| CVE-2026-20716 | 7 | high | intel / xeon 634 firmware | Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of p | 25d ago |
| CVE-2026-58230 | 7 | high | — | SAP Approuter does not sufficiently validate certain token content under specific configurations. | 26d ago |
| CVE-2026-70640 | 7 | high | — | llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JN | 30d ago |
| CVE-2026-64587 | 7 | high | — | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts b | 30d ago |
| CVE-2026-18718 | 7 | high | — | Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker | 33d ago |
| CVE-2026-18605 | 7 | high | — | A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. | 33d ago |
| CVE-2026-69097 | 7 | high | — | GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject a | 33d ago |
| CVE-2026-10848 | 7 | high | zephyrproject / zephyr | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ | 34d ago |
| CVE-2026-67326 | 7 | high | — | GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing | 35d ago |
| CVE-2026-17993 | 7 | high | google / chrome | Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege e | 38d ago |
| CVE-2026-40272 | 7 | high | — | Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corru | 38d ago |
| CVE-2026-16184 | 7 | high | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a | 39d ago |
| CVE-2026-43755 | 7 | high | apple / macos | A race condition was addressed with improved state management. | 40d ago |
| CVE-2026-43693 | 7 | high | apple / macos | A race condition was addressed with improved state handling. | 40d ago |
| CVE-2026-28926 | 7 | high | apple / macos | A race condition was addressed with improved state handling. | 40d ago |
| CVE-2026-64510 | 7 | high | — | In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix acpi_nfit_init() error c | 42d ago |
| CVE-2026-64460 | 7 | high | — | In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Skip VF Resizable BAR restore on read | 42d ago |
| CVE-2026-64420 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mfd: cros_ec: Delay dev_set_drvdata() until pr | 42d ago |
| CVE-2026-64413 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sas | 42d ago |
| CVE-2026-64315 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: caam - use print_hex_dump_devel to gua | 42d ago |
| CVE-2026-64283 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Treat memslot binding offset | 42d ago |
| CVE-2026-64222 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack | 43d ago |
| CVE-2026-64219 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and l | 43d ago |
| CVE-2026-16584 | 7 | high | — | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an act | 44d ago |
| CVE-2026-61120 | 7 | high | oracle / human resources management system | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). | 46d ago |
| CVE-2026-61061 | 7 | high | oracle / jdeveloper | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). | 46d ago |
| CVE-2026-60833 | 7 | high | oracle / solaris | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). | 46d ago |
| CVE-2026-60705 | 7 | high | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 46d ago |
| CVE-2026-60494 | 7 | high | oracle / jd edwards enterpriseone general ledger | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundatio | 46d ago |
| CVE-2026-46999 | 7 | high | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Disc | 46d ago |
| CVE-2026-58598 | 7 | high | microsoft / windows 10 21h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engi | 51d ago |
| CVE-2026-53410 | 7 | high | zoom / remote control for zoom contact center | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Z | 51d ago |
| CVE-2026-61389 | 7 | high | — | An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory co | 51d ago |
| CVE-2026-60063 | 7 | high | — | An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory co | 51d ago |
| CVE-2026-9046 | 7 | high | — | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applica | 51d ago |
| CVE-2026-54684 | 7 | high | — | jadx is a Dex to Java decompiler. | 53d ago |
| CVE-2026-50526 | 7 | high | microsoft / .net | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform ta | 53d ago |
| CVE-2026-58637 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges lo | 53d ago |
| CVE-2026-58629 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-58619 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-58544 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-57093 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 53d ago |
| CVE-2026-56187 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-56183 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-56173 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50674 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50672 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50669 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 53d ago |
| CVE-2026-50658 | 7 | high | microsoft / defender for endpoint | Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate p | 53d ago |
| CVE-2026-50503 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50491 | 7 | high | microsoft / windows 10 1607 | Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50490 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50459 | 7 | high | microsoft / windows 10 21h2 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50452 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50449 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50410 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50406 | 7 | high | microsoft / windows 10 21h2 | Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50404 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allow | 53d ago |
| CVE-2026-50403 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50397 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |