Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-56174
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9115 / 10.0.19044.7663+
HIGH 7.8
CVE-2026-54984
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.8
CVE-2026-54981
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a securit…
Python
No fix yet
MEDIUM 5.5
CVE-2026-54123
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information l…
Defender For Endpoint
101.26042.0020+
HIGH 7.5
CVE-2026-54113
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
CRITICAL 9.4
CVE-2026-50516
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Azure Kubernetes Service
No fix yet
HIGH 7.0
CVE-2026-50472
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 8.8
CVE-2026-49179
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to ex…
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.4
CVE-2026-48483
TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwar…
Patch available
MEDIUM 5.5
CVE-2026-48446
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lea…
C2pa
0.12.1 / 0.27.6+
MEDIUM 6.2
CVE-2026-48445
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta…
C2pa
0.12.1 / 0.27.6+
MEDIUM 6.2
CVE-2026-48444
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta…
C2pa
0.12.1 / 0.27.6+
MEDIUM 6.2
CVE-2026-48443
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack…
C2pa
0.12.1 / 0.27.6+
HIGH 7.1
CVE-2026-48442
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could res…
C2pa
0.12.1 / 0.27.6+
HIGH 8.1
CVE-2026-48440
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user…
Coldfusion
No fix yet
HIGH 7.5
CVE-2026-48439
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack…
C2pa
0.12.1 / 0.27.6+
HIGH 7.5
CVE-2026-48438
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker co…
C2pa
0.12.1 / 0.27.6+
MEDIUM 5.5
CVE-2026-48437
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker c…
C2pa
0.12.1 / 0.27.6+
MEDIUM 6.5
CVE-2026-48436
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could l…
C2pa
0.12.1 / 0.27.6+
MEDIUM 6.2
CVE-2026-48435
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service.…
C2pa
0.12.1 / 0.27.6+
MEDIUM 6.2
CVE-2026-48434
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack…
C2pa
0.12.1 / 0.27.6+
MEDIUM 6.2
CVE-2026-48387
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta…
C2pa
0.12.1 / 0.27.6+
HIGH 7.5
CVE-2026-48386
ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An atta…
Coldfusion
No fix yet
HIGH 7.7
CVE-2026-48385
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu…
Coldfusion
No fix yet
MEDIUM 5.4
CVE-2026-48376
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker cou…
Coldfusion
No fix yet
MEDIUM 6.5
CVE-2026-48375
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker c…
Coldfusion
No fix yet
CRITICAL 10.0
CVE-2026-48362
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu…
Coldfusion
No fix yet
HIGH 7.1
CVE-2026-47704
TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook ses…
Patch available
HIGH 7.2
CVE-2026-47299
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate p…
Azure Monitor Agent
1.43+
MEDIUM 6.5
CVE-2026-47285
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose…
Visual Studio Code
1.132.1+