| CVE-2026-26133 | 7.1 | — | — | — | microsoft / 365 copilot | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 206d ago |
| CVE-2025-15553 | 7.1 | — | — | — | truesec / lapswebui | Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a wor | 206d ago |
| CVE-2019-25529 | 7.1 | — | — | — | — | Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate d | 210d ago |
| CVE-2019-25473 | 7.1 | — | — | — | — | Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queri | 210d ago |
| CVE-2026-32126 | 7.1 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 211d ago |
| CVE-2026-2368 | 7.1 | — | — | — | lenovo / filez | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a us | 211d ago |
| CVE-2026-1716 | 7.1 | — | — | — | lenovo / vantage | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo B | 211d ago |
| CVE-2026-1715 | 7.1 | — | — | — | lenovo / vantage | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo B | 211d ago |
| CVE-2026-71221 | 7 | — | — | — | — | A stack out-of-bounds write vulnerability was found in gfs2-utils. | 35d ago |
| CVE-2026-71220 | 7 | — | — | — | — | A stack out-of-bounds write vulnerability was found in gfs2-utils. | 35d ago |
| CVE-2026-78409 | 7 | — | — | — | — | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdire | 36d ago |
| CVE-2026-73725 | 7 | — | — | — | arubanetworks / fabric composer | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. | 37d ago |
| CVE-2026-84233 | 7 | — | — | — | — | A flaw was found in rpm. | 37d ago |
| CVE-2026-13732 | 7 | — | — | — | — | A flaw was found in GDB's STABS debug format parser. | 38d ago |
| CVE-2026-16821 | 7 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a fo | 41d ago |
| CVE-2026-81726 | 7 | — | — | — | nltk / nltk | NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement | 42d ago |
| CVE-2026-81714 | 7 | — | — | — | jahlives / openssl encrypt | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_ | 42d ago |
| CVE-2026-58093 | 7 | — | — | — | — | The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. | 44d ago |
| CVE-2026-54467 | 7 | — | — | — | — | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2 | 44d ago |
| CVE-2026-65082 | 7 | — | — | — | nvidia / nemoclaw | NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause co | 44d ago |
| CVE-2026-66153 | 7 | — | — | — | — | The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which | 44d ago |
| CVE-2026-75037 | 7 | — | — | — | — | Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. | 44d ago |
| CVE-2026-78465 | 7 | — | — | — | gimp / gimp | A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. | 45d ago |
| CVE-2026-78367 | 7 | — | — | — | — | A vulnerability was found in RPM's rpmbuild tarball processing. | 45d ago |
| CVE-2026-77584 | 7 | — | — | — | — | Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached stream | 49d ago |
| CVE-2026-63387 | 7 | — | — | — | — | Libevent is an event notification library. | 49d ago |
| CVE-2026-18268 | 7 | — | — | — | — | Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. | 49d ago |
| CVE-2026-16923 | 7 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to impr | 49d ago |
| CVE-2026-16922 | 7 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time | 49d ago |
| CVE-2026-62727 | 7 | — | — | — | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 50d ago |
| CVE-2026-16838 | 7 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain | 50d ago |
| CVE-2026-48711 | 7 | — | — | — | — | SSHFS is a network filesystem client for connecting to SSH servers. | 50d ago |
| CVE-2026-71098 | 7 | — | — | — | oracle / business intelligence | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platf | 51d ago |
| CVE-2026-71041 | 7 | — | — | — | oracle / agile product lifecycle management | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Gantt Chart). | 51d ago |
| CVE-2026-70992 | 7 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 51d ago |
| CVE-2026-70914 | 7 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 51d ago |
| CVE-2026-70697 | 7 | — | — | — | oracle / agile engineering data management | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineeri | 51d ago |
| CVE-2026-70676 | 7 | — | — | — | oracle / hyperion calculation manager | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). | 51d ago |
| CVE-2026-62449 | 7 | — | — | — | oracle / work in process | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-60902 | 7 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). | 51d ago |
| CVE-2026-75857 | 7 | — | — | — | — | CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) | 51d ago |
| CVE-2026-34789 | 7 | — | — | — | — | FreeCAD is a free and open-source multiplatform 3D parametric modeler. | 52d ago |
| CVE-2026-6387 | 7 | — | — | — | — | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authe | 56d ago |
| CVE-2026-15994 | 7 | — | — | — | — | During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage | 56d ago |
| CVE-2026-53996 | 7 | — | — | — | — | NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allow | 57d ago |
| CVE-2026-70307 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 58d ago |
| CVE-2026-68820zero day | 7 | 0.33% | 3/3 | same day | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 58d ago |
| CVE-2026-65788 | 7 | — | — | — | microsoft / windows 11 23h2 | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-65783 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-65782 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-65781 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-65780 | 7 | — | — | — | microsoft / windows 11 24h2 | Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-65779 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-65778 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-65776 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-65678 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62908 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engi | 58d ago |
| CVE-2026-62897 | 7 | — | — | — | microsoft / .net framework | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | 58d ago |
| CVE-2026-62892 | 7 | — | — | — | microsoft / windows 10 1809 | Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privilege | 58d ago |
| CVE-2026-62788 | 7 | — | — | — | microsoft / windows 11 23h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 58d ago |