Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

365 Apps HIGH 7.8
CVE-2026-55056

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55049

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 5.5
CVE-2026-55035

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2026-07-14
Minecraft Bedrock Dedicated Server CRITICAL 9.8
CVE-2026-55010

Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-14
Unclassified HIGH 7.8
CVE-2026-50665

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.1
CVE-2026-50661

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.1
CVE-2026-50453

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

Mitigation only
Fix from $1,600 2026-07-14
365 Apps HIGH 7.8
CVE-2026-50314

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.4
CVE-2026-4018

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_T…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 7.4
CVE-2026-4017

Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data …

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15757

A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the…

No fix yet
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.2
CVE-2026-0515

Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 7.1
CVE-2026-56193

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.6
CVE-2026-50678

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2026-07-14
Surface Go 2 1901 Firmware HIGH 7.8
CVE-2026-48581

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $1,950 2026-07-14
365 Copilot CRITICAL 9.6
CVE-2026-48561

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …

Mitigation only
Fix from $2,300 2026-07-14
Azure Connected Machine Agent HIGH 8.8
CVE-2026-47632

Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 7.3
CVE-2026-15703

A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/u…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-15701

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified MEDIUM 5.1
CVE-2026-14645

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, all…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 8.2
CVE-2026-9636

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation h…

No fix yet
Fix from $1,950 2026-07-14
Unclassified HIGH 8.4
CVE-2026-9292

A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralizati…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 7.3
CVE-2026-9128

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The exe…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 7.3
CVE-2026-9127

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can all…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 5.4
CVE-2026-9108

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The soft…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.3
CVE-2026-7494

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-trust…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 7.1
CVE-2026-55651

Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15697

A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm P…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 8.2
CVE-2026-14504

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda …

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 7.5
CVE-2026-12707

Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migratio…

Mitigation only
Fix from $1,950 2026-07-14