FR
live
cve

Full archive

Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-48381Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.Adobe Campaign Critical CVSS 9 11/08 CVE-2026-48385ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.Adobe Coldfusion High CVSS 7.7 11/08 CVE-2026-48386ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.Adobe Coldfusion High CVSS 7.5 11/08 CVE-2026-48397Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Adobe Lightroom High CVSS 8.6 11/08 CVE-2026-48404Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Lightroom High CVSS 7.8 11/08 CVE-2026-48405Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Lightroom High CVSS 7.8 11/08 CVE-2026-48406Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Lightroom High CVSS 7.8 11/08 CVE-2026-48407Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Lightroom High CVSS 7.8 11/08 CVE-2026-48408Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Lightroom High CVSS 7.8 11/08 CVE-2026-48409Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Lightroom High CVSS 7.8 11/08 CVE-2026-48410Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Adobe Lightroom High CVSS 7.8 11/08 CVE-2026-48413Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.NVD analysis in progress High CVSS 8.7 11/08 CVE-2026-48414Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Scope is changed.NVD analysis in progress High CVSS 7.7 11/08 CVE-2026-48415Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.NVD analysis in progress High CVSS 7.6 11/08 CVE-2026-48416Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.NVD analysis in progress High CVSS 7.5 11/08 CVE-2026-48438CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.Adobe C2pa High CVSS 7.5 11/08 CVE-2026-48439CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.Adobe C2pa High CVSS 7.5 11/08 CVE-2026-48440ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.Adobe Coldfusion High CVSS 8.1 11/08 CVE-2026-48441Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Adobe Lightroom High CVSS 8.6 11/08 CVE-2026-48442CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.Adobe C2pa High CVSS 7.1 11/08 CVE-2026-48447Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Adobe Lightroom High CVSS 7.7 11/08 CVE-2026-48494TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign preview phone number tied to another preview session. The WhatsApp test-webhook handler authorizes the parent typebot first, but then resolves the preview chat session only by `wa-preview-{phone}`. As a result, an attacker can inject arbitrary webhook JSON into another workspace's WhatsApp preview session and advance its draft/unpublished flow without any access to the victim typebot. Version 3.17.0 patches the issue.NVD analysis in progress High CVSS 7.1 11/08 CVE-2026-48495TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callback route is authenticated, but it does not verify that the authenticated user has write access to the target workspace or Typebot before creating credentials in the workspace or updating Typebot groups. An authenticated user who can obtain a valid Google OAuth `code` can alter the `state` value to create Google Sheets credentials in another workspace and, if target IDs are known, attach those credentials to a block in another Typebot. Version 3.17.0 patches the issue.NVD analysis in progress High CVSS 7.1 11/08 CVE-2026-48763TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact key. Because the endpoint only checks that the referenced typebot is public and that the referenced block is a file input block, an unauthenticated attacker who knows a valid public `typebotId` and `blockId` can request presigned upload URLs for arbitrary objects in the shared bucket, including `private/...` and other tenants' `public/...` paths. Version 3.17.0 fixes this issue.NVD analysis in progress High CVSS 8.2 11/08 CVE-2026-48765TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an attacker-controlled writable `workspaceId`. The update path validates only the attacker-supplied workspace and then updates the credential record by global `id` alone, while also rewriting the credential's `workspaceId`. This allows cross-workspace OAuth credential takeover and reassignment. Version 3.17.0 patches the issue.NVD analysis in progress Critical CVSS 9.9 11/08 CVE-2026-48766TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible API keys by invoking the OpenAI model-listing helper with an attacker-controlled `baseUrl`. The vulnerable path decrypts the selected workspace credential, creates an OpenAI client with the secret in both `apiKey` and the explicit `api-key` header, and then sends the outbound request to the caller-supplied URL. Because the permission check accepts any readable workspace member and `listCredentials` reveals credential identifiers to guests, a guest can force the server to deliver the workspace secret to attacker infrastructure. Version 3.17.0 patches the issue.NVD analysis in progress High CVSS 7.6 11/08 CVE-2026-48767TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the caller has read access to the workspace, decrypts the stored Google OAuth credential, refreshes or retrieves the access token through the Google client, and returns the raw bearer token directly to the caller. Because guest members can also enumerate credential identifiers, a guest can mint and reuse the workspace's Google access token outside Typebot. Version 3.17.0 patches the issue.NVD analysis in progress High CVSS 7.6 11/08 CVE-2026-48771ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications using publicly exposed database credentials or permissive database rules may allow unauthorised users to read, modify, or abuse stored form submission data. This could impact personally identifiable information (PII) submitted through the website contact form, including names, email addresses, phone numbers, and messages. The issue has been patched in version 1.0.1. Users unable to upgrade immediately can reduce risk by disabling public read/write database access, rotating exposed API keys, restricting database policies to authenticated requests only, moving sensitive operations to secure backend/serverless functions, and/or monitoring database activity logs for suspicious access.NVD analysis in progress High CVSS 8.2 11/08 CVE-2026-48802python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet. This issue primarily affects synchronous servers. Asynchronous servers allocate background tasks instead of physical threads, which are lightweight and less likely to cause denial of service. However, the fix that was implemented was also applied to the asynchronous case. Version 4.13.2 addresses this issue as follows: The initial background thread (or async task( for heartbeat management is only launched if a client passes authentication in the `connect` handler; and the server now ensures that there is only one background heatbeat thread (or async task) per client at a given point in time. Out of sequence PONG packets are now discarded when an active heartbeat thread is already running.NVD analysis in progress High CVSS 7.5 11/08 CVE-2026-48804python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. Version 5.16.4 takes the following measures to address this issue: Binary packets are only accepted from authenticated clients and, when a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.NVD analysis in progress High CVSS 7.5 11/08 CVE-2026-48809python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary memory allocations in the python-engineio server. The two cases are POST requests, when using ASGI with the long polling transport and WebSocket messages, when using Aiohttp with the WebSocket transport. Version 4.13.2 addresses this issue. ASGI severs now only load the body of incoming requests into memory after the client is confirmed to be known and authenticated, and the payload size is below the maximum allowed size. Requests that do not comply with these requirements are discarded. Aiohttp servers configure the maximum payload size in the underlying WebSocket layer from Aiohttp, so that large messages are discarded by Aiohttp before they are delivered to python-engineio.NVD analysis in progress High CVSS 7.5 11/08 CVE-2026-48813Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection. A malicious file whose name contains ANSI escape sequences can end up being included in flawfinder's standard terminal output, with many effects. Untrusted fields (such as filenames, categories, or code context text) were not properly sanitized when generating structured reports. An attacker could exploit this to corrupt CSV formats or inject arbitrary XML attributes into SonarQube outputs via output_sonar(). It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. This issue has been fully patched in Version 2.0.20 (released 2026-05-16). There is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by pre-scanning filenames, inspecting raw output, and/or restricting untrusted inputs.NVD analysis in progress High CVSS 8.7 11/08 CVE-2026-49179Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 11/08 CVE-2026-50058A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-50059A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-50060A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-50061A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-50062A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-50063A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-50064A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-50236An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.NVD analysis in progress High CVSS 7.4 11/08 CVE-2026-50237A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.NVD analysis in progress High CVSS 7.4 11/08 CVE-2026-50472Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 11/08 CVE-2026-50516Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.Microsoft Azure Kubernetes Service Critical CVSS 9.4 11/08 CVE-2026-51583An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.NVD analysis in progress High CVSS 8.5 11/08 CVE-2026-51584An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.NVD analysis in progress Critical CVSS 9.8 11/08 CVE-2026-53413Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.NVD analysis in progress High CVSS 8.3 11/08 CVE-2026-53415Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.NVD analysis in progress High CVSS 8.3 11/08 CVE-2026-53416Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.NVD analysis in progress High CVSS 7.1 11/08 CVE-2026-54113Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 11/08 CVE-2026-54981Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.Microsoft Python High CVSS 7.8 11/08 CVE-2026-54984Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-55676Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the `.php` extension intact. Committed files land in `/var/www/upload/server/php/files` (`file-upload/php/config.php:7`), and the component's nginx routes any URL ending in `.php` to php-fpm. An authenticated `GET /server/php/files/<name>.php` then executes the uploaded code as `www-data`. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular `ROLE_UPLOAD` role (`nginx/lua/nginx_auth_helpers.lua:71`), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as `www-data` inside the file-upload container. Version 26.06.1 fixes the issue.NVD analysis in progress High CVSS 8.8 11/08 CVE-2026-56174Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 11/08 CVE-2026-56179Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.Microsoft Windows 11 24h2 High CVSS 8.3 11/08 CVE-2026-56721CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting params[:id] to their own user ID to pass the self-authorization check while simultaneously setting params[:user_id] to a victim's ID, causing the controller to load and mutate the victim's account, including overwriting administrator passwords to achieve full site takeover.NVD analysis in progress High CVSS 8.8 11/08 CVE-2026-57104Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.Microsoft Azure Storage Explorer High CVSS 8.8 11/08 CVE-2026-58115A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.NVD analysis in progress Critical CVSS 10 11/08 CVE-2026-58230SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.NVD analysis in progress High CVSS 7 11/08 CVE-2026-58231SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.NVD analysis in progress Critical CVSS 10 11/08 CVE-2026-58243SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability.NVD analysis in progress High CVSS 8.8 11/08 CVE-2026-58612Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.Microsoft Powershell High CVSS 7.4 11/08 CVE-2026-58641Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.Microsoft .net High CVSS 7.8 11/08 CVE-2026-58650Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.Microsoft Visual Studio Code High CVSS 7.8 11/08 CVE-2026-58651Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-59086A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-59113Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.Microsoft Visual Studio Code High CVSS 8.8 11/08 CVE-2026-59119Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.Microsoft Powershell High CVSS 7.3 11/08 CVE-2026-59122Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 11/08 CVE-2026-59124Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.Microsoft Windows App Critical CVSS 9.8 11/08 CVE-2026-59125Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 11/08 CVE-2026-59126Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7 11/08 CVE-2026-59127Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-59132Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 11/08 CVE-2026-59133Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.Microsoft Windows App High CVSS 8.8 11/08 CVE-2026-59134Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 11/08 CVE-2026-5917libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.NVD analysis in progress Critical CVSS 9.6 11/08 CVE-2026-59700A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-59701A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-61346Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 11/08 CVE-2026-61348Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 11/08 CVE-2026-61349Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-61352Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 11/08 CVE-2026-61353Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-61355Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 11/08 CVE-2026-61356Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 11/08 CVE-2026-61357Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 11/08 CVE-2026-61358Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 11/08 CVE-2026-61359Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 High CVSS 7.8 11/08 CVE-2026-61361Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.Microsoft Windows 11 24h2 High CVSS 7 11/08 CVE-2026-61363Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 11/08 CVE-2026-61364Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-61365Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-61366Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 11/08 CVE-2026-61367Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-61918Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 11/08 CVE-2026-61923Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 11/08 CVE-2026-61924Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 11/08 CVE-2026-61925Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-61926Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08
3301–3400 / 11286 CVE

Type at least two characters.

navigate open esc dismiss