Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-56174 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-54984 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-54981 Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a securit… Python No fix yet Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-54123 Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information l… Defender For Endpoint 101.26042.0020+ Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-54113 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 CRITICAL 9.4 CVE-2026-50516 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $5,7502026-08-11 HIGH 7.0 CVE-2026-50472 Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-49179 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to ex… Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-48483 TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwar… Patch available Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-48446 CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lea… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.2 CVE-2026-48445 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.2 CVE-2026-48444 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.2 CVE-2026-48443 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 HIGH 7.1 CVE-2026-48442 CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could res… C2pa 0.12.1 / 0.27.6+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-48440 ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user… Coldfusion No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-48439 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack… C2pa 0.12.1 / 0.27.6+ Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-48438 CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker co… C2pa 0.12.1 / 0.27.6+ Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-48437 CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker c… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-48436 CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could l… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.2 CVE-2026-48435 CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service.… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.2 CVE-2026-48434 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.2 CVE-2026-48387 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-48386 ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An atta… Coldfusion No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-48385 ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu… Coldfusion No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-48376 is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker cou… Coldfusion No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-48375 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker c… Coldfusion No fix yet Fix from $4,0002026-08-11 CRITICAL 10.0 CVE-2026-48362 ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu… Coldfusion No fix yet Fix from $5,7502026-08-11 HIGH 7.1 CVE-2026-47704 TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook ses… Patch available Fix from $4,9002026-08-11 HIGH 7.2 CVE-2026-47299 Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate p… Azure Monitor Agent 1.43+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-47285 Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose… Visual Studio Code 1.132.1+ Fix from $4,0002026-08-11