Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-50694 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-50522 KEVEPSS 85% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 CRITICAL 9.3 CVE-2026-49798 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-49181 Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-49172 Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-49164 Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.6 CVE-2026-48561 Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker … 365 Copilot Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-42990 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-15701 A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-62644 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session … Webmail 1.6.17 / 1.7.2+ Fix from $2,3002026-07-14 CRITICAL 10.0 CVE-2026-62643 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to… Webmail 1.6.17 / 1.7.2+ Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source … Patch available Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-59836 A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.… Forticlientems 7.4.6+ Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-55954 Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.… Patch available Fix from $2,3002026-07-14 CRITICAL 9.2 CVE-2025-11698 A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a m… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-58479 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allow… Sustainable Irrigation Platform after 5.2.16 Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-15265 A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intende… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-10672 subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PA… Zephyr Patch available Fix from $2,3002026-07-14 CRITICAL 9.2 CVE-2025-12012 A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file dat… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.2 CVE-2025-12011 A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, caus… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-62392 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job… Kylin 5.0.4+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-62390 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca… Kylin 5.0.4+ Fix from $2,3002026-07-14 CRITICAL 10.0 CVE-2026-10577 A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-62422 In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct… Youtrack 2024.2.148429 / 2024.3.148430+ Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-58319 Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access … Doris 3.1.0+ Fix from $2,3002026-07-14 CRITICAL 10.0 CVE-2026-56451 A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in t… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-3014 Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. … Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engin… Patch available Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-59084 Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clea… Tomcat after 11.0.23 Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-59083 Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configura… Tomcat after 11.0.23 Fix from $2,3002026-07-14