89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,851–2,900 of 8,161 in High · page 58 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-21280 | CVE-2026-21280 CVSS 8.6adobe | Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte… |
| CVE-2026-21272 | CVE-2026-21272 CVSS 8.6adobe | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An att… |
| CVE-2026-21271 | CVE-2026-21271 CVSS 8.6adobe | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the c… |
| CVE-2026-21268 | CVE-2026-21268 CVSS 8.6adobe | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the c… |
| CVE-2026-21267 | CVE-2026-21267 CVSS 8.6adobe | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul… |
| CVE-2026-21262 | CVE-2026-21262 CVSS 8.8microsoft | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-21257 | CVE-2026-21257 CVSS 8.0 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevat… |
| CVE-2026-21256 | CVE-2026-21256 CVSS 8.8 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to exec… |
| CVE-2026-21255 | CVE-2026-21255 CVSS 8.8 | Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. |
| CVE-2026-21229 | CVE-2026-21229 CVSS 8.0microsoft | Improper input validation in Power BI allows an authorized attacker to execute code over a network. |
| CVE-2026-21228 | CVE-2026-21228 CVSS 8.1 | Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. |
| CVE-2026-2110 | CVE-2026-2110 CVSS 8.1 | A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown function… |
| CVE-2026-2109 | CVE-2026-2109 CVSS 8.1 | A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category … |
| CVE-2026-2107 | CVE-2026-2107 CVSS 8.8 | A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDelet… |
| CVE-2026-2106 | CVE-2026-2106 CVSS 8.8 | A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/… |
| CVE-2026-2105 | CVE-2026-2105 CVSS 8.8 | A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of… |
| CVE-2026-2101 | CVE-2026-2101 CVSS 8.7 | A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 … |
| CVE-2026-20990 | CVE-2026-20990 CVSS 8.1 | Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Sec… |
| CVE-2026-2097 | CVE-2026-2097 CVSS 8.8 | Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, … |
| CVE-2026-20967 | CVE-2026-20967 CVSS 8.8 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-20960 | CVE-2026-20960 CVSS 8.0 | Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. |
| CVE-2026-20953 | CVE-2026-20953 CVSS 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-20952 | CVE-2026-20952 CVSS 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-20947 | CVE-2026-20947 CVSS 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute co… |
| CVE-2026-20944 | CVE-2026-20944 CVSS 8.4 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-2094 | CVE-2026-2094 CVSS 8.8 | Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and… |
| CVE-2026-20931 | CVE-2026-20931 CVSS 8.0microsoft | External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. |
| CVE-2026-20916 | CVE-2026-20916 CVSS 8.1f5 | An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system… |
| CVE-2026-20910 | CVE-2026-20910 CVSS 8.0copeland | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the… |
| CVE-2026-20902 | CVE-2026-20902 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on … |
| CVE-2026-20868 | CVE-2026-20868 CVSS 8.8microsoft | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-2086 | CVE-2026-2086 CVSS 8.8 | A vulnerability was detected in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formFireWall of th… |
| CVE-2026-20856 | CVE-2026-20856 CVSS 8.1microsoft | Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. |
| CVE-2026-2079 | CVE-2026-2079 CVSS 8.8 | A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addMenu/updateMenu/deleteMenu… |
| CVE-2026-2078 | CVE-2026-2078 CVSS 8.8 | A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermission/delet… |
| CVE-2026-20777 | CVE-2026-20777 CVSS 8.1 | A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). … |
| CVE-2026-2077 | CVE-2026-2077 CVSS 8.8 | A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function addRole/u… |
| CVE-2026-20766 | CVE-2026-20766 CVSS 8.8 | An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras. |
| CVE-2026-20764 | CVE-2026-20764 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the… |
| CVE-2026-20761 | CVE-2026-20761 CVSS 8.1 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to s… |
| CVE-2026-2076 | CVE-2026-2076 CVSS 8.8 | A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vulnerability is the function addUser/updat… |
| CVE-2026-20759 | CVE-2026-20759 CVSS 8.8 | OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a logged-in user with the l… |
| CVE-2026-2075 | CVE-2026-2075 CVSS 8.8 | A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the function saveRolePermission of the file… |
| CVE-2026-20748 | CVE-2026-20748 CVSS 8.6 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifi… |
| CVE-2026-20742 | CVE-2026-20742 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on th… |
| CVE-2026-2072 | CVE-2026-2072 CVSS 8.2hitachi | Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hita… |
| CVE-2026-2071 | CVE-2026-2071 CVSS 8.8 | A vulnerability was found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formP2PLimitConfig. Performing a manipul… |
| CVE-2026-20700 | Apple Multiple Buffer Overflow Vulnerability KEVCVSS 7.8Apple | Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow… |
| CVE-2026-2070 | CVE-2026-2070 CVSS 8.8 | A vulnerability has been found in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/formPolicyRouteConf. Such manipulat… |
| CVE-2026-2068 | CVE-2026-2068 CVSS 8.8 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/formSyslogConf. The manipulation of the ar… |