Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-55056
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-55049
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
MEDIUM 5.5
CVE-2026-55035
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Mitigation only
CRITICAL 9.8
CVE-2026-55010
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
Minecraft Bedrock Dedicated Server
No fix yet
HIGH 7.8
CVE-2026-50665
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
No fix yet
MEDIUM 6.1
CVE-2026-50661
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Mitigation only
MEDIUM 6.1
CVE-2026-50453
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
Mitigation only
HIGH 7.8
CVE-2026-50314
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
MEDIUM 6.4
CVE-2026-4018
TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_T…
Mitigation only
HIGH 7.4
CVE-2026-4017
Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data …
Mitigation only
MEDIUM 6.3
CVE-2026-15757
A security flaw was discovered in the NETGEAR DGND3700v1 that could
allow someone on the same local WiFi network to send unauthorized commands to
the…
No fix yet
MEDIUM 6.2
CVE-2026-0515
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
Mitigation only
HIGH 7.1
CVE-2026-56193
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Mitigation only
MEDIUM 6.6
CVE-2026-50678
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Mitigation only
HIGH 7.8
CVE-2026-48581
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Surface Go 2 1901 Firmware
No fix yet
CRITICAL 9.6
CVE-2026-48561
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
365 Copilot
Mitigation only
HIGH 8.8
CVE-2026-47632
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Azure Connected Machine Agent
Mitigation only
HIGH 7.3
CVE-2026-15703
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/u…
Mitigation only
CRITICAL 9.8
CVE-2026-15701
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.…
Mitigation only
MEDIUM 5.1
CVE-2026-14645
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, all…
Mitigation only
HIGH 8.2
CVE-2026-9636
A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation h…
No fix yet
HIGH 8.4
CVE-2026-9292
A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralizati…
Mitigation only
HIGH 7.3
CVE-2026-9128
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The exe…
Mitigation only
HIGH 7.3
CVE-2026-9127
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can all…
Mitigation only
MEDIUM 5.4
CVE-2026-9108
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The soft…
Mitigation only
MEDIUM 5.3
CVE-2026-7494
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-trust…
Mitigation only
HIGH 7.1
CVE-2026-55651
Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint…
Mitigation only
MEDIUM 6.3
CVE-2026-15697
A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm P…
Mitigation only
HIGH 8.2
CVE-2026-14504
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda …
Mitigation only
HIGH 7.5
CVE-2026-12707
Summary
Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migratio…
Mitigation only