| CVE-2026-56642 | 8.8 | — | — | — | microsoft / fabric data warehouse | Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over | 53d ago |
| CVE-2026-56197 | 8.8 | — | — | — | microsoft / windows admin center | Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows | 53d ago |
| CVE-2026-56196 | 8.8 | — | — | — | microsoft / windows admin center | Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-56194 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over | 53d ago |
| CVE-2026-55052 | 8.8 | — | — | — | microsoft / sharepoint server | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a ne | 53d ago |
| CVE-2026-54121 | 8.8 | — | — | — | microsoft / windows 10 1607 | Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate p | 53d ago |
| CVE-2026-50692 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50687 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50670 | 8.8 | — | — | — | microsoft / windows 10 1809 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50666 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges ove | 53d ago |
| CVE-2026-50489 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50477 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50474 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-50444 | 8.8 | — | — | — | microsoft / windows 10 1607 | Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to ele | 53d ago |
| CVE-2026-50438 | 8.8 | — | — | — | microsoft / pc manager | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attack | 53d ago |
| CVE-2026-50413 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50398 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allow | 53d ago |
| CVE-2026-50385 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50382 | 8.8 | — | — | — | microsoft / windows 10 1809 | Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | 53d ago |
| CVE-2026-50370 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent | 53d ago |
| CVE-2026-50369 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a netwo | 53d ago |
| CVE-2026-50360 | 8.8 | — | — | — | microsoft / windows 10 21h2 | Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevat | 53d ago |
| CVE-2026-47295 | 8.8 | — | — | — | microsoft / sql server 2016 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an autho | 53d ago |
| CVE-2026-58608 | 8.8 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spool | 53d ago |
| CVE-2026-57969 | 8.8 | — | — | — | microsoft / azure cyclecloud | Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileg | 53d ago |
| CVE-2026-55005 | 8.8 | — | — | — | microsoft / exchange server | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a netwo | 53d ago |
| CVE-2026-55002 | 8.8 | — | — | — | microsoft / sql server 2016 | External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a net | 53d ago |
| CVE-2026-54999 | 8.8 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allo | 53d ago |
| CVE-2026-54982 | 8.8 | — | — | — | microsoft / windows 10 1607 | Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized atta | 53d ago |
| CVE-2026-54107 | 8.8 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allo | 53d ago |
| CVE-2026-50663 | 8.8 | — | — | — | microsoft / age of empires ii | Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute c | 53d ago |
| CVE-2026-50342 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally | 53d ago |
| CVE-2026-49795 | 8.8 | — | — | — | microsoft / windows 10 1809 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49178 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over | 53d ago |
| CVE-2026-48564 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-47632 | 8.8 | — | — | — | microsoft / azure connected machine agent | Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privil | 53d ago |
| CVE-2026-15429 | 8.8 | — | — | — | tp-link / archer vx1800v firmware | A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. | 53d ago |
| CVE-2026-15428 | 8.8 | — | — | — | tp-link / archer vx1800v firmware | An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the dom | 53d ago |
| CVE-2026-15696 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. | 53d ago |
| CVE-2026-15695 | 8.8 | — | — | — | — | A flaw has been found in Tenda BE12 Pro 16.03.66.23. | 53d ago |
| CVE-2026-15694 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. | 53d ago |
| CVE-2026-15693 | 8.8 | — | — | — | — | A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. | 53d ago |
| CVE-2026-15692 | 8.8 | — | — | — | — | A weakness has been identified in Tenda BE12 Pro 16.03.66.23. | 53d ago |
| CVE-2026-15691 | 8.8 | — | — | — | — | A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. | 53d ago |
| CVE-2026-57856 | 8.8 | — | — | — | — | Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). | 54d ago |
| CVE-2026-57855 | 8.8 | — | — | — | — | Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). | 54d ago |
| CVE-2026-62200 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext trans | 54d ago |
| CVE-2026-62199 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter star | 54d ago |
| CVE-2026-62194 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install command | 54d ago |
| CVE-2026-62190 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows l | 54d ago |
| CVE-2026-55773 | 8.8 | — | — | — | — | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization | 54d ago |
| CVE-2026-55771 | 8.8 | — | — | — | — | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization | 54d ago |
| CVE-2026-55772 | 8.8 | — | — | — | — | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization | 54d ago |
| CVE-2026-49972 | 8.8 | — | — | — | — | Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achiev | 54d ago |
| CVE-2026-49970 | 8.8 | — | — | — | — | Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that al | 54d ago |
| CVE-2026-61463 | 8.8 | — | — | — | — | Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated user | 54d ago |
| CVE-2026-57786 | 8.8 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication | 55d ago |
| CVE-2026-57713 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Objec | 55d ago |
| CVE-2026-57410 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalati | 55d ago |
| CVE-2026-57386 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue | 55d ago |