint Server Tampering Vulnerability |
| CVE-2026-62823 | 8.8 | 43.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-72781 | 8.7 | 42.9 | craftcms | cms | CWE-693 | Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape |
| CVE-2026-62814 | 6.5 | 42.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-48397 | 8.6 | 42.7 | Adobe | Lightroom Classic | CWE-502 | Lightroom Classic | Deserialization of Untrusted Data (CWE-502) |
| CVE-2026-47704 | 7.1 | 42.7 | baptisteArno | typebot.io | CWE-639 | TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` l… |
| CVE-2026-48414 | 7.7 | 42.5 | Adobe | Adobe Commerce | CWE-79 | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-62872 | 8.8 | 42.2 | Microsoft | Microsoft .NET Framework 3.5 | CWE-863 | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-13738 | 9.2 | 42.1 | Commvault | Commvault Cloud | CWE-863 | Improper Authorization Validation |
| CVE-2026-65811 | 8.8 | 41.4 | Microsoft | Power BI Report Server | CWE-20 | Power BI Remote Code Execution Vulnerability |
| CVE-2026-62787 | 7.5 | 41.2 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62781 | 8.1 | 41.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | RPC Runtime Library Remote Code Execution Vulnerability |
| CVE-2026-65796 | 8.1 | 41.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows iSCSI Target Service Remote Code Execution Vulnerability |
| CVE-2026-48438 | 7.5 | 41.0 | Adobe | Content Credentials Rust SDK | CWE-476 | CAI Content Credentials | NULL Pointer Dereference (CWE-476) |
| CVE-2026-48439 | 7.5 | 41.0 | Adobe | Content Credentials Rust SDK | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-44758 | 9.1 | 41.0 | SAP_SE | SAP Manufacturing Integration and Intelligence | CWE-94 | Code Injection vulnerability in Manufacturing Integration and Intelligence |
| CVE-2026-62778 | 8.1 | 40.9 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-48376 | 5.4 | 40.8 | Adobe | ColdFusion 2025 | CWE-116 | ColdFusion | Improper Encoding or Escaping of Output (CWE-116) |
| CVE-2026-16230 | 9.8 | 40.3 | Strategy11 | Formidable Digital Signatures | CWE-23 | Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Delet… |
| CVE-2026-48416 | 7.5 | 40.3 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-48411 | 6.5 | 40.2 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-72602 | 7.5 | 39.9 | AsyncFuncAI | deepwiki-open | CWE-22 | AsyncFuncAI deepwiki-open - Path Traversal |
| CVE-2026-61920 | 6.6 | 39.6 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-62915 | 6.5 | 39.6 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-862 | Microsoft Exchange Server Security Feature Bypass Vulnerability |
| CVE-2024-14042 | 2.1 | 39.5 | n/a | Open5GS | CWE-119 | Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow |
| CVE-2024-14043 | 2.1 | 39.5 | n/a | Open5GS | CWE-119 | Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-ba… |
| CVE-2026-62715 | 6.5 | 39.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62718 | 6.5 | 39.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62742 | 6.5 | 39.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-71362 | 9.1 | 39.2 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-65675 | 6.5 | 39.2 | Microsoft | Microsoft Visual Studio Code CoPilot Chat Extension | CWE-284 | CoPilot Chat Security Feature Bypass Vulnerability |
| CVE-2026-48381 | 9.0 | 39.1 | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-15565 | 7.5 | 39.1 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-120 | Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint w… |
| CVE-2026-19425 | 9.3 | 39.0 | Win Men Intermational | Travel Agency Management System | CWE-89 | Win Men Intermational|Travel Agency Management System - SQL Injection |
| CVE-2026-72770 | 7.1 | 38.8 | n8n-io | n8n | CWE-22 | n8n before 1.123.67 Path Traversal via Git Node Operations |
| CVE-2016-20097 | 8.7 | 38.7 | Weaver Network Co., Ltd. | E-cology 8.0 | CWE-89 | Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad |
| CVE-2026-62714 | 6.5 | 38.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62716 | 6.5 | 38.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-62720 | 6.5 | 38.5 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-29035 | 8.3 | 38.5 | civetweb | civetweb | CWE-787 | CivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate Decompre… |
| CVE-2026-70314 | 5.5 | 38.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70335 | 7.8 | 38.4 | Microsoft | Visual Studio Code | CWE-78 | GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2022-50997 | 8.7 | 38.2 | Weaver Network Co., Ltd. | E-cology 9.0 | CWE-89 | Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp |
| CVE-2026-69109 | 8.7 | 38.2 | Siemens | Siemens License Server (SLS) | CWE-35 | A vulnerability has been identified in Siemens License Server (SLS) (All vers… |
| CVE-2026-70355 | 8.7 | 38.2 | Microsoft | Microsoft SharePoint Server 2019 | CWE-79 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2026-63530 | 5.5 | 38.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-69320 | 8.8 | 37.7 | Microsoft | Visual Studio Code | CWE-78 | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-72548 | 7.5 | 37.7 | OpenSignLabs | OpenSign | CWE-200 | OpenSignLabs OpenSign - Information Disclosure |
| CVE-2026-72543 | 7.5 | 37.4 | OpenSignLabs | OpenSign | CWE-639 | OpenSignLabs OpenSign - Insecure Direct Object Reference |
| CVE-2026-61350 | 4.6 | 37.3 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-72778 | 8.7 | 37.1 | craftcms | cms | CWE-915 | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
| CVE-2026-68797 | 5.5 | 37.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-73232 | 7.5 | 37.1 | ffuf | ffuf | CWE-409 | ffuf denial of service (OOM) via HTTP response decompression bomb |
| CVE-2026-64900 | 5.4 | 37.1 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-65789 | 8.1 | 37.0 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-71331 | 8.1 | 37.0 | Microsoft | Windows 10 Version 1809 | CWE-190 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
| CVE-2026-62820 | 8.1 | 36.9 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2026-65767 | 7.6 | 36.9 | Microsoft | Microsoft Teams for Android | CWE-79 | Microsoft Teams for Android Spoofing Vulnerability |
| CVE-2026-69102 | 9.3 | 36.8 | dromara | MaxKey | CWE-798 | MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust |
| CVE-2026-15562 | 7.5 | 36.7 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-190 | Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pr… |
| CVE-2026-47922 | 4.7 | 36.7 | Adobe | Content Credentials Rust SDK | CWE-918 | CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-34265 | 9.8 | 36.6 | SAP_SE | SAP NetWeaver and ABAP Platform | CWE-787 | Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver … |
| CVE-2026-15560 | 8.1 | 36.6 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-829 | Openjdk-orb: unauthed class loading via iiop in eap |
| CVE-2026-65657 | 7.8 | 36.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-54123 | 5.5 | 36.5 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-200 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
| CVE-2026-62917 | 4.6 | 36.5 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-20 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-73032 | 9.4 | 36.4 | papersgpt | papersgpt-for-zotero | CWE-94 | PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() |
| CVE-2026-15567 | 7.5 | 36.3 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-789 | Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on… |
| CVE-2026-54981 | 7.8 | 36.2 | Microsoft | Python extension for Visual Studio Code | CWE-829 | Visual Studio Code Python Extension Security Feature Bypass Vulnerability |
| CVE-2026-66145 | 9.1 | 36.1 | SonicWall | GMS | CWE-94 | An unauthenticated remote code execution vulnerability was identified in GMS … |
| CVE-2026-65807 | 8.8 | 36.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-72552 | 7.5 | 36.0 | Dub | Dub | CWE-918 | Dub Dub - Server-Side Request Forgery |
| CVE-2026-61352 | 8.1 | 35.7 | Microsoft | Windows 10 Version 1607 | CWE-362 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-39452 | 6.3 | 35.7 | n/a | Intel(R) Transfer Learning Tool | CWE-693 | Protection mechanism failure for some Intel(R) Transfer Learning Tool before … |
| CVE-2026-13737 | 9.2 | 35.4 | Commvault | Commvault Cloud | CWE-863 | Command Restriction Bypass |
| CVE-2026-70348 | 5.5 | 35.5 | Microsoft | Windows 11 Version 24H2 | CWE-59 | Windows Management Services Denial of Service Vulnerability |
| CVE-2026-72535 | 8.6 | 35.4 | Chaskiq | Chaskiq | CWE-306 | Chaskiq Chaskiq - Missing Authentication |
| CVE-2026-72536 | 8.6 | 35.4 | Chaskiq | Chaskiq | CWE-306 | Chaskiq Chaskiq - Missing Authentication |
| CVE-2026-73214 | 8.2 | 35.3 | coturn | coturn | CWE-400 | coturn allocates a full per-peer SSL/session before verifying the DTLS cookie… |
| CVE-2026-72712 | 6.9 | 35.3 | Nmap Project | Nmap | CWE-835 | Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet |
| CVE-2026-73210 | 5.1 | 35.3 | Lookyloo | PlaywrightCapture | CWE-918 | Server-Side Request Forgery via Favicon Retrieval in Lookyloo PlaywrightCapture |
| CVE-2026-68798 | 7.8 | 35.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-51584 | 9.8 | 34.9 | n/a | n/a | CWE-287 | An issue in usememos v0.27.1 allows a remote attacker to achieve account take… |
| CVE-2026-21279 | 8.2 | 34.9 | Adobe | ColdFusion 2025 | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-54984 | 7.8 | 34.9 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Imaging Component Remote Code Execution Vulnerability |
| CVE-2026-18247 | 5.3 | 34.8 | BlackBerry | BlackBerry AtHoc IWS | CWE-79 | DOM-Based Cross-Site Scripting in BlackBerry AtHoc Web Portals |
| CVE-2026-72550 | 9.8 | 34.7 | Friendica | Friendica | CWE-89 | Friendica Friendica - SQL Injection |
| CVE-2026-71217 | 7.5 | 34.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-20 | Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabl… |
| CVE-2026-66806 | 5.5 | 34.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-193 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-62869 | 8.8 | 34.4 | Microsoft | Microsoft Entra | CWE-345 | Azure Entra ID Spoofing Vulnerability |
| CVE-2026-14180 | 5.3 | 34.4 | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-444 | Undertow-core: undertow:http request smuggling via oversized chunk-size bit o… |
| CVE-2026-64897 | 5.4 | 34.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64902 | 5.4 | 34.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64916 | 5.4 | 34.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-64922 | 5.4 | 34.3 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-19424 | 8.7 | 34.1 | Inventec Appliances | Chiline Cloud | CWE-639 | Inventec Appliances|Chiline Cloud - Insecure Direct Object Reference |
| CVE-2026-71467 | 7.5 | 34.1 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-287 | Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated v… |
| CVE-2026-53413 | 8.3 | 34.0 | Zoom Communications | Zoom Clients | CWE-787 | Zoom Clients - Buffer Over-write |
| CVE-2026-62699 | 6.8 | 34.0 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution… |
| CVE-2026-72920 | 9.8 | 34.0 | seaweedfs | seaweedfs | CWE-306 | SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative co… |
| CVE-2026-18692 | 7.7 | 33.7 | MongoDB | MongoDB Server | CWE-416 | Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Servi… |
| CVE-2026-73216 | 6.5 | 33.7 | coturn | coturn | CWE-400 | coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity |
| CVE-2026-69306 | 8.2 | 33.6 | Microsoft | Visual Studio Code | CWE-636 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-68812 | 7.8 | 33.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68814 | 7.8 | 33.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68817 | 7.8 | 33.6 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-19556 | 8.8 | 33.6 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remot… |
| CVE-2026-19559 | 8.8 | 33.6 | Google | Chrome | CWE-416 | Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a rem… |
| CVE-2026-19560 | 8.8 | 33.6 | Google | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a re… |
| CVE-2026-72533 | 8.8 | 32.9 | Portainer | Portainer CE | CWE-287 | Portainer Portainer CE - Authentication Bypass |
| CVE-2026-72545 | 7.5 | 32.9 | OpenSignLabs | OpenSign | CWE-639 | OpenSignLabs OpenSign - Insecure Direct Object Reference |
| CVE-2026-62871 | 7.8 | 32.8 | Microsoft | .NET 8.0 | CWE-787 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-62886 | 7.8 | 32.8 | Microsoft | .NET 10.0 | CWE-190 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-73211 | 9.8 | 32.5 | Chocobozzz | PeerTube | CWE-89 | PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() |
| CVE-2026-62816 | 8.8 | 32.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vu… |
| CVE-2026-58641 | 7.8 | 32.4 | Microsoft | .NET 10.0 | CWE-190 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-58651 | 7.8 | 32.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-64914 | 7.8 | 32.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-68806 | 7.8 | 32.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-787 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-18127 | 7.7 | 32.4 | Ivanti | Endpoint Manager | CWE-73 | External control of a filename in the Core of Ivanti Endpoint Manager before … |
| CVE-2026-4757 | 7.2 | 32.2 | Axis Communications AB | AXIS OS | CWE-732 | A VAPIX API parameter had improper input validation which could allow code ex… |
| CVE-2026-48436 | 6.5 | 32.1 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-53415 | 8.3 | 31.9 | Zoom Communications | Zoom Clients | CWE-416 | Zoom Clients - Use After Free |
| CVE-2026-72767 | 8.7 | 31.9 | n8n-io | n8n | CWE-78 | n8n before 1.123.67 Remote Code Execution via Git node |
| CVE-2026-59128 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
| CVE-2026-59137 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-61347 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Event Logging Service Information Disclosure Vulnerability |
| CVE-2026-61360 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-822 | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-61933 | 5.5 | 31.9 | Microsoft | Windows 11 Version 24H2 | CWE-125 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-62703 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-62709 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows GDI+ Information Disclosure Vulnerability |
| CVE-2026-62730 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Wired AutoConfig Service Information Disclosure Vulnerability |
| CVE-2026-62738 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Management Instrumentation Information Disclosure Vulnerability |
| CVE-2026-62740 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Imaging Component Information Disclosure Vulnerability |
| CVE-2026-62743 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-125 | Win32k Information Disclosure Vulnerability |
| CVE-2026-62746 | 5.5 | 31.9 | Microsoft | Windows 10 Version 1607 | CWE-126 | Win32k Information Disclosure Vulnerability |
| CVE-2026-73226 | 8.8 | 31.7 | electerm | electerm | CWE-913 | Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/fu… |
| CVE-2026-73080 | 9.3 | 31.6 | seaweedfs | seaweedfs | CWE-918 | SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.Fetc… |
| CVE-2026-71218 | 5.3 | 31.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-789 | Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows una… |
| CVE-2026-73241 | 8.3 | 31.3 | FreeRDP | FreeRDP | CWE-287 | FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities … |
| CVE-2026-72773 | 4.9 | 31.3 | n8n-io | n8n | CWE-22 | n8n before 2.32.1 Path Traversal via computer-use search_files |
| CVE-2026-62712 | 7.8 | 31.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62735 | 7.8 | 31.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-48056 | 10.0 | 31.1 | truelockmc | streambert | CWE-20 | Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler |
| CVE-2026-47705 | 9.6 | 30.9 | baptisteArno | typebot.io | CWE-1236 | TypeBot vulnerable to CSV injection in result export |
| CVE-2026-65785 | 6.5 | 30.9 | Microsoft | Windows 11 Version 24H2 | CWE-400 | Windows DHCP Client Denial of Service Vulnerability |
| CVE-2026-63525 | 7.8 | 30.8 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-197 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-58236 | 5.5 | 30.8 | SAP_SE | SAP NetWeaver Application Server ABAP and ABAP Platform | CWE-78 | OS Command Injection vulnerability in Application Server ABAP of SAP NetWeave… |
| CVE-2026-70315 | 5.5 | 30.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70316 | 5.5 | 30.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70319 | 5.5 | 30.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-70320 | 5.5 | 30.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70322 | 5.5 | 30.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70323 | 5.5 | 30.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-70325 | 5.5 | 30.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-72764 | 5.8 | 30.5 | n8n-io | n8n | CWE-668 | n8n before 1.123.67 Module Cache Poisoning via Code Node |
| CVE-2026-72742 | 9.2 | 30.4 | Stanford NLP | DSPy | CWE-73 | DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing |
| CVE-2026-61368 | 5.5 | 30.4 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2026-72765 | 8.7 | 30.2 | n8n-io | n8n | CWE-94 | n8n before 2.32.1 Remote Code Execution via Expression Sandbox Escape |
| CVE-2026-62803 | 7.8 | 30.2 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-62807 | 7.8 | 30.2 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-59136 | 5.5 | 30.1 | Microsoft | Windows 10 Version 1607 | CWE-908 | Microsoft COM for Windows Information Disclosure Vulnerability |
| CVE-2026-73031 | 8.2 | 29.5 | GramSearch | telegram-search | CWE-79 | telegram-search Stored XSS via v-html in MessageList.vue |
| CVE-2026-56721 | 8.7 | 29.2 | owen2345 | CamaleonCMS | CWE-639 | CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersContro… |
| CVE-2026-62688 | 7.8 | 29.2 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-62698 | 7.8 | 29.2 | Microsoft | Windows 10 Version 1607 | CWE-197 | Microsoft Digest Authentication Elevation of Privilege Vulnerability |
| CVE-2026-73088 | 7.5 | 29.2 | browserslist | browserslist | CWE-248 | Browserslist: Uncaught crash / prototype write via untrusted browserslist-sta… |
| CVE-2026-62745 | 6.5 | 29.2 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-73089 | 7.5 | 29.1 | browserslist | browserslist | CWE-770 | Browserslist: Unbounded memory growth (no cache eviction) via distinct query … |
| CVE-2026-62842 | 5.5 | 29.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-63517 | 5.5 | 29.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-70318 | 5.5 | 29.1 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-70317 | 5.5 | 29.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-72971 | 5.5 | 28.8 | Microsoft | Windows 11 version 26H1 | CWE-59 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerab… |
| CVE-2026-65656 | 7.8 | 28.7 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-77 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-59119 | 7.3 | 28.7 | Microsoft | PowerShell 7.4 | CWE-276 | PowerShell Elevation of Privilege Vulnerability |
| CVE-2026-62829 | 5.4 | 28.7 | Microsoft | Microsoft SharePoint Server 2019 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-73069 | 9.1 | 28.6 | twentyhq | twenty | CWE-89 | Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary P… |
| CVE-2026-62761 | 7.8 | 28.6 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-72600 | 7.5 | 28.6 | Idurar | IDURAR ERP CRM | CWE-284 | Idurar IDURAR ERP CRM - Broken Access Control |
| CVE-2026-72601 | 7.5 | 28.6 | CSZ CMS | CSZ CMS | CWE-284 | CSZ CMS CSZ CMS - Broken Access Control |
| CVE-2026-72549 | 5.3 | 28.6 | OpenSignLabs | OpenSign | CWE-200 | OpenSignLabs OpenSign - Information Disclosure |
| CVE-2026-15426 | 8.8 | 28.3 | acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | CWE-269 | AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to … |
| CVE-2026-66802 | 8.1 | 28.3 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
| CVE-2026-63513 | 7.8 | 28.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63515 | 7.8 | 28.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-63518 | 7.8 | 28.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63519 | 7.8 | 28.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-65664 | 7.8 | 28.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-66807 | 7.8 | 28.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-68794 | 7.8 | 28.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68804 | 7.8 | 28.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-197 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-40130 | 5.3 | 28.2 | SAP_SE | SAPSPrint Service | CWE-121 | Memory Corruption vulnerability in SAPSPrint Service |
| CVE-2026-73242 | 8.3 | 28.0 | FreeRDP | FreeRDP | CWE-122 | FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-b… |
| CVE-2026-15561 | 7.5 | 28.1 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-770 | Undertow-core: oom via missing limits in chunked trailer in eap's undertow |
| CVE-2026-48415 | 7.6 | 27.9 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-73246 | 7.5 | 27.8 | kestra-io | kestra | CWE-200 | Kestra: Unauthenticated management `/worker` endpoint exposes live task confi… |
| CVE-2026-63524 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-63528 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-63529 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-63531 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-64899 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-64917 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-68799 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68802 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68808 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-68813 | 5.5 | 27.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-24329 | 4.9 | 27.4 | Red Hat | Red Hat Fuse 7 | CWE-91 | Wildfly-core: wildfly core: denial of service via malformed payload injection… |
| CVE-2026-19434 | 5.1 | 27.3 | maalfer | Pentestify | CWE-79 | Stored Cross-site Scripting in Pentestify finding severity field |
| CVE-2026-18706 | 7.5 | 27.2 | MongoDB | MongoDB Server | CWE-416 | Use-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of S… |
| CVE-2026-48494 | 7.1 | 27.1 | baptisteArno | typebot.io | CWE-639 | TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via globa… |
| CVE-2026-73219 | 5.3 | 27.2 | cvat-ai | cvat | CWE-1288 | CVAT: Denial of service with regards to automatic annotation |
| CVE-2026-73244 | 5.3 | 27.1 | kekingcn | kkFileView | CWE-22 | kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrar… |
| CVE-2026-63526 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-63532 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64898 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64903 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64907 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64909 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-191 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64910 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64911 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-68816 | 7.8 | 27.0 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-73224 | 8.8 | 26.8 | electerm | electerm | CWE-78 | Electerm check folder size function may get attacked by unsafe folder name |
| CVE-2026-11734 | 1.1 | 26.8 | NETGEAR | MR70 | CWE-121 | Device administrator can interrupt the normal operation of some NETGEAR Night… |
| CVE-2026-72599 | 9.8 | 26.7 | e107 | e107 | CWE-89 | e107 e107 - SQL Injection |
| CVE-2026-59130 | 5.6 | 26.6 | Microsoft | Windows 10 Version 1607 | CWE-200 | AMD Zen Information Disclosure Vulnerability |
| CVE-2026-73078 | 8.6 | 26.5 | vim | vim | CWE-77 | Vim: Arbitrary Code Execution via Netrw Menu Construction |
| CVE-2026-70338 | 7.8 | 26.4 | Microsoft | PowerShell 7.4 | CWE-94 | Microsoft PowerShell Security Feature Bypass Vulnerability |
| CVE-2026-62914 | 5.4 | 26.4 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-79 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-61359 | 7.8 | 26.3 | Microsoft | Windows 11 version 23H2 | CWE-122 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-62797 | 7.8 | 26.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62811 | 7.8 | 26.3 | Microsoft | Windows 11 version 23H2 | CWE-122 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-72554 | 6.5 | 26.3 | Ladybird Web Solution | Faveo Helpdesk | CWE-284 | Ladybird Web Solution Faveo Helpdesk - Broken Access Control |
| CVE-2026-62737 | 7.8 | 26.2 | Microsoft | Windows 11 Version 24H2 | CWE-822 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-70330 | 7.8 | 26.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-73215 | 7.1 | 25.9 | coturn | coturn | CWE-400 | The coturn server can end in a state where it does not accept more requests w… |
| CVE-2026-48483 | 5.4 | 25.9 | baptisteArno | typebot.io | CWE-918 | TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, a… |
| CVE-2026-73156 | 5.3 | 25.9 | MISP | cti-transmute | CWE-79 | cti-transmute Sunburst and Treemap Tooltips Allow Cross-Site Scripting via Cr… |
| CVE-2026-62897 | 7.0 | 25.8 | Microsoft | .NET 10.0 | CWE-190 | .NET Framework Remote Code Execution Vulnerability |
| CVE-2026-72557 | 8.8 | 25.7 | Cockpit CMS | Cockpit CMS | CWE-434 | Cockpit CMS Cockpit CMS - Unrestricted File Upload |
| CVE-2026-58650 | 7.8 | 25.6 | Microsoft | Visual Studio Code | CWE-639 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-69278 | 7.8 | 25.6 | Microsoft | Visual Studio Code | CWE-863 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-48813 | 8.7 | 25.5 | david-a-wheeler | flawfinder | CWE-74 | Flawfinder output manipulation via untrusted filenames and source text |
| CVE-2026-11733 | 1.1 | 25.5 | NETGEAR | RAX41 | CWE-121 | Buffer overflow vulnerability in some NETGEAR Nighthawk routers |
| CVE-2026-18972 | 9.6 | 25.3 | Rapid7 | Velociraptor | CWE-290 | Velociraptor authenticated identity-spoofing vulnerability |
| CVE-2026-20702 | 8.9 | 25.4 | n/a | Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts. | CWE-693 | Protection mechanism failure for some Intel(R) Data Center Attestation Primit… |
| CVE-2026-65661 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-68793 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68795 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68796 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68800 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68801 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68805 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-70313 | 7.8 | 25.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-62769 | 6.7 | 25.3 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62881 | 6.7 | 25.3 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-72604 | 6.5 | 25.3 | Intelliants | Subrion CMS | CWE-22 | Intelliants Subrion CMS - Path Traversal |
| CVE-2026-18697 | 8.7 | 25.2 | MongoDB | MongoDB Server | CWE-617 | Improper Input Validation in MongoDB Aggregation Framework Allows Unauthentic… |
| CVE-2026-61925 | 7.8 | 25.1 | Microsoft | Windows 10 Version 1607 | CWE-863 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-19539 | 8.6 | 25.0 | Roskus | Prospero Flow CRM | CWE-862 | IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and del… |
| CVE-2026-62721 | 7.8 | 25.0 | Microsoft | Windows 10 Version 1607 | CWE-1220 | Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability |