boxscore/security
Tuesday, August 11, 2026 · all times UTC← 2026-08-10 · archive · 2026-08-12 →

Edition of August 11, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–933 of 933
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-656737.825.0MicrosoftMicrosoft Entra ConnectCWE-89Microsoft Entra Connect Elevation of Privilege Vulnerability
CVE-2026-732285.324.9encodedjango-rest-frameworkCWE-400Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZ…
CVE-2026-591355.524.8MicrosoftWindows 10 Version 1607CWE-1390Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-627327.824.6MicrosoftWindows 10 Version 1607CWE-122Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-488027.524.5miguelgrinbergpython-engineioCWE-770python-engineio has unbound thread allocation that can cause denial of service
CVE-2026-156068.824.4shabtiFrontend Admin by DynamiAppsCWE-862Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrar…
CVE-2026-732435.824.4kekingcnkkFileViewCWE-918kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusio…
CVE-2026-207158.224.3n/aIntel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.CWE-20Improper input validation in some firmware for some Intel(R) Active Managemen…
CVE-2026-701307.824.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Remote Code Execution Vulnerability
CVE-2026-703047.824.3MicrosoftWindows 10 Version 1607CWE-122Windows DNS Elevation of Privilege Vulnerability
CVE-2026-627086.424.4MicrosoftWindows 11 Version 24H2CWE-416Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-487667.624.2baptisteArnotypebot.ioCWE-200TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-…
CVE-2026-487677.624.2baptisteArnotypebot.ioCWE-200Google Sheets OAuth access token disclosure to guest members via getAccessToken
CVE-2026-691197.224.2TaubytetauCWE-639Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id}
CVE-2026-484122.724.2AdobeAdobe CommerceCWE-863Adobe Commerce | Incorrect Authorization (CWE-863)
CVE-2026-667775.924.1SAP_SESAP Business AI Platform (Approuter)CWE-22Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-186407.124.0Rapid7VelociraptorCWE-22Velociraptor directory traversal via the NewNotebook API
CVE-2026-117351.924.0NETGEARR7000CWE-121Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models
CVE-2026-117361.924.0NETGEARRAX20CWE-20Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers
CVE-2026-487638.223.8baptisteArnotypebot.ioCWE-862TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint vi…
CVE-2026-732177.723.9cursorcursorCWE-693Cursor: Sandbox escape via tampered Python virtual environments
CVE-2026-627865.523.9MicrosoftWindows 10 Version 1607CWE-125Win32k Information Disclosure Vulnerability
CVE-2026-627935.523.9MicrosoftWindows 10 Version 1607CWE-126Windows NTFS Information Disclosure Vulnerability
CVE-2026-627965.523.9MicrosoftWindows 10 Version 1607CWE-125Windows NTFS Information Disclosure Vulnerability
CVE-2026-627985.523.9MicrosoftWindows 11 version 23H2CWE-822Win32k Information Disclosure Vulnerability
CVE-2026-656625.523.9MicrosoftWindows 10 Version 1607CWE-125Windows GDI Information Disclosure Vulnerability
CVE-2026-732238.123.8electermelectermCWE-22electerm: Path traversal in editWithSystemEditor temp file path via unsanitiz…
CVE-2026-732258.123.8electermelectermCWE-22electerm: Path traversal in FTP/SFTP recursive folder download via unsanitize…
CVE-2026-732278.123.8electermelectermCWE-22electerm's RDP clipboard file download may parse unsafe file name
CVE-2026-591277.823.8MicrosoftWindows 10 Version 1607CWE-190Windows Installer Elevation of Privilege Vulnerability
CVE-2026-613537.823.8MicrosoftWindows 10 Version 1607CWE-122Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-613557.823.8MicrosoftWindows 10 Version 21H2CWE-122Windows Sensor Data Service Elevation of Privilege Vulnerability
CVE-2026-613577.823.8MicrosoftWindows 11 Version 24H2CWE-416Application Information Services Elevation of Privilege Vulnerability
CVE-2026-619237.823.8MicrosoftWindows 10 Version 1809CWE-122Windows Display Enhancement Service Elevation of Privilege Vulnerability
CVE-2026-619267.823.8MicrosoftWindows 10 Version 1607CWE-122Windows USB Driver Elevation of Privilege Vulnerability
CVE-2026-619327.823.8MicrosoftWindows 10 Version 1607CWE-122Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-619347.823.8MicrosoftWindows 11 version 23H2CWE-416Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2026-619377.823.8MicrosoftWindows 10 Version 1607CWE-122Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-626927.823.8MicrosoftWindows 10 Version 1607CWE-122Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-626957.823.8MicrosoftWindows 11 version 23H2CWE-122Windows Storage Elevation of Privilege Vulnerability
CVE-2026-627007.823.8MicrosoftWindows 10 Version 1607CWE-122Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-627017.823.8MicrosoftWindows 10 Version 1607CWE-416Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-627077.823.8MicrosoftWindows 10 Version 1607CWE-416Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-627107.823.8MicrosoftWindows 10 Version 1607CWE-122Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-627117.823.7MicrosoftWindows 10 Version 1607CWE-416Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-627177.823.8MicrosoftWindows 10 Version 1607CWE-122Windows Message Queuing Elevation of Privilege Vulnerability
CVE-2026-627197.823.8MicrosoftWindows 10 Version 1607CWE-122Windows Message Queuing Elevation of Privilege Vulnerability
CVE-2026-627227.823.8MicrosoftWindows 11 Version 24H2CWE-122Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-627477.823.8MicrosoftWindows 10 Version 1607CWE-122Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-627517.823.8MicrosoftWindows 10 Version 21H2CWE-190Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-627527.823.8MicrosoftWindows 10 Version 1607CWE-122Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-627547.823.8MicrosoftWindows 10 Version 1607CWE-122Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-627687.823.8MicrosoftWindows 10 Version 1607CWE-121Windows Installer Elevation of Privilege Vulnerability
CVE-2026-657877.823.8MicrosoftWindows 10 Version 1607CWE-122Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-703447.823.8MicrosoftWindows 10 Version 1607CWE-121Windows Installer Elevation of Privilege Vulnerability
CVE-2026-703467.823.8MicrosoftWindows 10 Version 1607CWE-121Windows Installer Elevation of Privilege Vulnerability
CVE-2026-703477.823.7MicrosoftWindows 10 Version 1607CWE-122Windows Installer Elevation of Privilege Vulnerability
CVE-2026-730798.523.6Wei-Shawsub2apiCWE-22Sub2API: Path traversal in the Responses subpath routes lets an authenticated…
CVE-2026-582438.823.6SAP_SESAP ABAP Developer ToolsCWE-862Privilege Escalation vulnerability in SAP ABAP Developer Tools
CVE-2026-137398.823.5CommvaultCommvault CloudCWE-918Server-Side Request Forgery (SSRF)
CVE-2026-726057.523.4Swing MusicSwing MusicCWE-306Swing Music Swing Music - Missing Authentication
CVE-2026-727497.123.4n8n-ion8nCWE-1321n8n before 1.123.67 Prototype Pollution via Edit Fields
CVE-2026-725348.823.3Authentik SecurityauthentikCWE-269Authentik Security authentik - Privilege Escalation
CVE-2026-195468.823.2Red HatRed Hat Enterprise Linux 10CWE-94Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via call…
CVE-2026-725396.523.1Windmill LabsWindmillCWE-200Windmill Labs Windmill - Information Disclosure
CVE-2026-188608.723.0Rapid7VelociraptorCWE-280Velociraptor incorrect Org deletion permissions check
CVE-2026-105799.822.9Red HatRed Hat JBoss Enterprise Application Platform 7.4.25CWE-347Picketlink-federation: auth bypass in picketlink saml unsolicited-response
CVE-2026-195578.322.9GoogleChromeCWE-416Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 al…
CVE-2026-635277.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-121Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-635337.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Remote Code Execution Vulnerability
CVE-2026-649047.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-843Microsoft Office Remote Code Execution Vulnerability
CVE-2026-649057.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-126Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-649067.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Access Remote Code Execution Vulnerability
CVE-2026-649087.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Access Remote Code Execution Vulnerability
CVE-2026-649127.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-121Microsoft Access Remote Code Execution Vulnerability
CVE-2026-649157.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-649197.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-121Microsoft Access Remote Code Execution Vulnerability
CVE-2026-649207.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Access Remote Code Execution Vulnerability
CVE-2026-688037.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-843Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-688077.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-688107.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-822Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-688117.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-843Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-688157.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-703117.822.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-416Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-732135.823.0coturncoturnCWE-863Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a l…
CVE-2026-187017.122.8MongoDBMongoDB ServerCWE-843Type Confusion in MongoDB Query Subsystem Leads to Denial of Service
CVE-2026-731608.722.7MISPcti-transmuteCWE-918cti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP Add…
CVE-2026-355024.622.6n/aIntel(R) Extension for PyTorchCWE-502Deserialization of untrusted data for some Intel(R) Extension for PyTorch bef…
CVE-2026-657845.522.4MicrosoftWindows 10 Version 1607CWE-125Windows NTFS Information Disclosure Vulnerability
CVE-2026-556768.822.4cisagovMalcolmCWE-434Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload com…
CVE-2026-628875.522.4MicrosoftWindows 10 Version 1607CWE-125Windows NTFS Information Disclosure Vulnerability
CVE-2026-730818.722.3activepiecesactivepiecesCWE-78Activepieces: Remote Code Execution via Command Injection in Code Step Name
CVE-2026-243306.522.2Red HatRed Hat Fuse 7CWE-434Wildfly-core: wildfly: arbitrary file read via malicious archive deployment
CVE-2026-732478.622.2kestra-iokestraCWE-918Kestra: SSRF via Pebble http() function allows unauthenticated access to inte…
CVE-2026-730867.422.2ainanoidCWE-190nanoid: Integer Overflow or Wraparound
CVE-2026-61815.922.1Axis Communications ABAXIS OSCWE-290The Device Configuration Framework is vulnerable to an authentication bypass …
CVE-2026-713868.822.1AdobeColdFusion 2025CWE-79ColdFusion | Cross-site Scripting (XSS) (CWE-79)
CVE-2026-727747.122.0n8n-ion8nCWE-639n8n before 1.123.67 Authentication Bypass via HTTP Request Node
CVE-2026-703547.821.9Microsoft.NET 10.0CWE-787.NET Core Remote Code Execution Vulnerability
CVE-2026-725378.821.7Authentik SecurityauthentikCWE-269Authentik Security authentik - Privilege Escalation
CVE-2026-515838.521.5n/an/aCWE-918An issue in usememos through v0.30.0 allows a remote authenticated attacker t…
CVE-2026-561747.821.6MicrosoftWindows 10 Version 1809CWE-426Windows Narrator Braille Elevation of Privilege Vulnerability
CVE-2026-628127.821.6MicrosoftWindows 10 Version 1607CWE-59Windows DHCP Server Elevation of Privilege Vulnerability
CVE-2026-155637.421.5Red HatRed Hat JBoss Enterprise Application Platform 7.4.25CWE-306Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads …
CVE-2026-635215.521.4MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Office Word Information Disclosure Vulnerability
CVE-2026-186957.121.4MongoDBMongoDB ServerCWE-617Improper Input Validation in MongoDB Timeseries Query Processing Leads to Den…
CVE-2026-186386.521.4Rapid7VelociraptorCWE-476Velociraptor server crash via the SetPassword API
CVE-2026-186996.021.4MongoDBMongoDB ServerCWE-476Improper Input Validation in MongoDB Query Planner Leads to Denial of Service
CVE-2026-187006.021.4MongoDBMongoDB ServerCWE-416Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service
CVE-2026-629097.821.3Microsoft.NET 10.0CWE-252.NET Elevation of Privilege Vulnerability
CVE-2026-657775.321.3MicrosoftWindows 11 version 23H2CWE-326Active Directory Security Feature Bypass Vulnerability
CVE-2026-186967.021.2MongoDBMongoDB ServerCWE-863Improper Authorization in MongoDB applyOps Command Handling Allows Unauthoriz…
CVE-2026-680679.320.9Quanovate Tech Inc. (operating as Mira / Mira Care)Mira FirmwareCWE-1390Mira Hormone Monitor, Mira Android App Weak Authentication
CVE-2026-591315.620.9MicrosoftWindows 10 Version 1607AMD Zen Information Disclosure Vulnerability
CVE-2026-187085.320.9MongoDBMongoDB ServerCWE-94Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Eng…
CVE-2026-726067.520.8PinryPinryCWE-918Pinry Pinry - Server-Side Request Forgery
CVE-2026-656806.720.8MicrosoftOneDrive for MacOSCWE-59Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
CVE-2026-447637.620.7SAP_SESAP Manufacturing Integration and IntelligenceCWE-22Directory Traversal vulnerability in SAP Manufacturing Integration and Intell…
CVE-2026-732125.820.7coturncoturnCWE-284coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNEC…
CVE-2026-619365.520.7MicrosoftWindows 10 Version 1809CWE-862Windows Defender Firewall Service Security Feature Bypass Vulnerability
CVE-2026-582486.520.6SAP_SESAP BusinessObjects Business IntelligenceCWE-611XML External Entity Injection in SAP BusinessObjects Business Intelligence
CVE-2026-714755.020.5Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-22Insights-client-rhel9: insights-client: spoke-controlled clusterid injected u…
CVE-2026-656552.320.5Temporal Technologies, Inc.Temporal UI ServerCWE-614Temporal UI Server may set OAuth credential cookies without Secure behind a T…
CVE-2026-488047.520.4miguelgrinbergpython-socketioCWE-770python-socketio: Binary attachment accumulation can cause denial of service
CVE-2026-488097.520.4miguelgrinbergpython-engineioCWE-770python-engineio has possible denial of service due to maximum payload size so…
CVE-2026-727668.220.2n8n-ion8nCWE-843n8n before 1.123.67 Arbitrary File Read via Send Email Node
CVE-2026-613567.820.3MicrosoftWindows 10 Version 1809CWE-306Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-613647.820.3MicrosoftWindows 10 Version 1607CWE-306Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-613657.820.3MicrosoftWindows 10 Version 1607CWE-306Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-613677.820.3MicrosoftWindows 10 Version 1607CWE-306Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-635227.820.2MicrosoftAzure SQL DatabaseCWE-732Azure SQL Database Elevation of Privilege Vulnerability
CVE-2026-447657.320.2SAP_SESAP Manufacturing Integration and IntelligenceCWE-862Missing Authorization Check in SAP Manufacturing Integration and Intelligence
CVE-2026-627887.020.3MicrosoftWindows 11 version 23H2CWE-416Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-668095.520.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Office Graphics Component Information Disclosure Vulnerability
CVE-2026-668105.520.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Word Information Disclosure Vulnerability
CVE-2026-688095.520.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-459Powerpoint Information Disclosure Vulnerability
CVE-2026-703105.520.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Word Information Disclosure Vulnerability
CVE-2026-703125.520.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-20Powerpoint Information Disclosure Vulnerability
CVE-2026-534146.520.0Zoom CommunicationsZoom ClientsCWE-126Zoom Clients - Buffer Over-read
CVE-2026-480469.319.7truelockmcstreambertCWE-494Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Upd…
CVE-2026-732294.319.7encodedjango-rest-frameworkCWE-200Django REST framework: AdminRenderer may disclose GET-protected data when ren…
CVE-2026-195194.319.6Red HatRed Hat Advanced Cluster Security 4CWE-617Claircore: claircore: denial of service via unchecked type assertion in rpm h…
CVE-2026-713878.819.4AdobeColdFusion 2025CWE-863ColdFusion | Incorrect Authorization (CWE-863)
CVE-2026-627767.819.5MicrosoftWindows 10 Version 1607CWE-59Windows DHCP Server Elevation of Privilege Vulnerability
CVE-2026-729228.219.2Significant-GravitasAutoGPTCWE-287AutoGPT: Webhook provider path confusion bypasses generic webhook secret veri…
CVE-2026-688217.819.3MicrosoftApp InstallerCWE-269Windows Package Manager Elevation of Privilege Vulnerability
CVE-2026-187057.119.2MongoDBMongoDB ServerCWE-807Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Acc…
CVE-2026-187117.119.2MongoDBMongoDB ServerCWE-416Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service a…
CVE-2026-421427.119.3baptisteArnotypebot.ioCWE-862TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that A…
CVE-2026-725986.519.3ApiooFusioCWE-918Apioo Fusio - Server-Side Request Forgery
CVE-2026-212695.419.2AdobeColdFusion 2025CWE-79ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-628907.819.2MicrosoftWindows 10 Version 1607CWE-122Windows GDI+ Elevation of Privilege Vulnerability
CVE-2026-667997.819.2MicrosoftWindows 10 Version 1607CWE-122Windows Key Guard Elevation of Privilege Vulnerability
CVE-2026-703077.019.1MicrosoftWindows 10 Version 1607CWE-416Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab…
CVE-2026-186887.119.0MongoDBMongoDB ServerCWE-125Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Servic…
CVE-2026-186947.119.0MongoDBMongoDB ServerCWE-125Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of …
CVE-2026-658107.818.9MicrosoftMicrosoft .NET Framework 3.5CWE-23.NET Framework Elevation of Privilege Vulnerability
CVE-2026-730855.318.9advplyraudiobookshelfCWE-287Audiobookshelf: Refresh Token Accepted on Resource Endpoints
CVE-2026-730872.318.9amir20dozzleCWE-918Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) i…
CVE-2026-713837.318.5AdobeColdFusion 2025CWE-863ColdFusion | Incorrect Authorization (CWE-863)
CVE-2026-726077.118.6Koha CommunityKohaCWE-89Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Mod…
CVE-2026-661466.118.3SonicWallGMSCWE-79Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.…
CVE-2026-155558.818.3Red HatRed Hat JBoss Enterprise Application Platform 7.4.25CWE-502Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss des…
CVE-2026-725558.118.2Peppermint LabPeppermintCWE-284Peppermint Lab Peppermint - Broken Access Control
CVE-2026-186397.318.2Rapid7VelociraptorCWE-290Velociraptor OIDC Authenticator susceptible to email spoofing
CVE-2026-187075.318.0MongoDBMongoDB ServerCWE-617Improper Input Validation in MongoDB Aggregation Command Handling Leads to De…
CVE-2026-731572.318.1MISPcti-transmuteCWE-79cti-transmute Remote MISP Event Browser Allows Cross-Site Scripting via Malic…
CVE-2026-582385.917.8SAP_SESAP Business AI Platform (Approuter)CWE-770Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-190784.317.8Red HatRed Hat OpenShift Container Platform 4CWE-601Ose-oauth-server: oauth-server: open redirect vulnerability enables phishing …
CVE-2026-186907.217.7MongoDBMongoDB ServerCWE-863Improper Authorization in MongoDB Server Allows Unauthorized Actions on Syste…
CVE-2026-627755.517.7MicrosoftWindows 11 version 26H1CWE-863Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclo…
CVE-2026-727475.117.7WWBNAVideoCWE-79AVideo Stored Cross-Site Scripting via Unauthenticated Registration
CVE-2026-290368.717.7DaveGamblecJSONCWE-706cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
CVE-2026-627997.817.5MicrosoftWindows 11 version 26H1CWE-122Windows SMB Client Elevation of Privilege Vulnerability
CVE-2026-656717.817.5MicrosoftWindows 10 Version 1607CWE-122Remote Access API Elevation of Privilege Vulnerability
CVE-2026-656727.817.5MicrosoftWindows 11 version 23H2CWE-122Remote Access API Elevation of Privilege Vulnerability
CVE-2026-657747.817.5MicrosoftWindows 10 Version 1607CWE-122Windows Installer Elevation of Privilege Vulnerability
CVE-2026-186357.217.5Rapid7VelociraptorCWE-863Velociraptor query plugin allows impersonation in other orgs
CVE-2026-487659.917.3baptisteArnotypebot.ioCWE-639TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAut…
CVE-2026-627575.917.2MicrosoftWindows 10 Version 1607CWE-347Windows Schannel Security Feature Bypass Vulnerability
CVE-2026-731405.317.3MISPcti-transmuteCWE-862cti-transmute Evaluation Report Exports Expose Private Comments and Author In…
CVE-2026-731555.317.3MISPcti-transmuteCWE-862cti-transmute Missing Authorization Allows Reactions to Private Comments
CVE-2026-727696.117.0n8n-ion8nCWE-1321n8n before 1.123.67 Prototype Pollution via VM Expression Engine
CVE-2026-658147.816.9MicrosoftWindows 10 Version 1607CWE-122Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
CVE-2026-627237.016.8MicrosoftWindows 10 Version 1607CWE-416Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-627247.016.8MicrosoftWindows 10 Version 1607CWE-416Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-627267.016.8MicrosoftWindows 10 Version 1607CWE-416Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-484957.116.7baptisteArnotypebot.ioCWE-862TypeBot Google Sheets OAuth callback can create credentials in unauthorized w…
CVE-2026-628836.716.7MicrosoftWindows 10 Version 1607CWE-197Windows DNS Elevation of Privilege Vulnerability
CVE-2026-657956.716.7MicrosoftWindows 10 Version 1607Windows DNS Elevation of Privilege Vulnerability
CVE-2026-657976.716.7MicrosoftWindows 10 Version 1607CWE-197Windows DNS Elevation of Privilege Vulnerability
CVE-2026-657986.716.7MicrosoftWindows 10 Version 1607CWE-197Windows DNS Elevation of Privilege Vulnerability
CVE-2026-567205.316.7owen2345CamaleonCMSCWE-862CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action
CVE-2026-691177.116.6NetBox LabsNetBoxCWE-639NetBox 4.5.8 ORM Injection via WritableNestedSerializer
CVE-2026-687927.816.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-77Microsoft Office Elevation of Privilege Vulnerability
CVE-2026-631336.516.5cisagovMalcolmCWE-770Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Ex…
CVE-2026-631345.416.4cisagovMalcolmCWE-22Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Cre…
CVE-2026-732497.516.3kovidgoyalcalibreCWE-862calibre Content Server `/book-update-annotations` Missing Write Authorization…
CVE-2026-731615.116.3MISPcti-transmuteCWE-79cti-transmute Conversion Table Allows XSS via Unescaped Cell Content During S…
CVE-2026-117374.316.3NETGEARRAX20CWE-20Some NETGEAR Nighthawk devices allow administrators to tamper with the device
CVE-2026-195587.516.1GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed…
CVE-2026-504727.016.1MicrosoftWindows 10 Version 1607CWE-122Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerab…
CVE-2026-591257.016.1MicrosoftWindows 10 Version 1607CWE-416Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
CVE-2026-613467.016.1MicrosoftWindows 10 Version 1809CWE-416Windows Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-613617.016.1MicrosoftWindows 11 Version 24H2CWE-416Windows DHCP Client Remote Code Execution Vulnerability
CVE-2026-613667.016.1MicrosoftWindows 10 Version 1607CWE-415Windows Network Connection Broker Elevation of Privilege Vulnerability
CVE-2026-619387.016.1MicrosoftWindows 11 Version 24H2CWE-416Windows Installer Elevation of Privilege Vulnerability
CVE-2026-619397.016.1MicrosoftWindows 10 Version 1607CWE-416Winlogon Elevation of Privilege Vulnerability
CVE-2026-730825.316.1activepiecesactivepiecesCWE-200Activepieces: Server-side request forgery in MCP tool validation endpoint
CVE-2026-732215.316.1cvat-aicvatCWE-863CVAT: Flawed authorization logic in endpoints related to lambda requests
CVE-2026-183484.116.1Rapid7VelociraptorCWE-863Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb V…
CVE-2026-207085.915.9n/aIntel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.CWE-532Insertion of sensitive information into log file in the subsystem for the Int…
CVE-2026-207654.615.8n/aIntel(R) TDX Guest softwareCWE-697Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.…
CVE-2026-713849.615.7AdobeColdFusion 2025CWE-863ColdFusion | Incorrect Authorization (CWE-863)
CVE-2026-657997.815.8MicrosoftWindows 10 Version 1607CWE-190Windows DNS Elevation of Privilege Vulnerability
CVE-2026-582307.015.7SAP_SESAP Business AI Platform (Approuter)CWE-601Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-668758.715.5Quanovate Tech Inc. (operating as Mira / Mira Care)Mira FirmwareCWE-306Mira Hormone Monitor, Mira Android App Missing authentication for critical fu…
CVE-2026-657737.815.6MicrosoftWindows 10 Version 1809CWE-284Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-484427.115.6AdobeContent Credentials Rust SDKCWE-22CAI Content Credentials | Improper Limitation of a Pathname to a Restricted D…
CVE-2026-484465.515.6AdobeContent Credentials Rust SDKCWE-22CAI Content Credentials | Improper Limitation of a Pathname to a Restricted D…
CVE-2026-675689.315.5Quanovate Tech Inc. (operating as Mira / Mira Care)Mira FirmwareCWE-798Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials
CVE-2026-627337.815.3MicrosoftWindows 10 Version 1607CWE-125Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-627367.815.3MicrosoftWindows 11 version 23H2CWE-122Windows DHCP Client Elevation of Privilege Vulnerability
CVE-2026-627397.815.3MicrosoftWindows 10 Version 1809CWE-122Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-627557.815.3MicrosoftWindows 10 Version 1607CWE-121Windows DHCP Client Elevation of Privilege Vulnerability
CVE-2026-627587.815.3MicrosoftWindows 10 Version 1607CWE-122Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2026-627707.815.3MicrosoftWindows 10 Version 1607CWE-122Windows Shell Elevation of Privilege Vulnerability
CVE-2026-627717.815.3MicrosoftWindows 10 Version 1809CWE-122Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-627727.815.3MicrosoftWindows 11 version 26H1CWE-122Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privi…
CVE-2026-627797.815.3MicrosoftWindows 11 Version 24H2CWE-416Windows Schannel Elevation of Privilege Vulnerability
CVE-2026-628767.815.3MicrosoftWindows 10 Version 1607CWE-125Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-628777.815.3MicrosoftWindows 10 Version 1607CWE-121Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-628807.815.3MicrosoftWindows 10 Version 1607CWE-125Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-628857.815.3MicrosoftWindows 10 Version 1607CWE-122Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-628947.815.3MicrosoftWindows 10 Version 1607CWE-122Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-657867.815.3MicrosoftWindows 10 Version 1607CWE-122Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-657907.815.3MicrosoftWindows 10 Version 1607CWE-122Windows Message Queuing Elevation of Privilege Vulnerability
CVE-2026-703457.815.3MicrosoftWindows 10 Version 1607CWE-122Windows Installer Elevation of Privilege Vulnerability
CVE-2026-725588.815.2CiviCRMCiviCRMCWE-89CiviCRM CiviCRM - SQL Injection
CVE-2026-725628.815.2Pimcorepimcore admin-ui-classic-bundleCWE-89Pimcore pimcore admin-ui-classic-bundle - SQL Injection
CVE-2026-729218.115.1seaweedfsseaweedfsCWE-863SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenan…
CVE-2026-613497.815.1MicrosoftWindows 10 Version 1607CWE-362Windows Work Folder Service Elevation of Privilege Vulnerability
CVE-2026-691157.115.1OpenIMSDKOpenIM Server (open-im-server)CWE-862OpenIM Server v3.8.3 Missing Authorization on User and Group Enumeration Endp…
CVE-2026-195795.315.0GrokabilitySnipe-ITCWE-639Snipe-IT Checkout Request Cancellation IDOR
CVE-2026-663406.914.8Quanovate Tech Inc. (operating as Mira / Mira Care)Mira FirmwareCWE-307Mira Hormone Monitor, Mira Android App Improper restriction of excessive auth…
CVE-2026-186366.814.8Rapid7VelociraptorCWE-288Velociraptor VFSGetBuffer API path deny list bypass
CVE-2026-447647.314.7SAP_SESAP Manufacturing Integration and IntelligenceCWE-862Missing Authorization Check in SAP Manufacturing Integration and Intelligence
CVE-2026-703395.414.7MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-561798.314.5MicrosoftWindows 11 Version 24H2CWE-346Windows Network Address Translation (NAT) Spoofing Vulnerability
CVE-2026-667785.314.6SAP_SESAP Business AI Platform (Approuter)CWE-644Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-731585.114.5MISPcti-transmuteCWE-20cti-transmute Saved Graph Configuration Allows Stored Cross-Site Scripting vi…
CVE-2026-731595.114.5MISPcti-transmuteCWE-79cti-transmute Stored XSS via Crafted Tag Icon on Admin Triage Interface
CVE-2026-725618.814.3Peppermint LabPeppermintCWE-284Peppermint Lab Peppermint - Broken Access Control
CVE-2026-53045.714.3Axis Communications ABAXIS OSCWE-1287An ACAP configuration file lacks input validation, which could potentially le…
CVE-2026-186919.014.2MongoDBMongoDB ServerCWE-757Improper Authentication in MongoDB Intra-Cluster Connections Allows Credentia…
CVE-2026-730846.114.2activepiecesactivepiecesCWE-79Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint
CVE-2026-186937.213.8MongoDBMongoDB ServerCWE-787Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denia…
CVE-2026-725416.513.8Windmill LabsWindmillCWE-306Windmill Labs Windmill - Missing Authorization
CVE-2026-727686.413.8n8n-ion8nCWE-918n8n before 2.32.1 SSRF Protection Bypass via MCP Client
CVE-2026-725425.413.8Windmill LabsWindmillCWE-306Windmill Labs Windmill - Missing Authorization
CVE-2026-727807.113.6craftcmscmsCWE-294Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey
CVE-2026-727827.113.7craftcmscmsCWE-668Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak
CVE-2026-195169.113.5GrafanaGrafana MCP ServerCWE-918CVE-2026-19516 CVE Record
CVE-2026-657767.013.4MicrosoftWindows 11 Version 24H2CWE-416Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-668326.913.4Quanovate Tech Inc. (operating as Mira / Mira Care)Mira FirmwareCWE-598Mira Hormone Monitor, Mira Android App Use of GET request method with sensiti…
CVE-2026-730909.313.3ChocobozzzPeerTubeCWE-863PeerTube: Cross-origin remote video takeover via Update activity
CVE-2026-726086.513.2Koha CommunityKohaCWE-89Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name
CVE-2026-487625.413.1baptisteArnotypebot.ioCWE-918TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcript…
CVE-2026-691135.313.1CapSoftwareCapCWE-862Cap v0.3.1 Broken Access Control via video comment endpoint
CVE-2026-155547.413.0Red HatRed Hat JBoss Enterprise Application Platform 7.4.25CWE-295Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery
CVE-2026-186348.412.9SonicWallGMSCWE-502An insecure handling of serialized objects vulnerability was found in the one…
CVE-2026-667743.712.9SAP_SESAP Business AI Platform (Approuter)CWE-754Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-667614.312.8SAP_SESAP Business AI Platform (Approuter)CWE-770Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-582393.712.7SAP_SESAP Business AI Platform (Approuter)CWE-807Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-208787.112.7n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-476Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for …
CVE-2026-726097.112.7Koha CommunityKohaCWE-89Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl
CVE-2026-208866.912.7n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-787Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windo…
CVE-2026-727798.712.5craftcmscmsCWE-184Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject
CVE-2026-155568.112.5Red HatRed Hat JBoss Enterprise Application Platform 7.4.25CWE-347Picketlink-federation: picketlink saml 2.0 auth bypass via missing assertions
CVE-2026-81585.312.2Axis Communications ABSigned Video FrameworkThe Signed Video Framework contained a buffer overflow issue which could lead…
CVE-2026-727728.912.2n8n-ion8nCWE-640n8n before 2.32.1 Authentication Bypass via Token Exchange
CVE-2026-502367.412.2Red HatRed Hat OpenShift Container Platform 4CWE-918Openshift/console: authenticated ssrf with full response reflection and path …
CVE-2026-727637.212.2n8n-ion8nCWE-639n8n before 1.123.67 Credential Exfiltration via Sub-Workflow
CVE-2026-727717.112.2n8n-ion8nCWE-863n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes
CVE-2026-667716.112.2SAP_SESAPUI5CWE-79Cross Site Scripting (XSS) vulnerability in SAPUI5
CVE-2026-582375.912.2SAP_SESAP Business AI Platform (Approuter)CWE-862Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-429767.812.1MicrosoftWindows 10 Version 1607CWE-306Remote Access Management service/API (RPC server) Elevation of Privilege Vuln…
CVE-2026-627777.812.1MicrosoftWindows 10 Version 1607CWE-306Windows License Manager Elevation of Privilege Vulnerability
CVE-2026-656787.012.0MicrosoftWindows 10 Version 1607CWE-416Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-657787.012.0MicrosoftWindows 11 Version 24H2CWE-416Windows Autopilot Elevation of Privilege Vulnerability
CVE-2026-657797.012.0MicrosoftWindows 11 Version 24H2CWE-416Windows Autopilot Elevation of Privilege Vulnerability
CVE-2026-484436.212.1AdobeContent Credentials Rust SDKCWE-400CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVE-2026-484446.212.1AdobeContent Credentials Rust SDKCWE-190CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
CVE-2026-484456.212.1AdobeContent Credentials Rust SDKCWE-190CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
CVE-2026-582475.312.0SAP_SESAP ABAP PlatformCWE-908Memory Corruption vulnerability in SAP ABAP Platform
CVE-2026-194187.311.8TYPO3TYPO3 CMSCWE-346TYPO3 CMS - Broken Access Control in Backend and Install Tool
CVE-2026-187047.111.8MongoDBMongoDB ServerCWE-862Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User…
CVE-2026-725467.111.7AttendizeAttendizeCWE-639Attendize Attendize - Insecure Direct Object Reference
CVE-2026-725477.111.7AttendizeAttendizeCWE-639Attendize Attendize - Insecure Direct Object Reference
CVE-2026-727755.811.7n8n-ion8nCWE-89n8n before 1.123.67 SQL Injection via PostgresTrigger Node
CVE-2026-727505.311.7n8n-ion8nCWE-89n8n before 1.123.67 SQL Injection via executeQuery Operation
CVE-2026-725968.111.5Ghost FoundationGhostCWE-284Ghost Foundation Ghost - Broken Access Control
CVE-2026-619285.511.6MicrosoftWindows 10 Version 1607CWE-312Windows Hello Tampering Vulnerability
CVE-2026-487718.211.3Ishankjha740ishankportfolioCWE-200ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Si…
CVE-2026-187025.311.4MongoDBMongoDB ServerCWE-269Improper Authorization in MongoDB profile Command Allows Unauthorized Modific…
CVE-2026-718456.310.8Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-532Insights-client: insights-client: ccx_token bearer credential logged in clear…
CVE-2026-727627.710.7n8n-ion8nCWE-434n8n before 1.123.67 Arbitrary File Write via Edit Image Node
CVE-2026-627257.010.7MicrosoftWindows 10 Version 1607CWE-416Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-725447.510.6OpenSignLabsOpenSignCWE-345OpenSignLabs OpenSign - Insufficient Verification of Data Authenticity
CVE-2026-732228.810.5davila7claude-code-templatesCWE-78Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude C…
CVE-2026-627807.010.5MicrosoftWindows 11 version 23H2CWE-416Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-725638.110.3BadChoiceHandeskCWE-284BadChoice Handesk - Broken Access Control
CVE-2026-725958.110.3BadChoiceHandeskCWE-284BadChoice Handesk - Broken Access Control
CVE-2026-725606.510.3HumanSignalLabel StudioCWE-918HumanSignal Label Studio - Server-Side Request Forgery
CVE-2026-725976.510.3FriendicaFriendicaCWE-918Friendica Friendica - Server-Side Request Forgery
CVE-2026-667796.310.3SAP_SESAP NetWeaver Application Server ABAPCWE-79Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server …
CVE-2026-661497.810.0SonicWallEmail SecurityCWE-94Improper Control of Generation of Code ('Code Injection') Vulnerability in th…
CVE-2026-661507.810.0SonicWallEmail SecurityCWE-94Improper Control of Generation of Code ('Code Injection') Vulnerability in th…
CVE-2026-627497.010.1MicrosoftWindows 11 Version 24H2CWE-416Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-627537.010.1MicrosoftWindows 10 Version 1607CWE-122Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-627737.010.1MicrosoftWindows 10 Version 1607CWE-416Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-627747.010.1MicrosoftWindows 10 Version 1607CWE-416Windows Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-628927.010.1MicrosoftWindows 10 Version 1809CWE-416Capability Access Management Service (camsvc) Elevation of Privilege Vulnerab…
CVE-2026-657807.010.1MicrosoftWindows 11 Version 24H2CWE-415Windows Autopilot Elevation of Privilege Vulnerability
CVE-2026-657817.010.1MicrosoftWindows 11 Version 24H2CWE-416Windows Autopilot Elevation of Privilege Vulnerability
CVE-2026-657827.010.1MicrosoftWindows 11 Version 24H2CWE-416Windows Autopilot Elevation of Privilege Vulnerability
CVE-2026-657837.010.1MicrosoftWindows 11 Version 24H2CWE-416Windows Autopilot Elevation of Privilege Vulnerability
CVE-2026-195176.510.1Samsung Open SourcerlottieCWE-1284Improper Validation of Specified Quantity in Input and Allocation of Resource…
CVE-2026-195186.510.1Samsung Open SourcerlottieCWE-1284Improper Validation of Specified Quantity in Input vulnerability in Samsung O…
CVE-2026-714746.310.0Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-532Insights-client-rhel9: insights-client: pull-secret bearer token written to l…
CVE-2026-726104.310.0Koha CommunityKohaCWE-89Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Sli…
CVE-2026-660987.19.8Quanovate Tech Inc. (operating as Mira / Mira Care)Mira FirmwareCWE-306Mira Hormone Monitor, Mira Android App Missing authentication for critical fu…
CVE-2026-117384.39.8NETGEARR7000CWE-20Insufficient input validation in certain NETGEAR Nighthawk routers allows adm…
CVE-2026-477029.19.7baptisteArnotypebot.ioCWE-312TypeBot API tokens stored in plaintext
CVE-2026-727859.39.5craftcmscmsCWE-863Craft CMS before 5.10.6 Authorization Bypass via structures/move-element
CVE-2026-732456.59.4kestra-iokestraCWE-306Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/…
CVE-2026-729256.19.4swc-projectswcCWE-79SWC HTML minifier may allow script element breakout when minifying embedded JSON
CVE-2026-667735.99.4SAP_SEOdataCWE-601Server-controlled `__next` URL is not checking cross-origin
CVE-2026-484418.69.3AdobeLightroom ClassicCWE-22Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directo…
CVE-2026-627297.09.3MicrosoftWindows 10 Version 1607CWE-362Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-627347.09.3MicrosoftWindows 10 Version 1607CWE-362Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-627487.09.3MicrosoftWindows 10 Version 1607CWE-362Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-195504.39.3Red HatRed Hat Enterprise Linux 10CWE-863Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a priv…
CVE-2026-346358.49.1AdobeColdFusion 2025CWE-321ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)
CVE-2026-714685.39.1Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-266Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via glo…
CVE-2026-591227.08.8MicrosoftWindows 10 Version 1607CWE-362Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-591267.08.8MicrosoftWindows 10 Version 21H2CWE-362Windows Event Logging Service Elevation of Privilege Vulnerability
CVE-2026-619277.08.8MicrosoftWindows 11 Version 24H2CWE-416Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2026-626907.08.8MicrosoftWindows 10 Version 1809CWE-362Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-626937.08.8MicrosoftWindows 11 Version 24H2CWE-362Windows MIDI Service Module Elevation of Privileges Vulnerability
CVE-2026-627057.08.8MicrosoftWindows 11 Version 24H2CWE-362Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2026-627287.08.8MicrosoftWindows 10 Version 1607CWE-125Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-712909.18.6Apache Software FoundationApache HttpComponents ClientCWE-295Apache HttpComponents Client: TLS hostname verification silently disabled on …
CVE-2026-120525.28.7zephyrprojectzephyrCWE-787Out-of-bounds write in USB CDC NCM control handler when host wLength is small…
CVE-2026-730685.98.4ToolJetToolJetCWE-639ToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db):…
CVE-2026-649345.38.2Quanovate Tech Inc. (operating as Mira / Mira Care)Mira FirmwareCWE-807Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a secu…
CVE-2026-667724.38.1SAP_SESAP BusinessObjects Business Intelligence Platform (Admin Tools)CWE-862Missing Authorization Check in SAP BusinessObjects Business Intelligence Plat…
CVE-2026-479407.88.0AdobeLightroom ClassicCWE-190Lightroom Classic | Integer Overflow or Wraparound (CWE-190)
CVE-2026-631777.17.6cisagovMalcolmCWE-863Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential…
CVE-2026-187127.27.3MongoDBMongoDB ServerCWE-863Improper Authorization in MongoDB Queryable Encryption Maintenance Operations…
CVE-2026-249118.37.2n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-121Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software f…
CVE-2026-145486.57.2UnknownRay Enterprise TranslationCWE-862Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update
CVE-2026-582356.37.2SAP_SESAP NetWeaver AS Java (Adobe Document Services)CWE-1395Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Docum…
CVE-2026-731625.37.2MISPcti-transmuteCWE-352cti-transmute CSRF Allows Unauthorized Follow and Notification State Changes
CVE-2026-207278.36.9n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-476Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for …
CVE-2026-207768.36.9n/aIntel(R) PROSet/Wireless WiFi SoftwareCWE-754Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software wit…
CVE-2026-228878.36.9n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-119Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software …
CVE-2026-207497.26.9n/aIntel(R) PROSet/Wireless WiFi SoftwareCWE-125Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Rin…
CVE-2026-207397.16.9n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-754Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for…
CVE-2026-207457.16.9n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-787Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windo…
CVE-2026-207477.16.9n/aIntel(R) PROSet/Wireless WiFi SoftwareCWE-754Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software wit…
CVE-2026-207877.16.9n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-476Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for …
CVE-2026-207957.16.9n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-119Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software …
CVE-2026-582453.86.9SAP_SESAP Advanced Planning and Optimization (Model Mix Planning)CWE-798Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix P…
CVE-2026-534167.16.8Zoom CommunicationsZoom VDICWE-23Zoom VDI - Path Traversal
CVE-2026-118945.96.7zephyrprojectzephyrCWE-415Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` err…
CVE-2026-251941.86.7n/aIntel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.CWE-787Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allo…
CVE-2026-502377.46.7Red HatRed Hat OpenShift Container Platform 4CWE-918Openshift/console: namespace tenant ssrf with egress bypass, catalog poisonin…
CVE-2026-675588.26.5Quanovate Tech Inc. (operating as Mira / Mira Care)Mira FirmwareCWE-290Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing
CVE-2026-186877.16.5MongoDBMongoDB ServerCWE-191Improper Validation in MongoDB Queryable Encryption Maintenance Operation Lea…
CVE-2026-53035.76.5Axis Communications ABAXIS OSCWE-367The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race cond…
CVE-2026-186985.36.5MongoDBMongoDB ServerCWE-863Improper Authorization in MongoDB Server Allows Unauthorized Actions on Syste…
CVE-2026-582444.36.5SAP_SESAP Manufacturing Integration and IntelligenceCWE-862Missing Authorization Check in SAP Manufacturing Integration and Intelligence…
CVE-2026-667644.36.5SAP_SESAP S/4 HANA (Reprocess Bank Statement Items)CWE-639Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)
CVE-2026-120514.66.4zephyrprojectzephyrCWE-476NULL pointer dereference in USB DFU device_next download handler (handle_down…
CVE-2026-671807.56.1GoogleTurbiniaCWE-78Google Turbinia arbitrary command execution
CVE-2026-483876.26.1AdobeContent Credentials Rust SDKCWE-190CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
CVE-2026-484346.26.1AdobeContent Credentials Rust SDKCWE-400CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVE-2026-484356.26.1AdobeContent Credentials Rust SDKCWE-191CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVE-2026-326775.46.0n/agaudi-container-runtimeCWE-22Path traversal for some gaudi-container-runtime before version 1.24.0 within …
CVE-2026-596935.36.0SiemensDesigo DXR2CWE-754A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233…
CVE-2026-732824.85.9OpenBSDOpenSSHCWE-416In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if…
CVE-2026-92144.36.0NETGEARR7000CWE-20Insufficient input validation in NETGEAR R7000 router allows administrators t…
CVE-2026-67267.95.9Trusted Computing GroupTPM2.0CWE-704An information leakage vulnerability in the TCG TPM 2.0 reference code.
CVE-2026-725535.45.9ElkArte ForumElkArteCWE-79ElkArte Forum ElkArte - Cross-Site Scripting
CVE-2026-484047.85.5AdobeLightroom ClassicCWE-787Lightroom Classic | Out-of-bounds Write (CWE-787)
CVE-2026-484057.85.5AdobeLightroom ClassicCWE-787Lightroom Classic | Out-of-bounds Write (CWE-787)
CVE-2026-484067.85.5AdobeLightroom ClassicCWE-787Lightroom Classic | Out-of-bounds Write (CWE-787)
CVE-2026-484077.85.5AdobeLightroom ClassicCWE-787Lightroom Classic | Out-of-bounds Write (CWE-787)
CVE-2026-484087.85.5AdobeLightroom ClassicCWE-787Lightroom Classic | Out-of-bounds Write (CWE-787)
CVE-2026-484097.85.5AdobeLightroom ClassicCWE-787Lightroom Classic | Out-of-bounds Write (CWE-787)
CVE-2026-484107.85.5AdobeLightroom ClassicCWE-787Lightroom Classic | Out-of-bounds Write (CWE-787)
CVE-2026-732347.85.5FreeCADFreeCADCWE-22FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized fil…
CVE-2026-208916.35.5n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-287Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for W…
CVE-2026-118935.95.5zephyrprojectzephyrCWE-415Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (h…
CVE-2026-582414.25.5SAP_SESAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration WizardCWE-862Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Tr…
CVE-2026-732813.55.5OpenBSDOpenSSHCWE-669In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but w…
CVE-2026-667706.35.4SAP_SESAP Social IntelligenceCWE-89SQL Injection vulnerability in SAP Social Intelligence
CVE-2026-730837.65.3activepiecesactivepiecesCWE-693Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading
CVE-2026-169746.45.3themeumKirki – Freeform Page Builder, Website Builder & CustomizerCWE-79Kirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authen…
CVE-2026-713904.05.2AdobeContent Credentials Rust SDKCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-732317.85.1faker-jsfakerCWE-95Faker: helpers.fake exploitable into arbritary code execution
CVE-2026-209035.45.1n/aIntel(R) AI ContainersCWE-693Protection mechanism failure for some Intel(R) AI Containers before version v…
CVE-2026-209065.45.1n/aIntel(R) Neural Compressor softwareCWE-693Protection mechanism failure for some Intel(R) Neural Compressor software bef…
CVE-2026-213875.45.1n/aIntel(R) LLM Library for PyTorchCWE-693Protection mechanism failure for some Intel(R) LLM Library for PyTorch within…
CVE-2026-214005.45.1n/aIntel(R) AI Reference ModelsCWE-693Protection mechanism failure for some Intel(R) AI Reference Models before ver…
CVE-2026-287005.45.1n/aEquiTritonCWE-427Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ri…
CVE-2026-327885.45.1n/aApproximate Bayesian Inference FrameworkCWE-427Uncontrolled search path for some Approximate Bayesian Inference Framework be…
CVE-2026-341755.45.1n/aHardware-Aware-Automated-MachineLearning NACWE-427Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA…
CVE-2026-629087.05.0MicrosoftWindows 10 Version 1607CWE-362Windows Backup Engine Elevation of Privilege Vulnerability
CVE-2026-713896.25.0AdobeContent Credentials Rust SDKCWE-191CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVE-2026-67275.95.0Trusted Computing GroupTPM2.0CWE-208CVE-2026-6727
CVE-2026-145494.34.9UnknownRay Enterprise TranslationCWE-862Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and Deletion
CVE-2026-193916.54.8Red HatPen Drive Powered by Red Hat LightspeedCWE-312Insights-core: insights-core: incomplete credential redaction exposes sssd bi…
CVE-2026-732338.54.7FreeCADFreeCADCWE-94FreeCAD: FEM formula incomplete escape
CVE-2026-732488.54.6kovidgoyalcalibreCWE-94calibre: Bypass of Python template restrictions via nested `template()` leadi…
CVE-2026-207787.04.5n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-125Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Window…
CVE-2026-208857.04.5n/aIntel(R) platformsCWE-287Improper authentication in the Intel(R) TDX module for some Intel(R) platform…
CVE-2026-727836.94.5craftcmscmsCWE-22Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained
CVE-2025-485064.64.6AMDVitis™ Unified Installer for FPGAs & Adaptive SoCs in WindowsCWE-427Uncontrolled search paths in Vitis™ Unified installation path on local Window…
CVE-2026-256527.84.5AdobeColdFusion 2025CWE-863ColdFusion | Incorrect Authorization (CWE-863)
CVE-2026-727846.94.2craftcmscmsCWE-918Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation
CVE-2026-484477.74.2AdobeLightroom ClassicCWE-863Lightroom Classic | Incorrect Authorization (CWE-863)
CVE-2026-207696.94.1n/aIntel(R) NPU DriverCWE-754Improper conditions check for the Intel(R) NPU Driver for all versions within…
CVE-2026-207866.94.1n/aIntel(R) NPU DriverCWE-125Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3…
CVE-2026-207526.74.1n/aIntel(R) PROSet/Wireless WiFi SoftwareCWE-287Improper authentication for some Intel(R) PROSet/Wireless WiFi Software withi…
CVE-2026-447623.74.0SAP_SESAP Data Services Management ConsoleCWE-1021Security Misconfiguration in SAP Data Services Management Console
CVE-2026-187095.93.9MongoDBMongoDB ServerCWE-862Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Le…
CVE-2026-730778.43.9vimvimCWE-78Vim: Arbitrary Code Execution via Shell Keyword Lookup
CVE-2026-667765.93.7SAP_SESAP Business AI Platform (Approuter)CWE-347Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2025-00414.63.7AMDVitis™ Embedded Single File Download (SFD) for WindowsCWE-427Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) f…
CVE-2026-671797.83.6genkit-aigenkitCWE-644Genkit improper host header validation
CVE-2026-727446.93.5nuxtnuxtCWE-200Nuxt before 4.5.1 Information Disclosure via Chrome DevTools
CVE-2026-207376.33.4n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-200Exposure of sensitive information to an unauthorized actor for some Intel(R) …
CVE-2026-730364.63.3Bash-itBash-itCWE-150Bash-it barbuk Theme 3.2.0 Terminal Escape Sequence Injection via pyproject.toml
CVE-2026-188447.23.3PulsettoVagus Nerve StimulatorCWE-912Pulsetto Vagus Nerve Stimulator Hidden Functionality
CVE-2026-725595.43.3Daniel BrendelHortusFoxCWE-79Daniel Brendel HortusFox - Cross-Site Scripting
CVE-2026-339214.83.3Nozomi NetworksArcCWE-1188Npcap driver installed without administrator-only access restriction on Windo…
CVE-2026-240995.93.2n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-416Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows wi…
CVE-2026-730768.43.1vimvimCWE-94Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay …
CVE-2026-667637.93.2SAP_SESAP BusinessObjects Business Intelligence Platform (Central Management Server)CWE-321Credentials disclosure in SAP BusinessObjects Business Intelligence Platform …
CVE-2026-661548.33.1SonicWallGMSCWE-295An insufficient certificate validation in a privileged communication workflow…
CVE-2026-207806.93.0n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-400Uncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Soft…
CVE-2026-732505.43.0notepad-plus-plusnotepad-plus-plusCWE-77Notepad++: Install-time PowerShell command injection through installation path
CVE-2026-732305.92.9enteenteCWE-200Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-e…
CVE-2026-726947.12.8Red HatRed Hat Enterprise Linux 10CWE-59Mrtg: mrtg daemon symlink-following chown allows local privilege escalation v…
CVE-2026-207898.42.7n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-284Improper access control for some Intel(R) PROSet/Wireless WiFi Software for W…
CVE-2026-730666.82.7tesseract-ocrtesseractCWE-787Tesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .train…
CVE-2026-730676.72.7tesseract-ocrtesseractCWE-125Tesseract: Heap OOB read in the DAWG loader
CVE-2026-730728.52.6vimvimCWE-122Vim: Heap Buffer Overflow when Loading a Spell File
CVE-2026-732356.12.7FreeCADFreeCADCWE-611FreeCAD: XXE file read and SSRF via external entity injection in Document.xml…
CVE-2026-208907.12.5n/aIntel(R) PROSet/Wireless WiFi Software for WindowsCWE-269Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software…
CVE-2026-339226.82.5Nozomi NetworksArcCWE-22Path traversal in the Offline archives functionality of the local web interfa…
CVE-2026-667754.32.6SAP_SESAP Business AI Platform (Approuter)CWE-352Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-207418.32.2n/aIntel(R) PROSet/Wireless WiFi SoftwareCWE-284Improper access control for some Intel(R) PROSet/Wireless WiFi Software withi…
CVE-2026-667606.42.1SAP_SESAP Business AI Platform (Approuter)CWE-295Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-207345.62.1n/aIntel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.CWE-665Improper initialization in some firmware for some Intel(R) Active Management …
CVE-2026-207285.42.2n/aIntel Extension for TensorFlow softwareCWE-693Protection mechanism failure for some Intel Extension for TensorFlow software…
CVE-2026-207555.42.2n/aLLM Scaler softwareCWE-693Protection mechanism failure for some LLM Scaler software within Ring 3: User…
CVE-2026-207705.42.2n/aCluster Management Toolkit for Kubernetes softwareCWE-693Protection mechanism failure for some Cluster Management Toolkit for Kubernet…
CVE-2026-246935.42.2n/aIntel(R) oneCCL Bindings for PyTorchCWE-693Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch be…
CVE-2026-287075.42.2n/aLLM-on-RayCWE-693Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ri…
CVE-2026-287575.42.2n/aIntel(R) Workload Services Framework softwareCWE-693Protection mechanism failure for some Intel(R) Workload Services Framework so…
CVE-2026-207634.62.1n/aIntel(R) TDX Guest softwareCWE-682Incorrect calculation for some Intel(R) TDX Guest software before version 0.3…
CVE-2026-207124.02.1n/aIntel(R) reference platformsCWE-459Incomplete cleanup in some UEFI firmware for some Intel(R) reference platform…
CVE-2026-436068.52.1AMDVitis™ Libraries - Security ModuleCWE-208Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 comp…
CVE-2026-175356.22.0Rapid7VelociraptorCWE-125Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Vol…
CVE-2026-208988.52.0n/ain Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.CWE-284Improper access control in the firmware for some in Alias Checking Trusted Mo…
CVE-2025-80877.02.0AMDAMD Power Design Manager (PDM) Software Un-InstallerCWE-427A DLL hijacking vulnerability in AMD Power Design Manager could allow a malic…
CVE-2025-545127.02.0AMDAMD Ryzen™ MasterCWE-427A DLL hijacking vulnerability within the AMD Ryzen Master installation could …
CVE-2026-730754.62.0vimvimCWE-124Vim: Out-of-bounds Access in Popup Opacity Handling
CVE-2026-327915.41.9n/aIntel(R) Performance Counter Monitor (Intel(R) PCM)CWE-426Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R)…
CVE-2026-590867.31.8SiemensSimcenter FemapCWE-121A vulnerability has been identified in Simcenter Femap (All versions < V2606)…
CVE-2026-187032.31.8MongoDBMongoDB ServerCWE-863Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Serv…
CVE-2026-89178.41.7ASUSGPU Tweak IIICWE-822Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, a…
CVE-2026-213996.91.7n/aIntel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R)CWE-122Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel…
CVE-2026-04655.61.7AMDAMD Ryzen™ MasterCWE-416A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver …
CVE-2026-187108.21.7MongoDBMongoDB DriverCWE-532Cleartext Storage of Sensitive Information in MongoDB Driver Logging During C…
CVE-2026-500587.31.7SiemensSolid Edge SE2025CWE-125A vulnerability has been identified in Solid Edge SE2025 (All versions < V225…
CVE-2026-500597.31.7SiemensSolid Edge SE2025CWE-787A vulnerability has been identified in Solid Edge SE2025 (All versions < V225…
CVE-2026-500607.31.7SiemensSolid Edge SE2025CWE-416A vulnerability has been identified in Solid Edge SE2025 (All versions < V225…
CVE-2026-500617.31.7SiemensSolid Edge SE2025CWE-416A vulnerability has been identified in Solid Edge SE2025 (All versions < V225…
CVE-2026-500627.31.7SiemensSolid Edge SE2025CWE-125A vulnerability has been identified in Solid Edge SE2025 (All versions < V225…
CVE-2026-500637.31.7SiemensSolid Edge SE2025CWE-125A vulnerability has been identified in Solid Edge SE2025 (All versions < V225…
CVE-2026-500647.31.7SiemensSolid Edge SE2025CWE-787A vulnerability has been identified in Solid Edge SE2025 (All versions < V225…
CVE-2026-597007.31.7SiemensSimcenter FemapCWE-125A vulnerability has been identified in Simcenter Femap (All versions < V2606.…
CVE-2026-597017.31.7SiemensSimcenter FemapCWE-125A vulnerability has been identified in Simcenter Femap (All versions < V2606.…
CVE-2026-646297.31.7SiemensParasolid V38.0CWE-125A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.…
CVE-2025-485051.01.7AMDVitis™ Unified Installer for FPGAs & Adaptive SoCs in WindowsCWE-276Weak permissions in the Vitis™ Unified installation path on local Windows mac…
CVE-2026-691088.31.6SiemensSiemens License Server (SLS)CWE-732A vulnerability has been identified in Siemens License Server (SLS) (All vers…
CVE-2026-572627.01.6SiemensLOGO! Soft ComfortCWE-321A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9)…
CVE-2026-207316.91.6n/aIntel(R) NPU DriverCWE-119Improper buffer restrictions for the Intel(R) NPU Driver for all versions wit…
CVE-2026-207836.91.6n/aIntel(R) NPU DriverCWE-754Improper conditions check in the firmware for the Intel(R) NPU Driver for all…
CVE-2026-277656.81.6n/avLLM Hardware Plugin for Intel(R) Gaudi(R) softwareCWE-20Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R)…
CVE-2026-209134.81.6n/aIntel(R) Neural Compressor softwareCWE-20Improper input validation for some Intel(R) Neural Compressor software before…
CVE-2026-287292.41.6n/aIntel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (none) and availability (low) impacts.CWE-190Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may al…
CVE-2026-730706.81.6vimvimCWE-121Vim: Stack Buffer Overflow in the Vim Socket Server
CVE-2026-209174.01.5n/aIntel(R) ProcessorsCWE-1422Exposure of sensitive information caused by incorrect data forwarding during …
CVE-2026-730713.31.4vimvimCWE-416Vim: Use-after-free in JSON Decoding
CVE-2026-730747.11.4vimvimCWE-190Vim: Heap Buffer Overflow in Text Property Handling
CVE-2025-00467.01.3AMDAMD Power Design Manager (PDM) Software Installer for WindowsCWE-732Incorrect directory permissions could allow a local user to escalate their pr…
CVE-2026-726937.81.2Red HatRed Hat Hardened ImagesCWE-284Kbd: local privilege escalation in openvt via incorrect process owner verific…
CVE-2026-487905.51.2tursodatabaseturso-cliCWE-276turso-cli persists Turso platform JWT with world-readable (0o644) file permis…
CVE-2026-207606.81.1n/aIntel(R) ProcessorsCWE-1260Improper handling of overlap between protected memory ranges in some microcod…
CVE-2026-484375.51.1AdobeContent Credentials Rust SDKCWE-295CAI Content Credentials | Improper Certificate Validation (CWE-295)
CVE-2025-619701.01.1AMDVitis™ Embedded Single File Download (SFD) for WindowsCWE-276Weak permissions in the Vitis™ Unified installation path on local Windows mac…
CVE-2026-207056.81.1n/aIntel(R) platformCWE-922Insecure storage of sensitive information in the Intel(R) TDX module for some…
CVE-2026-207756.81.1n/aIntel(R) TDX modulesCWE-248Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain …
CVE-2025-359734.51.1n/aIntel(R) ProcessorsCWE-229Improper handling of values for some Intel(R) Processors within Ring 0: Kerne…
CVE-2026-207134.51.1n/aIntel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.CWE-670Always-incorrect control flow implementation in some firmware for some Intel(…
CVE-2025-359874.31.1n/aIntel(R) Software Guard Extensions Data Center Attestation PrimitivesCWE-223Omission of security-relevant information for some Intel(R) Software Guard Ex…
CVE-2026-209014.01.0n/aIntel(R) Xeon(R) processorsCWE-20Improper input validation for some Intel(R) Xeon(R) processors within firmwar…
CVE-2025-319367.00.8n/aIntel(R) Xeon(R) 6 processors when using Intel(R) TDXCWE-1260Improper handling of overlap between protected memory ranges for some Intel(R…
CVE-2026-207995.40.8n/aBattery Life Diagnostic Tool softwareCWE-426Untrusted search path for some Battery Life Diagnostic Tool software before v…
CVE-2026-119853.60.6zephyrprojectzephyrCWE-200Cross-thread FPU register leak on ARM when FPU enabled without register sharing
CVE-2026-207167.20.4n/aIntel(R) ProcessorsCWE-284Improper access control for some Intel(R) Processors within Ring 3: User Appl…
CVE-2025-319384.30.4n/aIntel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.CWE-1220Insufficient granularity of access control in some subsystem for some Intel(R…
CVE-2026-572637.00.3SiemensLOGO! Soft ComfortCWE-759A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9)…
CVE-2026-732832.50.3OpenBSDOpenSSHCWE-670In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was…
CVE-2026-207076.80.1n/a3rd Gen Intel(R) Xeon(R) Scalable ProcessorsCWE-1298Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Sca…
CVE-2026-65055.10.1Axis Communications ABAXIS OSCWE-367The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race cond…
CVE-2026-209085.80.1n/aIntel(R) NPU Driver for WindowsCWE-367Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Wind…
CVE-2025-313565.60.1n/aIntel(R) Trust Domain Extensions (Intel(R) TDX)CWE-345Insufficient verification of data authenticity for some Intel(R) Trust Domain…