| CVE-2026-71386 | 8.8 | — | — | — | adobe / coldfusion | is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the con | 25d ago |
| CVE-2026-70337 | 8.8 | — | — | — | microsoft / powershell | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a networ | 25d ago |
| CVE-2026-70336 | 8.8 | — | — | — | microsoft / visual studio code | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to | 25d ago |
| CVE-2026-70329 | 8.8 | — | — | — | microsoft / 365 apps | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a | 25d ago |
| CVE-2026-70326 | 8.8 | — | — | — | microsoft / sharepoint server | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privile | 25d ago |
| CVE-2026-70324 | 8.8 | — | — | — | microsoft / sharepoint server | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privile | 25d ago |
| CVE-2026-70321 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-69320 | 8.8 | — | — | — | microsoft / visual studio code | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code a | 25d ago |
| CVE-2026-66808 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-66805 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-65815 | 8.8 | — | — | — | microsoft / dynamics 365 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute | 25d ago |
| CVE-2026-65811 | 8.8 | — | — | — | microsoft / power bi report server | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 25d ago |
| CVE-2026-65807 | 8.8 | — | — | — | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized att | 25d ago |
| CVE-2026-65768 | 8.8 | — | — | — | microsoft / teams | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allo | 25d ago |
| CVE-2026-65767 | 8.8 | — | — | — | microsoft / teams | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Androi | 25d ago |
| CVE-2026-65665 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-65663 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-65660 | 8.8 | — | — | — | microsoft / sharepoint server | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized atta | 25d ago |
| CVE-2026-65658 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-64921 | 8.8 | — | — | — | microsoft / sharepoint server | Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to eleva | 25d ago |
| CVE-2026-64901 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-63514 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-62913 | 8.8 | — | — | — | microsoft / exchange server | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a netwo | 25d ago |
| CVE-2026-62872 | 8.8 | — | — | — | microsoft / .net framework | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | 25d ago |
| CVE-2026-62869 | 8.8 | — | — | — | microsoft / entra id | Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing | 25d ago |
| CVE-2026-62827 | 8.8 | — | — | — | microsoft / sharepoint server | Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a | 25d ago |
| CVE-2026-62824 | 8.8 | — | — | — | microsoft / windows 10 1607 | Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a networ | 25d ago |
| CVE-2026-62823 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent | 25d ago |
| CVE-2026-62822 | 8.8 | — | — | — | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62818 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over | 25d ago |
| CVE-2026-62817 | 8.8 | — | — | — | microsoft / windows 10 1809 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | 25d ago |
| CVE-2026-62816 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to exec | 25d ago |
| CVE-2026-62800 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62795 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute | 25d ago |
| CVE-2026-62790 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62785 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker | 25d ago |
| CVE-2026-62784 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to | 25d ago |
| CVE-2026-59133 | 8.8 | — | — | — | microsoft / windows app | Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized atta | 25d ago |
| CVE-2026-59113 | 8.8 | — | — | — | microsoft / visual studio code | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-57104 | 8.8 | — | — | — | microsoft / azure storage explorer | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer all | 25d ago |
| CVE-2026-49179 | 8.8 | — | — | — | microsoft / windows 10 1607 | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory al | 25d ago |
| CVE-2026-20749 | 8.8 | — | — | — | intel / proset\/wireless wifi | Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow an esca | 25d ago |
| CVE-2026-56721 | 8.8 | — | — | — | — | CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object ref | 25d ago |
| CVE-2026-19546 | 8.8 | — | — | — | — | A flaw was found in DBI. | 25d ago |
| CVE-2026-72781 | 8.8 | — | — | — | — | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulne | 25d ago |
| CVE-2026-72778 | 8.8 | — | — | — | — | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote c | 25d ago |
| CVE-2026-72775 | 8.8 | — | — | — | n8n / n8n | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which | 25d ago |
| CVE-2026-72750 | 8.8 | — | — | — | n8n / n8n | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Que | 25d ago |
| CVE-2026-72562 | 8.8 | — | — | — | — | An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend | 25d ago |
| CVE-2026-72561 | 8.8 | — | — | — | — | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated | 25d ago |
| CVE-2026-72558 | 8.8 | — | — | — | — | An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire databa | 25d ago |
| CVE-2026-72557 | 8.8 | — | — | — | — | An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any e | 25d ago |
| CVE-2026-72556 | 8.8 | — | — | — | — | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands b | 25d ago |
| CVE-2026-72551 | 8.8 | — | — | — | — | A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to e | 25d ago |
| CVE-2026-72538 | 8.8 | — | — | — | — | An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remot | 25d ago |
| CVE-2026-72537 | 8.8 | — | — | — | — | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a so | 25d ago |
| CVE-2026-72534 | 8.8 | — | — | — | — | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a so | 25d ago |
| CVE-2026-72533 | 8.8 | — | — | — | — | An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to | 25d ago |
| CVE-2026-15555 | 8.8 | — | — | — | — | A flaw was found in JBoss marshalling. | 25d ago |
| CVE-2026-58243 | 8.8 | — | — | — | — | SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an | 26d ago |