Edition of August 11, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-65673 | 7.8 | 25.0 | Microsoft | Microsoft Entra Connect | CWE-89 | Microsoft Entra Connect Elevation of Privilege Vulnerability |
| CVE-2026-73228 | 5.3 | 24.9 | encode | django-rest-framework | CWE-400 | Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZ… |
| CVE-2026-59135 | 5.5 | 24.8 | Microsoft | Windows 10 Version 1607 | CWE-1390 | Microsoft Windows Search Component Information Disclosure Vulnerability |
| CVE-2026-62732 | 7.8 | 24.6 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-48802 | 7.5 | 24.5 | miguelgrinberg | python-engineio | CWE-770 | python-engineio has unbound thread allocation that can cause denial of service |
| CVE-2026-15606 | 8.8 | 24.4 | shabti | Frontend Admin by DynamiApps | CWE-862 | Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrar… |
| CVE-2026-73243 | 5.8 | 24.4 | kekingcn | kkFileView | CWE-918 | kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusio… |
| CVE-2026-20715 | 8.2 | 24.3 | n/a | Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | CWE-20 | Improper input validation in some firmware for some Intel(R) Active Managemen… |
| CVE-2026-70130 | 7.8 | 24.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-70304 | 7.8 | 24.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-62708 | 6.4 | 24.4 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-48766 | 7.6 | 24.2 | baptisteArno | typebot.io | CWE-200 | TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-… |
| CVE-2026-48767 | 7.6 | 24.2 | baptisteArno | typebot.io | CWE-200 | Google Sheets OAuth access token disclosure to guest members via getAccessToken |
| CVE-2026-69119 | 7.2 | 24.2 | Taubyte | tau | CWE-639 | Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id} |
| CVE-2026-48412 | 2.7 | 24.2 | Adobe | Adobe Commerce | CWE-863 | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-66777 | 5.9 | 24.1 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-22 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-18640 | 7.1 | 24.0 | Rapid7 | Velociraptor | CWE-22 | Velociraptor directory traversal via the NewNotebook API |
| CVE-2026-11735 | 1.9 | 24.0 | NETGEAR | R7000 | CWE-121 | Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models |
| CVE-2026-11736 | 1.9 | 24.0 | NETGEAR | RAX20 | CWE-20 | Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers |
| CVE-2026-48763 | 8.2 | 23.8 | baptisteArno | typebot.io | CWE-862 | TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint vi… |
| CVE-2026-73217 | 7.7 | 23.9 | cursor | cursor | CWE-693 | Cursor: Sandbox escape via tampered Python virtual environments |
| CVE-2026-62786 | 5.5 | 23.9 | Microsoft | Windows 10 Version 1607 | CWE-125 | Win32k Information Disclosure Vulnerability |
| CVE-2026-62793 | 5.5 | 23.9 | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-62796 | 5.5 | 23.9 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-62798 | 5.5 | 23.9 | Microsoft | Windows 11 version 23H2 | CWE-822 | Win32k Information Disclosure Vulnerability |
| CVE-2026-65662 | 5.5 | 23.9 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-73223 | 8.1 | 23.8 | electerm | electerm | CWE-22 | electerm: Path traversal in editWithSystemEditor temp file path via unsanitiz… |
| CVE-2026-73225 | 8.1 | 23.8 | electerm | electerm | CWE-22 | electerm: Path traversal in FTP/SFTP recursive folder download via unsanitize… |
| CVE-2026-73227 | 8.1 | 23.8 | electerm | electerm | CWE-22 | electerm's RDP clipboard file download may parse unsafe file name |
| CVE-2026-59127 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-61353 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-61355 | 7.8 | 23.8 | Microsoft | Windows 10 Version 21H2 | CWE-122 | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-61357 | 7.8 | 23.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Application Information Services Elevation of Privilege Vulnerability |
| CVE-2026-61923 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Display Enhancement Service Elevation of Privilege Vulnerability |
| CVE-2026-61926 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows USB Driver Elevation of Privilege Vulnerability |
| CVE-2026-61932 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-61934 | 7.8 | 23.8 | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-61937 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62692 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-62695 | 7.8 | 23.8 | Microsoft | Windows 11 version 23H2 | CWE-122 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-62700 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62701 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62707 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability |
| CVE-2026-62710 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Device Association Service Elevation of Privilege Vulnerability |
| CVE-2026-62711 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62717 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-62719 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-62722 | 7.8 | 23.8 | Microsoft | Windows 11 Version 24H2 | CWE-122 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-62747 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Device Association Service Elevation of Privilege Vulnerability |
| CVE-2026-62751 | 7.8 | 23.8 | Microsoft | Windows 10 Version 21H2 | CWE-190 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-62752 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62754 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62768 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-65787 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-122 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-70344 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70346 | 7.8 | 23.8 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-70347 | 7.8 | 23.7 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-73079 | 8.5 | 23.6 | Wei-Shaw | sub2api | CWE-22 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated… |
| CVE-2026-58243 | 8.8 | 23.6 | SAP_SE | SAP ABAP Developer Tools | CWE-862 | Privilege Escalation vulnerability in SAP ABAP Developer Tools |
| CVE-2026-13739 | 8.8 | 23.5 | Commvault | Commvault Cloud | CWE-918 | Server-Side Request Forgery (SSRF) |
| CVE-2026-72605 | 7.5 | 23.4 | Swing Music | Swing Music | CWE-306 | Swing Music Swing Music - Missing Authentication |
| CVE-2026-72749 | 7.1 | 23.4 | n8n-io | n8n | CWE-1321 | n8n before 1.123.67 Prototype Pollution via Edit Fields |
| CVE-2026-72534 | 8.8 | 23.3 | Authentik Security | authentik | CWE-269 | Authentik Security authentik - Privilege Escalation |
| CVE-2026-19546 | 8.8 | 23.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-94 | Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via call… |
| CVE-2026-72539 | 6.5 | 23.1 | Windmill Labs | Windmill | CWE-200 | Windmill Labs Windmill - Information Disclosure |
| CVE-2026-18860 | 8.7 | 23.0 | Rapid7 | Velociraptor | CWE-280 | Velociraptor incorrect Org deletion permissions check |
| CVE-2026-10579 | 9.8 | 22.9 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-347 | Picketlink-federation: auth bypass in picketlink saml unsolicited-response |
| CVE-2026-19557 | 8.3 | 22.9 | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 al… | |
| CVE-2026-63527 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-63533 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64904 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-64905 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64906 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64908 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64912 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64915 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-64919 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-121 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-64920 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Access Remote Code Execution Vulnerability |
| CVE-2026-68803 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68807 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68810 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68811 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-68815 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-70311 | 7.8 | 22.9 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Word Remote Code Execution Vulnerability |
| CVE-2026-73213 | 5.8 | 23.0 | coturn | coturn | CWE-863 | Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a l… |
| CVE-2026-18701 | 7.1 | 22.8 | MongoDB | MongoDB Server | CWE-843 | Type Confusion in MongoDB Query Subsystem Leads to Denial of Service |
| CVE-2026-73160 | 8.7 | 22.7 | MISP | cti-transmute | CWE-918 | cti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP Add… |
| CVE-2026-35502 | 4.6 | 22.6 | n/a | Intel(R) Extension for PyTorch | CWE-502 | Deserialization of untrusted data for some Intel(R) Extension for PyTorch bef… |
| CVE-2026-65784 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-55676 | 8.8 | 22.4 | cisagov | Malcolm | CWE-434 | Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload com… |
| CVE-2026-62887 | 5.5 | 22.4 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-73081 | 8.7 | 22.3 | activepieces | activepieces | CWE-78 | Activepieces: Remote Code Execution via Command Injection in Code Step Name |
| CVE-2026-24330 | 6.5 | 22.2 | Red Hat | Red Hat Fuse 7 | CWE-434 | Wildfly-core: wildfly: arbitrary file read via malicious archive deployment |
| CVE-2026-73247 | 8.6 | 22.2 | kestra-io | kestra | CWE-918 | Kestra: SSRF via Pebble http() function allows unauthenticated access to inte… |
| CVE-2026-73086 | 7.4 | 22.2 | ai | nanoid | CWE-190 | nanoid: Integer Overflow or Wraparound |
| CVE-2026-6181 | 5.9 | 22.1 | Axis Communications AB | AXIS OS | CWE-290 | The Device Configuration Framework is vulnerable to an authentication bypass … |
| CVE-2026-71386 | 8.8 | 22.1 | Adobe | ColdFusion 2025 | CWE-79 | ColdFusion | Cross-site Scripting (XSS) (CWE-79) |
| CVE-2026-72774 | 7.1 | 22.0 | n8n-io | n8n | CWE-639 | n8n before 1.123.67 Authentication Bypass via HTTP Request Node |
| CVE-2026-70354 | 7.8 | 21.9 | Microsoft | .NET 10.0 | CWE-787 | .NET Core Remote Code Execution Vulnerability |
| CVE-2026-72537 | 8.8 | 21.7 | Authentik Security | authentik | CWE-269 | Authentik Security authentik - Privilege Escalation |
| CVE-2026-51583 | 8.5 | 21.5 | n/a | n/a | CWE-918 | An issue in usememos through v0.30.0 allows a remote authenticated attacker t… |
| CVE-2026-56174 | 7.8 | 21.6 | Microsoft | Windows 10 Version 1809 | CWE-426 | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-62812 | 7.8 | 21.6 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-15563 | 7.4 | 21.5 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-306 | Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads … |
| CVE-2026-63521 | 5.5 | 21.4 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-18695 | 7.1 | 21.4 | MongoDB | MongoDB Server | CWE-617 | Improper Input Validation in MongoDB Timeseries Query Processing Leads to Den… |
| CVE-2026-18638 | 6.5 | 21.4 | Rapid7 | Velociraptor | CWE-476 | Velociraptor server crash via the SetPassword API |
| CVE-2026-18699 | 6.0 | 21.4 | MongoDB | MongoDB Server | CWE-476 | Improper Input Validation in MongoDB Query Planner Leads to Denial of Service |
| CVE-2026-18700 | 6.0 | 21.4 | MongoDB | MongoDB Server | CWE-416 | Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service |
| CVE-2026-62909 | 7.8 | 21.3 | Microsoft | .NET 10.0 | CWE-252 | .NET Elevation of Privilege Vulnerability |
| CVE-2026-65777 | 5.3 | 21.3 | Microsoft | Windows 11 version 23H2 | CWE-326 | Active Directory Security Feature Bypass Vulnerability |
| CVE-2026-18696 | 7.0 | 21.2 | MongoDB | MongoDB Server | CWE-863 | Improper Authorization in MongoDB applyOps Command Handling Allows Unauthoriz… |
| CVE-2026-68067 | 9.3 | 20.9 | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | CWE-1390 | Mira Hormone Monitor, Mira Android App Weak Authentication |
| CVE-2026-59131 | 5.6 | 20.9 | Microsoft | Windows 10 Version 1607 | — | AMD Zen Information Disclosure Vulnerability |
| CVE-2026-18708 | 5.3 | 20.9 | MongoDB | MongoDB Server | CWE-94 | Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Eng… |
| CVE-2026-72606 | 7.5 | 20.8 | Pinry | Pinry | CWE-918 | Pinry Pinry - Server-Side Request Forgery |
| CVE-2026-65680 | 6.7 | 20.8 | Microsoft | OneDrive for MacOS | CWE-59 | Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability |
| CVE-2026-44763 | 7.6 | 20.7 | SAP_SE | SAP Manufacturing Integration and Intelligence | CWE-22 | Directory Traversal vulnerability in SAP Manufacturing Integration and Intell… |
| CVE-2026-73212 | 5.8 | 20.7 | coturn | coturn | CWE-284 | coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNEC… |
| CVE-2026-61936 | 5.5 | 20.7 | Microsoft | Windows 10 Version 1809 | CWE-862 | Windows Defender Firewall Service Security Feature Bypass Vulnerability |
| CVE-2026-58248 | 6.5 | 20.6 | SAP_SE | SAP BusinessObjects Business Intelligence | CWE-611 | XML External Entity Injection in SAP BusinessObjects Business Intelligence |
| CVE-2026-71475 | 5.0 | 20.5 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-22 | Insights-client-rhel9: insights-client: spoke-controlled clusterid injected u… |
| CVE-2026-65655 | 2.3 | 20.5 | Temporal Technologies, Inc. | Temporal UI Server | CWE-614 | Temporal UI Server may set OAuth credential cookies without Secure behind a T… |
| CVE-2026-48804 | 7.5 | 20.4 | miguelgrinberg | python-socketio | CWE-770 | python-socketio: Binary attachment accumulation can cause denial of service |
| CVE-2026-48809 | 7.5 | 20.4 | miguelgrinberg | python-engineio | CWE-770 | python-engineio has possible denial of service due to maximum payload size so… |
| CVE-2026-72766 | 8.2 | 20.2 | n8n-io | n8n | CWE-843 | n8n before 1.123.67 Arbitrary File Read via Send Email Node |
| CVE-2026-61356 | 7.8 | 20.3 | Microsoft | Windows 10 Version 1809 | CWE-306 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61364 | 7.8 | 20.3 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61365 | 7.8 | 20.3 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-61367 | 7.8 | 20.3 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2026-63522 | 7.8 | 20.2 | Microsoft | Azure SQL Database | CWE-732 | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-44765 | 7.3 | 20.2 | SAP_SE | SAP Manufacturing Integration and Intelligence | CWE-862 | Missing Authorization Check in SAP Manufacturing Integration and Intelligence |
| CVE-2026-62788 | 7.0 | 20.3 | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-66809 | 5.5 | 20.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Graphics Component Information Disclosure Vulnerability |
| CVE-2026-66810 | 5.5 | 20.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-68809 | 5.5 | 20.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-459 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-70310 | 5.5 | 20.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-70312 | 5.5 | 20.2 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Powerpoint Information Disclosure Vulnerability |
| CVE-2026-53414 | 6.5 | 20.0 | Zoom Communications | Zoom Clients | CWE-126 | Zoom Clients - Buffer Over-read |
| CVE-2026-48046 | 9.3 | 19.7 | truelockmc | streambert | CWE-494 | Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Upd… |
| CVE-2026-73229 | 4.3 | 19.7 | encode | django-rest-framework | CWE-200 | Django REST framework: AdminRenderer may disclose GET-protected data when ren… |
| CVE-2026-19519 | 4.3 | 19.6 | Red Hat | Red Hat Advanced Cluster Security 4 | CWE-617 | Claircore: claircore: denial of service via unchecked type assertion in rpm h… |
| CVE-2026-71387 | 8.8 | 19.4 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-62776 | 7.8 | 19.5 | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-72922 | 8.2 | 19.2 | Significant-Gravitas | AutoGPT | CWE-287 | AutoGPT: Webhook provider path confusion bypasses generic webhook secret veri… |
| CVE-2026-68821 | 7.8 | 19.3 | Microsoft | App Installer | CWE-269 | Windows Package Manager Elevation of Privilege Vulnerability |
| CVE-2026-18705 | 7.1 | 19.2 | MongoDB | MongoDB Server | CWE-807 | Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Acc… |
| CVE-2026-18711 | 7.1 | 19.2 | MongoDB | MongoDB Server | CWE-416 | Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service a… |
| CVE-2026-42142 | 7.1 | 19.3 | baptisteArno | typebot.io | CWE-862 | TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that A… |
| CVE-2026-72598 | 6.5 | 19.3 | Apioo | Fusio | CWE-918 | Apioo Fusio - Server-Side Request Forgery |
| CVE-2026-21269 | 5.4 | 19.2 | Adobe | ColdFusion 2025 | CWE-79 | ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-62890 | 7.8 | 19.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows GDI+ Elevation of Privilege Vulnerability |
| CVE-2026-66799 | 7.8 | 19.2 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Key Guard Elevation of Privilege Vulnerability |
| CVE-2026-70307 | 7.0 | 19.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-18688 | 7.1 | 19.0 | MongoDB | MongoDB Server | CWE-125 | Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Servic… |
| CVE-2026-18694 | 7.1 | 19.0 | MongoDB | MongoDB Server | CWE-125 | Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of … |
| CVE-2026-65810 | 7.8 | 18.9 | Microsoft | Microsoft .NET Framework 3.5 | CWE-23 | .NET Framework Elevation of Privilege Vulnerability |
| CVE-2026-73085 | 5.3 | 18.9 | advplyr | audiobookshelf | CWE-287 | Audiobookshelf: Refresh Token Accepted on Resource Endpoints |
| CVE-2026-73087 | 2.3 | 18.9 | amir20 | dozzle | CWE-918 | Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) i… |
| CVE-2026-71383 | 7.3 | 18.5 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-72607 | 7.1 | 18.6 | Koha Community | Koha | CWE-89 | Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Mod… |
| CVE-2026-66146 | 6.1 | 18.3 | SonicWall | GMS | CWE-79 | Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.… |
| CVE-2026-15555 | 8.8 | 18.3 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-502 | Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss des… |
| CVE-2026-72555 | 8.1 | 18.2 | Peppermint Lab | Peppermint | CWE-284 | Peppermint Lab Peppermint - Broken Access Control |
| CVE-2026-18639 | 7.3 | 18.2 | Rapid7 | Velociraptor | CWE-290 | Velociraptor OIDC Authenticator susceptible to email spoofing |
| CVE-2026-18707 | 5.3 | 18.0 | MongoDB | MongoDB Server | CWE-617 | Improper Input Validation in MongoDB Aggregation Command Handling Leads to De… |
| CVE-2026-73157 | 2.3 | 18.1 | MISP | cti-transmute | CWE-79 | cti-transmute Remote MISP Event Browser Allows Cross-Site Scripting via Malic… |
| CVE-2026-58238 | 5.9 | 17.8 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-770 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-19078 | 4.3 | 17.8 | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-601 | Ose-oauth-server: oauth-server: open redirect vulnerability enables phishing … |
| CVE-2026-18690 | 7.2 | 17.7 | MongoDB | MongoDB Server | CWE-863 | Improper Authorization in MongoDB Server Allows Unauthorized Actions on Syste… |
| CVE-2026-62775 | 5.5 | 17.7 | Microsoft | Windows 11 version 26H1 | CWE-863 | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclo… |
| CVE-2026-72747 | 5.1 | 17.7 | WWBN | AVideo | CWE-79 | AVideo Stored Cross-Site Scripting via Unauthenticated Registration |
| CVE-2026-29036 | 8.7 | 17.7 | DaveGamble | cJSON | CWE-706 | cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding |
| CVE-2026-62799 | 7.8 | 17.5 | Microsoft | Windows 11 version 26H1 | CWE-122 | Windows SMB Client Elevation of Privilege Vulnerability |
| CVE-2026-65671 | 7.8 | 17.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Remote Access API Elevation of Privilege Vulnerability |
| CVE-2026-65672 | 7.8 | 17.5 | Microsoft | Windows 11 version 23H2 | CWE-122 | Remote Access API Elevation of Privilege Vulnerability |
| CVE-2026-65774 | 7.8 | 17.5 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-18635 | 7.2 | 17.5 | Rapid7 | Velociraptor | CWE-863 | Velociraptor query plugin allows impersonation in other orgs |
| CVE-2026-48765 | 9.9 | 17.3 | baptisteArno | typebot.io | CWE-639 | TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAut… |
| CVE-2026-62757 | 5.9 | 17.2 | Microsoft | Windows 10 Version 1607 | CWE-347 | Windows Schannel Security Feature Bypass Vulnerability |
| CVE-2026-73140 | 5.3 | 17.3 | MISP | cti-transmute | CWE-862 | cti-transmute Evaluation Report Exports Expose Private Comments and Author In… |
| CVE-2026-73155 | 5.3 | 17.3 | MISP | cti-transmute | CWE-862 | cti-transmute Missing Authorization Allows Reactions to Private Comments |
| CVE-2026-72769 | 6.1 | 17.0 | n8n-io | n8n | CWE-1321 | n8n before 1.123.67 Prototype Pollution via VM Expression Engine |
| CVE-2026-65814 | 7.8 | 16.9 | Microsoft | Windows 10 Version 1607 | CWE-122 | Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability |
| CVE-2026-62723 | 7.0 | 16.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62724 | 7.0 | 16.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62726 | 7.0 | 16.8 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-48495 | 7.1 | 16.7 | baptisteArno | typebot.io | CWE-862 | TypeBot Google Sheets OAuth callback can create credentials in unauthorized w… |
| CVE-2026-62883 | 6.7 | 16.7 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65795 | 6.7 | 16.7 | Microsoft | Windows 10 Version 1607 | — | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65797 | 6.7 | 16.7 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-65798 | 6.7 | 16.7 | Microsoft | Windows 10 Version 1607 | CWE-197 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-56720 | 5.3 | 16.7 | owen2345 | CamaleonCMS | CWE-862 | CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action |
| CVE-2026-69117 | 7.1 | 16.6 | NetBox Labs | NetBox | CWE-639 | NetBox 4.5.8 ORM Injection via WritableNestedSerializer |
| CVE-2026-68792 | 7.8 | 16.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-77 | Microsoft Office Elevation of Privilege Vulnerability |
| CVE-2026-63133 | 6.5 | 16.5 | cisagov | Malcolm | CWE-770 | Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Ex… |
| CVE-2026-63134 | 5.4 | 16.4 | cisagov | Malcolm | CWE-22 | Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Cre… |
| CVE-2026-73249 | 7.5 | 16.3 | kovidgoyal | calibre | CWE-862 | calibre Content Server `/book-update-annotations` Missing Write Authorization… |
| CVE-2026-73161 | 5.1 | 16.3 | MISP | cti-transmute | CWE-79 | cti-transmute Conversion Table Allows XSS via Unescaped Cell Content During S… |
| CVE-2026-11737 | 4.3 | 16.3 | NETGEAR | RAX20 | CWE-20 | Some NETGEAR Nighthawk devices allow administrators to tamper with the device |
| CVE-2026-19558 | 7.5 | 16.1 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed… | |
| CVE-2026-50472 | 7.0 | 16.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerab… |
| CVE-2026-59125 | 7.0 | 16.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
| CVE-2026-61346 | 7.0 | 16.1 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-61361 | 7.0 | 16.1 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows DHCP Client Remote Code Execution Vulnerability |
| CVE-2026-61366 | 7.0 | 16.1 | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows Network Connection Broker Elevation of Privilege Vulnerability |
| CVE-2026-61938 | 7.0 | 16.1 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-61939 | 7.0 | 16.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Winlogon Elevation of Privilege Vulnerability |
| CVE-2026-73082 | 5.3 | 16.1 | activepieces | activepieces | CWE-200 | Activepieces: Server-side request forgery in MCP tool validation endpoint |
| CVE-2026-73221 | 5.3 | 16.1 | cvat-ai | cvat | CWE-863 | CVAT: Flawed authorization logic in endpoints related to lambda requests |
| CVE-2026-18348 | 4.1 | 16.1 | Rapid7 | Velociraptor | CWE-863 | Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb V… |
| CVE-2026-20708 | 5.9 | 15.9 | n/a | Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | CWE-532 | Insertion of sensitive information into log file in the subsystem for the Int… |
| CVE-2026-20765 | 4.6 | 15.8 | n/a | Intel(R) TDX Guest software | CWE-697 | Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.… |
| CVE-2026-71384 | 9.6 | 15.7 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-65799 | 7.8 | 15.8 | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-58230 | 7.0 | 15.7 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-601 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66875 | 8.7 | 15.5 | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | CWE-306 | Mira Hormone Monitor, Mira Android App Missing authentication for critical fu… |
| CVE-2026-65773 | 7.8 | 15.6 | Microsoft | Windows 10 Version 1809 | CWE-284 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-48442 | 7.1 | 15.6 | Adobe | Content Credentials Rust SDK | CWE-22 | CAI Content Credentials | Improper Limitation of a Pathname to a Restricted D… |
| CVE-2026-48446 | 5.5 | 15.6 | Adobe | Content Credentials Rust SDK | CWE-22 | CAI Content Credentials | Improper Limitation of a Pathname to a Restricted D… |
| CVE-2026-67568 | 9.3 | 15.5 | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | CWE-798 | Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials |
| CVE-2026-62733 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62736 | 7.8 | 15.3 | Microsoft | Windows 11 version 23H2 | CWE-122 | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-62739 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62755 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows DHCP Client Elevation of Privilege Vulnerability |
| CVE-2026-62758 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
| CVE-2026-62770 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Shell Elevation of Privilege Vulnerability |
| CVE-2026-62771 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62772 | 7.8 | 15.3 | Microsoft | Windows 11 version 26H1 | CWE-122 | Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privi… |
| CVE-2026-62779 | 7.8 | 15.3 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Schannel Elevation of Privilege Vulnerability |
| CVE-2026-62876 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62877 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-121 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62880 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-62885 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-62894 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-65786 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-65790 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Message Queuing Elevation of Privilege Vulnerability |
| CVE-2026-70345 | 7.8 | 15.3 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-72558 | 8.8 | 15.2 | CiviCRM | CiviCRM | CWE-89 | CiviCRM CiviCRM - SQL Injection |
| CVE-2026-72562 | 8.8 | 15.2 | Pimcore | pimcore admin-ui-classic-bundle | CWE-89 | Pimcore pimcore admin-ui-classic-bundle - SQL Injection |
| CVE-2026-72921 | 8.1 | 15.1 | seaweedfs | seaweedfs | CWE-863 | SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenan… |
| CVE-2026-61349 | 7.8 | 15.1 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Work Folder Service Elevation of Privilege Vulnerability |
| CVE-2026-69115 | 7.1 | 15.1 | OpenIMSDK | OpenIM Server (open-im-server) | CWE-862 | OpenIM Server v3.8.3 Missing Authorization on User and Group Enumeration Endp… |
| CVE-2026-19579 | 5.3 | 15.0 | Grokability | Snipe-IT | CWE-639 | Snipe-IT Checkout Request Cancellation IDOR |
| CVE-2026-66340 | 6.9 | 14.8 | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | CWE-307 | Mira Hormone Monitor, Mira Android App Improper restriction of excessive auth… |
| CVE-2026-18636 | 6.8 | 14.8 | Rapid7 | Velociraptor | CWE-288 | Velociraptor VFSGetBuffer API path deny list bypass |
| CVE-2026-44764 | 7.3 | 14.7 | SAP_SE | SAP Manufacturing Integration and Intelligence | CWE-862 | Missing Authorization Check in SAP Manufacturing Integration and Intelligence |
| CVE-2026-70339 | 5.4 | 14.7 | Microsoft | Microsoft Edge (Chromium-based) | CWE-843 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-56179 | 8.3 | 14.5 | Microsoft | Windows 11 Version 24H2 | CWE-346 | Windows Network Address Translation (NAT) Spoofing Vulnerability |
| CVE-2026-66778 | 5.3 | 14.6 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-644 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-73158 | 5.1 | 14.5 | MISP | cti-transmute | CWE-20 | cti-transmute Saved Graph Configuration Allows Stored Cross-Site Scripting vi… |
| CVE-2026-73159 | 5.1 | 14.5 | MISP | cti-transmute | CWE-79 | cti-transmute Stored XSS via Crafted Tag Icon on Admin Triage Interface |
| CVE-2026-72561 | 8.8 | 14.3 | Peppermint Lab | Peppermint | CWE-284 | Peppermint Lab Peppermint - Broken Access Control |
| CVE-2026-5304 | 5.7 | 14.3 | Axis Communications AB | AXIS OS | CWE-1287 | An ACAP configuration file lacks input validation, which could potentially le… |
| CVE-2026-18691 | 9.0 | 14.2 | MongoDB | MongoDB Server | CWE-757 | Improper Authentication in MongoDB Intra-Cluster Connections Allows Credentia… |
| CVE-2026-73084 | 6.1 | 14.2 | activepieces | activepieces | CWE-79 | Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint |
| CVE-2026-18693 | 7.2 | 13.8 | MongoDB | MongoDB Server | CWE-787 | Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denia… |
| CVE-2026-72541 | 6.5 | 13.8 | Windmill Labs | Windmill | CWE-306 | Windmill Labs Windmill - Missing Authorization |
| CVE-2026-72768 | 6.4 | 13.8 | n8n-io | n8n | CWE-918 | n8n before 2.32.1 SSRF Protection Bypass via MCP Client |
| CVE-2026-72542 | 5.4 | 13.8 | Windmill Labs | Windmill | CWE-306 | Windmill Labs Windmill - Missing Authorization |
| CVE-2026-72780 | 7.1 | 13.6 | craftcms | cms | CWE-294 | Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey |
| CVE-2026-72782 | 7.1 | 13.7 | craftcms | cms | CWE-668 | Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak |
| CVE-2026-19516 | 9.1 | 13.5 | Grafana | Grafana MCP Server | CWE-918 | CVE-2026-19516 CVE Record |
| CVE-2026-65776 | 7.0 | 13.4 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-66832 | 6.9 | 13.4 | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | CWE-598 | Mira Hormone Monitor, Mira Android App Use of GET request method with sensiti… |
| CVE-2026-73090 | 9.3 | 13.3 | Chocobozzz | PeerTube | CWE-863 | PeerTube: Cross-origin remote video takeover via Update activity |
| CVE-2026-72608 | 6.5 | 13.2 | Koha Community | Koha | CWE-89 | Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name |
| CVE-2026-48762 | 5.4 | 13.1 | baptisteArno | typebot.io | CWE-918 | TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcript… |
| CVE-2026-69113 | 5.3 | 13.1 | CapSoftware | Cap | CWE-862 | Cap v0.3.1 Broken Access Control via video comment endpoint |
| CVE-2026-15554 | 7.4 | 13.0 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-295 | Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery |
| CVE-2026-18634 | 8.4 | 12.9 | SonicWall | GMS | CWE-502 | An insecure handling of serialized objects vulnerability was found in the one… |
| CVE-2026-66774 | 3.7 | 12.9 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-754 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66761 | 4.3 | 12.8 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-770 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-58239 | 3.7 | 12.7 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-807 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-20878 | 7.1 | 12.7 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-476 | Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for … |
| CVE-2026-72609 | 7.1 | 12.7 | Koha Community | Koha | CWE-89 | Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl |
| CVE-2026-20886 | 6.9 | 12.7 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-787 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windo… |
| CVE-2026-72779 | 8.7 | 12.5 | craftcms | cms | CWE-184 | Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject |
| CVE-2026-15556 | 8.1 | 12.5 | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4.25 | CWE-347 | Picketlink-federation: picketlink saml 2.0 auth bypass via missing assertions |
| CVE-2026-8158 | 5.3 | 12.2 | Axis Communications AB | Signed Video Framework | — | The Signed Video Framework contained a buffer overflow issue which could lead… |
| CVE-2026-72772 | 8.9 | 12.2 | n8n-io | n8n | CWE-640 | n8n before 2.32.1 Authentication Bypass via Token Exchange |
| CVE-2026-50236 | 7.4 | 12.2 | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-918 | Openshift/console: authenticated ssrf with full response reflection and path … |
| CVE-2026-72763 | 7.2 | 12.2 | n8n-io | n8n | CWE-639 | n8n before 1.123.67 Credential Exfiltration via Sub-Workflow |
| CVE-2026-72771 | 7.1 | 12.2 | n8n-io | n8n | CWE-863 | n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes |
| CVE-2026-66771 | 6.1 | 12.2 | SAP_SE | SAPUI5 | CWE-79 | Cross Site Scripting (XSS) vulnerability in SAPUI5 |
| CVE-2026-58237 | 5.9 | 12.2 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-862 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-42976 | 7.8 | 12.1 | Microsoft | Windows 10 Version 1607 | CWE-306 | Remote Access Management service/API (RPC server) Elevation of Privilege Vuln… |
| CVE-2026-62777 | 7.8 | 12.1 | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows License Manager Elevation of Privilege Vulnerability |
| CVE-2026-65678 | 7.0 | 12.0 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-65778 | 7.0 | 12.0 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65779 | 7.0 | 12.0 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-48443 | 6.2 | 12.1 | Adobe | Content Credentials Rust SDK | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-48444 | 6.2 | 12.1 | Adobe | Content Credentials Rust SDK | CWE-190 | CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-48445 | 6.2 | 12.1 | Adobe | Content Credentials Rust SDK | CWE-190 | CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-58247 | 5.3 | 12.0 | SAP_SE | SAP ABAP Platform | CWE-908 | Memory Corruption vulnerability in SAP ABAP Platform |
| CVE-2026-19418 | 7.3 | 11.8 | TYPO3 | TYPO3 CMS | CWE-346 | TYPO3 CMS - Broken Access Control in Backend and Install Tool |
| CVE-2026-18704 | 7.1 | 11.8 | MongoDB | MongoDB Server | CWE-862 | Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User… |
| CVE-2026-72546 | 7.1 | 11.7 | Attendize | Attendize | CWE-639 | Attendize Attendize - Insecure Direct Object Reference |
| CVE-2026-72547 | 7.1 | 11.7 | Attendize | Attendize | CWE-639 | Attendize Attendize - Insecure Direct Object Reference |
| CVE-2026-72775 | 5.8 | 11.7 | n8n-io | n8n | CWE-89 | n8n before 1.123.67 SQL Injection via PostgresTrigger Node |
| CVE-2026-72750 | 5.3 | 11.7 | n8n-io | n8n | CWE-89 | n8n before 1.123.67 SQL Injection via executeQuery Operation |
| CVE-2026-72596 | 8.1 | 11.5 | Ghost Foundation | Ghost | CWE-284 | Ghost Foundation Ghost - Broken Access Control |
| CVE-2026-61928 | 5.5 | 11.6 | Microsoft | Windows 10 Version 1607 | CWE-312 | Windows Hello Tampering Vulnerability |
| CVE-2026-48771 | 8.2 | 11.3 | Ishankjha740 | ishankportfolio | CWE-200 | ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Si… |
| CVE-2026-18702 | 5.3 | 11.4 | MongoDB | MongoDB Server | CWE-269 | Improper Authorization in MongoDB profile Command Allows Unauthorized Modific… |
| CVE-2026-71845 | 6.3 | 10.8 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-532 | Insights-client: insights-client: ccx_token bearer credential logged in clear… |
| CVE-2026-72762 | 7.7 | 10.7 | n8n-io | n8n | CWE-434 | n8n before 1.123.67 Arbitrary File Write via Edit Image Node |
| CVE-2026-62725 | 7.0 | 10.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-72544 | 7.5 | 10.6 | OpenSignLabs | OpenSign | CWE-345 | OpenSignLabs OpenSign - Insufficient Verification of Data Authenticity |
| CVE-2026-73222 | 8.8 | 10.5 | davila7 | claude-code-templates | CWE-78 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude C… |
| CVE-2026-62780 | 7.0 | 10.5 | Microsoft | Windows 11 version 23H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-72563 | 8.1 | 10.3 | BadChoice | Handesk | CWE-284 | BadChoice Handesk - Broken Access Control |
| CVE-2026-72595 | 8.1 | 10.3 | BadChoice | Handesk | CWE-284 | BadChoice Handesk - Broken Access Control |
| CVE-2026-72560 | 6.5 | 10.3 | HumanSignal | Label Studio | CWE-918 | HumanSignal Label Studio - Server-Side Request Forgery |
| CVE-2026-72597 | 6.5 | 10.3 | Friendica | Friendica | CWE-918 | Friendica Friendica - Server-Side Request Forgery |
| CVE-2026-66779 | 6.3 | 10.3 | SAP_SE | SAP NetWeaver Application Server ABAP | CWE-79 | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server … |
| CVE-2026-66149 | 7.8 | 10.0 | SonicWall | Email Security | CWE-94 | Improper Control of Generation of Code ('Code Injection') Vulnerability in th… |
| CVE-2026-66150 | 7.8 | 10.0 | SonicWall | Email Security | CWE-94 | Improper Control of Generation of Code ('Code Injection') Vulnerability in th… |
| CVE-2026-62749 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62753 | 7.0 | 10.1 | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows HTTP.sys Elevation of Privilege Vulnerability |
| CVE-2026-62773 | 7.0 | 10.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-62774 | 7.0 | 10.1 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2026-62892 | 7.0 | 10.1 | Microsoft | Windows 10 Version 1809 | CWE-416 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerab… |
| CVE-2026-65780 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-415 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65781 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65782 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-65783 | 7.0 | 10.1 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Autopilot Elevation of Privilege Vulnerability |
| CVE-2026-19517 | 6.5 | 10.1 | Samsung Open Source | rlottie | CWE-1284 | Improper Validation of Specified Quantity in Input and Allocation of Resource… |
| CVE-2026-19518 | 6.5 | 10.1 | Samsung Open Source | rlottie | CWE-1284 | Improper Validation of Specified Quantity in Input vulnerability in Samsung O… |
| CVE-2026-71474 | 6.3 | 10.0 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-532 | Insights-client-rhel9: insights-client: pull-secret bearer token written to l… |
| CVE-2026-72610 | 4.3 | 10.0 | Koha Community | Koha | CWE-89 | Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Sli… |
| CVE-2026-66098 | 7.1 | 9.8 | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | CWE-306 | Mira Hormone Monitor, Mira Android App Missing authentication for critical fu… |
| CVE-2026-11738 | 4.3 | 9.8 | NETGEAR | R7000 | CWE-20 | Insufficient input validation in certain NETGEAR Nighthawk routers allows adm… |
| CVE-2026-47702 | 9.1 | 9.7 | baptisteArno | typebot.io | CWE-312 | TypeBot API tokens stored in plaintext |
| CVE-2026-72785 | 9.3 | 9.5 | craftcms | cms | CWE-863 | Craft CMS before 5.10.6 Authorization Bypass via structures/move-element |
| CVE-2026-73245 | 6.5 | 9.4 | kestra-io | kestra | CWE-306 | Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/… |
| CVE-2026-72925 | 6.1 | 9.4 | swc-project | swc | CWE-79 | SWC HTML minifier may allow script element breakout when minifying embedded JSON |
| CVE-2026-66773 | 5.9 | 9.4 | SAP_SE | Odata | CWE-601 | Server-controlled `__next` URL is not checking cross-origin |
| CVE-2026-48441 | 8.6 | 9.3 | Adobe | Lightroom Classic | CWE-22 | Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directo… |
| CVE-2026-62729 | 7.0 | 9.3 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62734 | 7.0 | 9.3 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-62748 | 7.0 | 9.3 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-19550 | 4.3 | 9.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-863 | Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a priv… |
| CVE-2026-34635 | 8.4 | 9.1 | Adobe | ColdFusion 2025 | CWE-321 | ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321) |
| CVE-2026-71468 | 5.3 | 9.1 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-266 | Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via glo… |
| CVE-2026-59122 | 7.0 | 8.8 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-59126 | 7.0 | 8.8 | Microsoft | Windows 10 Version 21H2 | CWE-362 | Windows Event Logging Service Elevation of Privilege Vulnerability |
| CVE-2026-61927 | 7.0 | 8.8 | Microsoft | Windows 11 Version 24H2 | CWE-416 | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62690 | 7.0 | 8.8 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-62693 | 7.0 | 8.8 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows MIDI Service Module Elevation of Privileges Vulnerability |
| CVE-2026-62705 | 7.0 | 8.8 | Microsoft | Windows 11 Version 24H2 | CWE-362 | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-62728 | 7.0 | 8.8 | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-71290 | 9.1 | 8.6 | Apache Software Foundation | Apache HttpComponents Client | CWE-295 | Apache HttpComponents Client: TLS hostname verification silently disabled on … |
| CVE-2026-12052 | 5.2 | 8.7 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in USB CDC NCM control handler when host wLength is small… |
| CVE-2026-73068 | 5.9 | 8.4 | ToolJet | ToolJet | CWE-639 | ToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db):… |
| CVE-2026-64934 | 5.3 | 8.2 | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | CWE-807 | Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a secu… |
| CVE-2026-66772 | 4.3 | 8.1 | SAP_SE | SAP BusinessObjects Business Intelligence Platform (Admin Tools) | CWE-862 | Missing Authorization Check in SAP BusinessObjects Business Intelligence Plat… |
| CVE-2026-47940 | 7.8 | 8.0 | Adobe | Lightroom Classic | CWE-190 | Lightroom Classic | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-63177 | 7.1 | 7.6 | cisagov | Malcolm | CWE-863 | Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential… |
| CVE-2026-18712 | 7.2 | 7.3 | MongoDB | MongoDB Server | CWE-863 | Improper Authorization in MongoDB Queryable Encryption Maintenance Operations… |
| CVE-2026-24911 | 8.3 | 7.2 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-121 | Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software f… |
| CVE-2026-14548 | 6.5 | 7.2 | Unknown | Ray Enterprise Translation | CWE-862 | Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update |
| CVE-2026-58235 | 6.3 | 7.2 | SAP_SE | SAP NetWeaver AS Java (Adobe Document Services) | CWE-1395 | Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Docum… |
| CVE-2026-73162 | 5.3 | 7.2 | MISP | cti-transmute | CWE-352 | cti-transmute CSRF Allows Unauthorized Follow and Notification State Changes |
| CVE-2026-20727 | 8.3 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-476 | Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for … |
| CVE-2026-20776 | 8.3 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software | CWE-754 | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software wit… |
| CVE-2026-22887 | 8.3 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-119 | Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software … |
| CVE-2026-20749 | 7.2 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software | CWE-125 | Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Rin… |
| CVE-2026-20739 | 7.1 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-754 | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for… |
| CVE-2026-20745 | 7.1 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-787 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windo… |
| CVE-2026-20747 | 7.1 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software | CWE-754 | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software wit… |
| CVE-2026-20787 | 7.1 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-476 | Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for … |
| CVE-2026-20795 | 7.1 | 6.9 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-119 | Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software … |
| CVE-2026-58245 | 3.8 | 6.9 | SAP_SE | SAP Advanced Planning and Optimization (Model Mix Planning) | CWE-798 | Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix P… |
| CVE-2026-53416 | 7.1 | 6.8 | Zoom Communications | Zoom VDI | CWE-23 | Zoom VDI - Path Traversal |
| CVE-2026-11894 | 5.9 | 6.7 | zephyrproject | zephyr | CWE-415 | Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` err… |
| CVE-2026-25194 | 1.8 | 6.7 | n/a | Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | CWE-787 | Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allo… |
| CVE-2026-50237 | 7.4 | 6.7 | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-918 | Openshift/console: namespace tenant ssrf with egress bypass, catalog poisonin… |
| CVE-2026-67558 | 8.2 | 6.5 | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | CWE-290 | Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing |
| CVE-2026-18687 | 7.1 | 6.5 | MongoDB | MongoDB Server | CWE-191 | Improper Validation in MongoDB Queryable Encryption Maintenance Operation Lea… |
| CVE-2026-5303 | 5.7 | 6.5 | Axis Communications AB | AXIS OS | CWE-367 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race cond… |
| CVE-2026-18698 | 5.3 | 6.5 | MongoDB | MongoDB Server | CWE-863 | Improper Authorization in MongoDB Server Allows Unauthorized Actions on Syste… |
| CVE-2026-58244 | 4.3 | 6.5 | SAP_SE | SAP Manufacturing Integration and Intelligence | CWE-862 | Missing Authorization Check in SAP Manufacturing Integration and Intelligence… |
| CVE-2026-66764 | 4.3 | 6.5 | SAP_SE | SAP S/4 HANA (Reprocess Bank Statement Items) | CWE-639 | Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items) |
| CVE-2026-12051 | 4.6 | 6.4 | zephyrproject | zephyr | CWE-476 | NULL pointer dereference in USB DFU device_next download handler (handle_down… |
| CVE-2026-67180 | 7.5 | 6.1 | Turbinia | CWE-78 | Google Turbinia arbitrary command execution | |
| CVE-2026-48387 | 6.2 | 6.1 | Adobe | Content Credentials Rust SDK | CWE-190 | CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-48434 | 6.2 | 6.1 | Adobe | Content Credentials Rust SDK | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-48435 | 6.2 | 6.1 | Adobe | Content Credentials Rust SDK | CWE-191 | CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
| CVE-2026-32677 | 5.4 | 6.0 | n/a | gaudi-container-runtime | CWE-22 | Path traversal for some gaudi-container-runtime before version 1.24.0 within … |
| CVE-2026-59693 | 5.3 | 6.0 | Siemens | Desigo DXR2 | CWE-754 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233… |
| CVE-2026-73282 | 4.8 | 5.9 | OpenBSD | OpenSSH | CWE-416 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if… |
| CVE-2026-9214 | 4.3 | 6.0 | NETGEAR | R7000 | CWE-20 | Insufficient input validation in NETGEAR R7000 router allows administrators t… |
| CVE-2026-6726 | 7.9 | 5.9 | Trusted Computing Group | TPM2.0 | CWE-704 | An information leakage vulnerability in the TCG TPM 2.0 reference code. |
| CVE-2026-72553 | 5.4 | 5.9 | ElkArte Forum | ElkArte | CWE-79 | ElkArte Forum ElkArte - Cross-Site Scripting |
| CVE-2026-48404 | 7.8 | 5.5 | Adobe | Lightroom Classic | CWE-787 | Lightroom Classic | Out-of-bounds Write (CWE-787) |
| CVE-2026-48405 | 7.8 | 5.5 | Adobe | Lightroom Classic | CWE-787 | Lightroom Classic | Out-of-bounds Write (CWE-787) |
| CVE-2026-48406 | 7.8 | 5.5 | Adobe | Lightroom Classic | CWE-787 | Lightroom Classic | Out-of-bounds Write (CWE-787) |
| CVE-2026-48407 | 7.8 | 5.5 | Adobe | Lightroom Classic | CWE-787 | Lightroom Classic | Out-of-bounds Write (CWE-787) |
| CVE-2026-48408 | 7.8 | 5.5 | Adobe | Lightroom Classic | CWE-787 | Lightroom Classic | Out-of-bounds Write (CWE-787) |
| CVE-2026-48409 | 7.8 | 5.5 | Adobe | Lightroom Classic | CWE-787 | Lightroom Classic | Out-of-bounds Write (CWE-787) |
| CVE-2026-48410 | 7.8 | 5.5 | Adobe | Lightroom Classic | CWE-787 | Lightroom Classic | Out-of-bounds Write (CWE-787) |
| CVE-2026-73234 | 7.8 | 5.5 | FreeCAD | FreeCAD | CWE-22 | FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized fil… |
| CVE-2026-20891 | 6.3 | 5.5 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-287 | Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for W… |
| CVE-2026-11893 | 5.9 | 5.5 | zephyrproject | zephyr | CWE-415 | Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (h… |
| CVE-2026-58241 | 4.2 | 5.5 | SAP_SE | SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard | CWE-862 | Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Tr… |
| CVE-2026-73281 | 3.5 | 5.5 | OpenBSD | OpenSSH | CWE-669 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but w… |
| CVE-2026-66770 | 6.3 | 5.4 | SAP_SE | SAP Social Intelligence | CWE-89 | SQL Injection vulnerability in SAP Social Intelligence |
| CVE-2026-73083 | 7.6 | 5.3 | activepieces | activepieces | CWE-693 | Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading |
| CVE-2026-16974 | 6.4 | 5.3 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-79 | Kirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authen… |
| CVE-2026-71390 | 4.0 | 5.2 | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-73231 | 7.8 | 5.1 | faker-js | faker | CWE-95 | Faker: helpers.fake exploitable into arbritary code execution |
| CVE-2026-20903 | 5.4 | 5.1 | n/a | Intel(R) AI Containers | CWE-693 | Protection mechanism failure for some Intel(R) AI Containers before version v… |
| CVE-2026-20906 | 5.4 | 5.1 | n/a | Intel(R) Neural Compressor software | CWE-693 | Protection mechanism failure for some Intel(R) Neural Compressor software bef… |
| CVE-2026-21387 | 5.4 | 5.1 | n/a | Intel(R) LLM Library for PyTorch | CWE-693 | Protection mechanism failure for some Intel(R) LLM Library for PyTorch within… |
| CVE-2026-21400 | 5.4 | 5.1 | n/a | Intel(R) AI Reference Models | CWE-693 | Protection mechanism failure for some Intel(R) AI Reference Models before ver… |
| CVE-2026-28700 | 5.4 | 5.1 | n/a | EquiTriton | CWE-427 | Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ri… |
| CVE-2026-32788 | 5.4 | 5.1 | n/a | Approximate Bayesian Inference Framework | CWE-427 | Uncontrolled search path for some Approximate Bayesian Inference Framework be… |
| CVE-2026-34175 | 5.4 | 5.1 | n/a | Hardware-Aware-Automated-MachineLearning NA | CWE-427 | Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA… |
| CVE-2026-62908 | 7.0 | 5.0 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Backup Engine Elevation of Privilege Vulnerability |
| CVE-2026-71389 | 6.2 | 5.0 | Adobe | Content Credentials Rust SDK | CWE-191 | CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
| CVE-2026-6727 | 5.9 | 5.0 | Trusted Computing Group | TPM2.0 | CWE-208 | CVE-2026-6727 |
| CVE-2026-14549 | 4.3 | 4.9 | Unknown | Ray Enterprise Translation | CWE-862 | Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and Deletion |
| CVE-2026-19391 | 6.5 | 4.8 | Red Hat | Pen Drive Powered by Red Hat Lightspeed | CWE-312 | Insights-core: insights-core: incomplete credential redaction exposes sssd bi… |
| CVE-2026-73233 | 8.5 | 4.7 | FreeCAD | FreeCAD | CWE-94 | FreeCAD: FEM formula incomplete escape |
| CVE-2026-73248 | 8.5 | 4.6 | kovidgoyal | calibre | CWE-94 | calibre: Bypass of Python template restrictions via nested `template()` leadi… |
| CVE-2026-20778 | 7.0 | 4.5 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-125 | Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Window… |
| CVE-2026-20885 | 7.0 | 4.5 | n/a | Intel(R) platforms | CWE-287 | Improper authentication in the Intel(R) TDX module for some Intel(R) platform… |
| CVE-2026-72783 | 6.9 | 4.5 | craftcms | cms | CWE-22 | Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained |
| CVE-2025-48506 | 4.6 | 4.6 | AMD | Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows | CWE-427 | Uncontrolled search paths in Vitis™ Unified installation path on local Window… |
| CVE-2026-25652 | 7.8 | 4.5 | Adobe | ColdFusion 2025 | CWE-863 | ColdFusion | Incorrect Authorization (CWE-863) |
| CVE-2026-72784 | 6.9 | 4.2 | craftcms | cms | CWE-918 | Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation |
| CVE-2026-48447 | 7.7 | 4.2 | Adobe | Lightroom Classic | CWE-863 | Lightroom Classic | Incorrect Authorization (CWE-863) |
| CVE-2026-20769 | 6.9 | 4.1 | n/a | Intel(R) NPU Driver | CWE-754 | Improper conditions check for the Intel(R) NPU Driver for all versions within… |
| CVE-2026-20786 | 6.9 | 4.1 | n/a | Intel(R) NPU Driver | CWE-125 | Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3… |
| CVE-2026-20752 | 6.7 | 4.1 | n/a | Intel(R) PROSet/Wireless WiFi Software | CWE-287 | Improper authentication for some Intel(R) PROSet/Wireless WiFi Software withi… |
| CVE-2026-44762 | 3.7 | 4.0 | SAP_SE | SAP Data Services Management Console | CWE-1021 | Security Misconfiguration in SAP Data Services Management Console |
| CVE-2026-18709 | 5.9 | 3.9 | MongoDB | MongoDB Server | CWE-862 | Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Le… |
| CVE-2026-73077 | 8.4 | 3.9 | vim | vim | CWE-78 | Vim: Arbitrary Code Execution via Shell Keyword Lookup |
| CVE-2026-66776 | 5.9 | 3.7 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-347 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2025-0041 | 4.6 | 3.7 | AMD | Vitis™ Embedded Single File Download (SFD) for Windows | CWE-427 | Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) f… |
| CVE-2026-67179 | 7.8 | 3.6 | genkit-ai | genkit | CWE-644 | Genkit improper host header validation |
| CVE-2026-72744 | 6.9 | 3.5 | nuxt | nuxt | CWE-200 | Nuxt before 4.5.1 Information Disclosure via Chrome DevTools |
| CVE-2026-20737 | 6.3 | 3.4 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-200 | Exposure of sensitive information to an unauthorized actor for some Intel(R) … |
| CVE-2026-73036 | 4.6 | 3.3 | Bash-it | Bash-it | CWE-150 | Bash-it barbuk Theme 3.2.0 Terminal Escape Sequence Injection via pyproject.toml |
| CVE-2026-18844 | 7.2 | 3.3 | Pulsetto | Vagus Nerve Stimulator | CWE-912 | Pulsetto Vagus Nerve Stimulator Hidden Functionality |
| CVE-2026-72559 | 5.4 | 3.3 | Daniel Brendel | HortusFox | CWE-79 | Daniel Brendel HortusFox - Cross-Site Scripting |
| CVE-2026-33921 | 4.8 | 3.3 | Nozomi Networks | Arc | CWE-1188 | Npcap driver installed without administrator-only access restriction on Windo… |
| CVE-2026-24099 | 5.9 | 3.2 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-416 | Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows wi… |
| CVE-2026-73076 | 8.4 | 3.1 | vim | vim | CWE-94 | Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay … |
| CVE-2026-66763 | 7.9 | 3.2 | SAP_SE | SAP BusinessObjects Business Intelligence Platform (Central Management Server) | CWE-321 | Credentials disclosure in SAP BusinessObjects Business Intelligence Platform … |
| CVE-2026-66154 | 8.3 | 3.1 | SonicWall | GMS | CWE-295 | An insufficient certificate validation in a privileged communication workflow… |
| CVE-2026-20780 | 6.9 | 3.0 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-400 | Uncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Soft… |
| CVE-2026-73250 | 5.4 | 3.0 | notepad-plus-plus | notepad-plus-plus | CWE-77 | Notepad++: Install-time PowerShell command injection through installation path |
| CVE-2026-73230 | 5.9 | 2.9 | ente | ente | CWE-200 | Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-e… |
| CVE-2026-72694 | 7.1 | 2.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Mrtg: mrtg daemon symlink-following chown allows local privilege escalation v… |
| CVE-2026-20789 | 8.4 | 2.7 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-284 | Improper access control for some Intel(R) PROSet/Wireless WiFi Software for W… |
| CVE-2026-73066 | 6.8 | 2.7 | tesseract-ocr | tesseract | CWE-787 | Tesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .train… |
| CVE-2026-73067 | 6.7 | 2.7 | tesseract-ocr | tesseract | CWE-125 | Tesseract: Heap OOB read in the DAWG loader |
| CVE-2026-73072 | 8.5 | 2.6 | vim | vim | CWE-122 | Vim: Heap Buffer Overflow when Loading a Spell File |
| CVE-2026-73235 | 6.1 | 2.7 | FreeCAD | FreeCAD | CWE-611 | FreeCAD: XXE file read and SSRF via external entity injection in Document.xml… |
| CVE-2026-20890 | 7.1 | 2.5 | n/a | Intel(R) PROSet/Wireless WiFi Software for Windows | CWE-269 | Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software… |
| CVE-2026-33922 | 6.8 | 2.5 | Nozomi Networks | Arc | CWE-22 | Path traversal in the Offline archives functionality of the local web interfa… |
| CVE-2026-66775 | 4.3 | 2.6 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-352 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-20741 | 8.3 | 2.2 | n/a | Intel(R) PROSet/Wireless WiFi Software | CWE-284 | Improper access control for some Intel(R) PROSet/Wireless WiFi Software withi… |
| CVE-2026-66760 | 6.4 | 2.1 | SAP_SE | SAP Business AI Platform (Approuter) | CWE-295 | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-20734 | 5.6 | 2.1 | n/a | Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | CWE-665 | Improper initialization in some firmware for some Intel(R) Active Management … |
| CVE-2026-20728 | 5.4 | 2.2 | n/a | Intel Extension for TensorFlow software | CWE-693 | Protection mechanism failure for some Intel Extension for TensorFlow software… |
| CVE-2026-20755 | 5.4 | 2.2 | n/a | LLM Scaler software | CWE-693 | Protection mechanism failure for some LLM Scaler software within Ring 3: User… |
| CVE-2026-20770 | 5.4 | 2.2 | n/a | Cluster Management Toolkit for Kubernetes software | CWE-693 | Protection mechanism failure for some Cluster Management Toolkit for Kubernet… |
| CVE-2026-24693 | 5.4 | 2.2 | n/a | Intel(R) oneCCL Bindings for PyTorch | CWE-693 | Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch be… |
| CVE-2026-28707 | 5.4 | 2.2 | n/a | LLM-on-Ray | CWE-693 | Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ri… |
| CVE-2026-28757 | 5.4 | 2.2 | n/a | Intel(R) Workload Services Framework software | CWE-693 | Protection mechanism failure for some Intel(R) Workload Services Framework so… |
| CVE-2026-20763 | 4.6 | 2.1 | n/a | Intel(R) TDX Guest software | CWE-682 | Incorrect calculation for some Intel(R) TDX Guest software before version 0.3… |
| CVE-2026-20712 | 4.0 | 2.1 | n/a | Intel(R) reference platforms | CWE-459 | Incomplete cleanup in some UEFI firmware for some Intel(R) reference platform… |
| CVE-2026-43606 | 8.5 | 2.1 | AMD | Vitis™ Libraries - Security Module | CWE-208 | Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 comp… |
| CVE-2026-17535 | 6.2 | 2.0 | Rapid7 | Velociraptor | CWE-125 | Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Vol… |
| CVE-2026-20898 | 8.5 | 2.0 | n/a | in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts. | CWE-284 | Improper access control in the firmware for some in Alias Checking Trusted Mo… |
| CVE-2025-8087 | 7.0 | 2.0 | AMD | AMD Power Design Manager (PDM) Software Un-Installer | CWE-427 | A DLL hijacking vulnerability in AMD Power Design Manager could allow a malic… |
| CVE-2025-54512 | 7.0 | 2.0 | AMD | AMD Ryzen™ Master | CWE-427 | A DLL hijacking vulnerability within the AMD Ryzen Master installation could … |
| CVE-2026-73075 | 4.6 | 2.0 | vim | vim | CWE-124 | Vim: Out-of-bounds Access in Popup Opacity Handling |
| CVE-2026-32791 | 5.4 | 1.9 | n/a | Intel(R) Performance Counter Monitor (Intel(R) PCM) | CWE-426 | Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R)… |
| CVE-2026-59086 | 7.3 | 1.8 | Siemens | Simcenter Femap | CWE-121 | A vulnerability has been identified in Simcenter Femap (All versions < V2606)… |
| CVE-2026-18703 | 2.3 | 1.8 | MongoDB | MongoDB Server | CWE-863 | Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Serv… |
| CVE-2026-8917 | 8.4 | 1.7 | ASUS | GPU Tweak III | CWE-822 | Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, a… |
| CVE-2026-21399 | 6.9 | 1.7 | n/a | Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) | CWE-122 | Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel… |
| CVE-2026-0465 | 5.6 | 1.7 | AMD | AMD Ryzen™ Master | CWE-416 | A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver … |
| CVE-2026-18710 | 8.2 | 1.7 | MongoDB | MongoDB Driver | CWE-532 | Cleartext Storage of Sensitive Information in MongoDB Driver Logging During C… |
| CVE-2026-50058 | 7.3 | 1.7 | Siemens | Solid Edge SE2025 | CWE-125 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225… |
| CVE-2026-50059 | 7.3 | 1.7 | Siemens | Solid Edge SE2025 | CWE-787 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225… |
| CVE-2026-50060 | 7.3 | 1.7 | Siemens | Solid Edge SE2025 | CWE-416 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225… |
| CVE-2026-50061 | 7.3 | 1.7 | Siemens | Solid Edge SE2025 | CWE-416 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225… |
| CVE-2026-50062 | 7.3 | 1.7 | Siemens | Solid Edge SE2025 | CWE-125 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225… |
| CVE-2026-50063 | 7.3 | 1.7 | Siemens | Solid Edge SE2025 | CWE-125 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225… |
| CVE-2026-50064 | 7.3 | 1.7 | Siemens | Solid Edge SE2025 | CWE-787 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225… |
| CVE-2026-59700 | 7.3 | 1.7 | Siemens | Simcenter Femap | CWE-125 | A vulnerability has been identified in Simcenter Femap (All versions < V2606.… |
| CVE-2026-59701 | 7.3 | 1.7 | Siemens | Simcenter Femap | CWE-125 | A vulnerability has been identified in Simcenter Femap (All versions < V2606.… |
| CVE-2026-64629 | 7.3 | 1.7 | Siemens | Parasolid V38.0 | CWE-125 | A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.… |
| CVE-2025-48505 | 1.0 | 1.7 | AMD | Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows | CWE-276 | Weak permissions in the Vitis™ Unified installation path on local Windows mac… |
| CVE-2026-69108 | 8.3 | 1.6 | Siemens | Siemens License Server (SLS) | CWE-732 | A vulnerability has been identified in Siemens License Server (SLS) (All vers… |
| CVE-2026-57262 | 7.0 | 1.6 | Siemens | LOGO! Soft Comfort | CWE-321 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9)… |
| CVE-2026-20731 | 6.9 | 1.6 | n/a | Intel(R) NPU Driver | CWE-119 | Improper buffer restrictions for the Intel(R) NPU Driver for all versions wit… |
| CVE-2026-20783 | 6.9 | 1.6 | n/a | Intel(R) NPU Driver | CWE-754 | Improper conditions check in the firmware for the Intel(R) NPU Driver for all… |
| CVE-2026-27765 | 6.8 | 1.6 | n/a | vLLM Hardware Plugin for Intel(R) Gaudi(R) software | CWE-20 | Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R)… |
| CVE-2026-20913 | 4.8 | 1.6 | n/a | Intel(R) Neural Compressor software | CWE-20 | Improper input validation for some Intel(R) Neural Compressor software before… |
| CVE-2026-28729 | 2.4 | 1.6 | n/a | Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (none) and availability (low) impacts. | CWE-190 | Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may al… |
| CVE-2026-73070 | 6.8 | 1.6 | vim | vim | CWE-121 | Vim: Stack Buffer Overflow in the Vim Socket Server |
| CVE-2026-20917 | 4.0 | 1.5 | n/a | Intel(R) Processors | CWE-1422 | Exposure of sensitive information caused by incorrect data forwarding during … |
| CVE-2026-73071 | 3.3 | 1.4 | vim | vim | CWE-416 | Vim: Use-after-free in JSON Decoding |
| CVE-2026-73074 | 7.1 | 1.4 | vim | vim | CWE-190 | Vim: Heap Buffer Overflow in Text Property Handling |
| CVE-2025-0046 | 7.0 | 1.3 | AMD | AMD Power Design Manager (PDM) Software Installer for Windows | CWE-732 | Incorrect directory permissions could allow a local user to escalate their pr… |
| CVE-2026-72693 | 7.8 | 1.2 | Red Hat | Red Hat Hardened Images | CWE-284 | Kbd: local privilege escalation in openvt via incorrect process owner verific… |
| CVE-2026-48790 | 5.5 | 1.2 | tursodatabase | turso-cli | CWE-276 | turso-cli persists Turso platform JWT with world-readable (0o644) file permis… |
| CVE-2026-20760 | 6.8 | 1.1 | n/a | Intel(R) Processors | CWE-1260 | Improper handling of overlap between protected memory ranges in some microcod… |
| CVE-2026-48437 | 5.5 | 1.1 | Adobe | Content Credentials Rust SDK | CWE-295 | CAI Content Credentials | Improper Certificate Validation (CWE-295) |
| CVE-2025-61970 | 1.0 | 1.1 | AMD | Vitis™ Embedded Single File Download (SFD) for Windows | CWE-276 | Weak permissions in the Vitis™ Unified installation path on local Windows mac… |
| CVE-2026-20705 | 6.8 | 1.1 | n/a | Intel(R) platform | CWE-922 | Insecure storage of sensitive information in the Intel(R) TDX module for some… |
| CVE-2026-20775 | 6.8 | 1.1 | n/a | Intel(R) TDX modules | CWE-248 | Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain … |
| CVE-2025-35973 | 4.5 | 1.1 | n/a | Intel(R) Processors | CWE-229 | Improper handling of values for some Intel(R) Processors within Ring 0: Kerne… |
| CVE-2026-20713 | 4.5 | 1.1 | n/a | Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts. | CWE-670 | Always-incorrect control flow implementation in some firmware for some Intel(… |
| CVE-2025-35987 | 4.3 | 1.1 | n/a | Intel(R) Software Guard Extensions Data Center Attestation Primitives | CWE-223 | Omission of security-relevant information for some Intel(R) Software Guard Ex… |
| CVE-2026-20901 | 4.0 | 1.0 | n/a | Intel(R) Xeon(R) processors | CWE-20 | Improper input validation for some Intel(R) Xeon(R) processors within firmwar… |
| CVE-2025-31936 | 7.0 | 0.8 | n/a | Intel(R) Xeon(R) 6 processors when using Intel(R) TDX | CWE-1260 | Improper handling of overlap between protected memory ranges for some Intel(R… |
| CVE-2026-20799 | 5.4 | 0.8 | n/a | Battery Life Diagnostic Tool software | CWE-426 | Untrusted search path for some Battery Life Diagnostic Tool software before v… |
| CVE-2026-11985 | 3.6 | 0.6 | zephyrproject | zephyr | CWE-200 | Cross-thread FPU register leak on ARM when FPU enabled without register sharing |
| CVE-2026-20716 | 7.2 | 0.4 | n/a | Intel(R) Processors | CWE-284 | Improper access control for some Intel(R) Processors within Ring 3: User Appl… |
| CVE-2025-31938 | 4.3 | 0.4 | n/a | Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts. | CWE-1220 | Insufficient granularity of access control in some subsystem for some Intel(R… |
| CVE-2026-57263 | 7.0 | 0.3 | Siemens | LOGO! Soft Comfort | CWE-759 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9)… |
| CVE-2026-73283 | 2.5 | 0.3 | OpenBSD | OpenSSH | CWE-670 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was… |
| CVE-2026-20707 | 6.8 | 0.1 | n/a | 3rd Gen Intel(R) Xeon(R) Scalable Processors | CWE-1298 | Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Sca… |
| CVE-2026-6505 | 5.1 | 0.1 | Axis Communications AB | AXIS OS | CWE-367 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race cond… |
| CVE-2026-20908 | 5.8 | 0.1 | n/a | Intel(R) NPU Driver for Windows | CWE-367 | Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Wind… |
| CVE-2025-31356 | 5.6 | 0.1 | n/a | Intel(R) Trust Domain Extensions (Intel(R) TDX) | CWE-345 | Insufficient verification of data authenticity for some Intel(R) Trust Domain… |