89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,851–2,900 of 8,161 in High · page 58 of 164

IDTitleSummary
CVE-2026-21280CVE-2026-21280
CVSS 8.6adobe
Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte…
CVE-2026-21272CVE-2026-21272
CVSS 8.6adobe
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An att…
CVE-2026-21271CVE-2026-21271
CVSS 8.6adobe
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the c…
CVE-2026-21268CVE-2026-21268
CVSS 8.6adobe
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the c…
CVE-2026-21267CVE-2026-21267
CVSS 8.6adobe
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul…
CVE-2026-21262CVE-2026-21262
CVSS 8.8microsoft
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-21257CVE-2026-21257
CVSS 8.0
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevat…
CVE-2026-21256CVE-2026-21256
CVSS 8.8
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to exec…
CVE-2026-21255CVE-2026-21255
CVSS 8.8
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
CVE-2026-21229CVE-2026-21229
CVSS 8.0microsoft
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-21228CVE-2026-21228
CVSS 8.1
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
CVE-2026-2110CVE-2026-2110
CVSS 8.1
A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown function…
CVE-2026-2109CVE-2026-2109
CVSS 8.1
A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category …
CVE-2026-2107CVE-2026-2107
CVSS 8.8
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDelet…
CVE-2026-2106CVE-2026-2106
CVSS 8.8
A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/…
CVE-2026-2105CVE-2026-2105
CVSS 8.8
A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of…
CVE-2026-2101CVE-2026-2101
CVSS 8.7
A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 …
CVE-2026-20990CVE-2026-20990
CVSS 8.1
Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Sec…
CVE-2026-2097CVE-2026-2097
CVSS 8.8
Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, …
CVE-2026-20967CVE-2026-20967
CVSS 8.8
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-20960CVE-2026-20960
CVSS 8.0
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
CVE-2026-20953CVE-2026-20953
CVSS 8.4
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20952CVE-2026-20952
CVSS 8.4
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-20947CVE-2026-20947
CVSS 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute co…
CVE-2026-20944CVE-2026-20944
CVSS 8.4
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-2094CVE-2026-2094
CVSS 8.8
Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and…
CVE-2026-20931CVE-2026-20931
CVSS 8.0microsoft
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2026-20916CVE-2026-20916
CVSS 8.1f5
An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system…
CVE-2026-20910CVE-2026-20910
CVSS 8.0copeland
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the…
CVE-2026-20902CVE-2026-20902
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on …
CVE-2026-20868CVE-2026-20868
CVSS 8.8microsoft
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2026-2086CVE-2026-2086
CVSS 8.8
A vulnerability was detected in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy of the file /goform/formFireWall of th…
CVE-2026-20856CVE-2026-20856
CVSS 8.1microsoft
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
CVE-2026-2079CVE-2026-2079
CVSS 8.8
A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addMenu/updateMenu/deleteMenu…
CVE-2026-2078CVE-2026-2078
CVSS 8.8
A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermission/delet…
CVE-2026-20777CVE-2026-20777
CVSS 8.1
A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). …
CVE-2026-2077CVE-2026-2077
CVSS 8.8
A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function addRole/u…
CVE-2026-20766CVE-2026-20766
CVSS 8.8
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
CVE-2026-20764CVE-2026-20764
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the…
CVE-2026-20761CVE-2026-20761
CVSS 8.1
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to s…
CVE-2026-2076CVE-2026-2076
CVSS 8.8
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vulnerability is the function addUser/updat…
CVE-2026-20759CVE-2026-20759
CVSS 8.8
OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a logged-in user with the l…
CVE-2026-2075CVE-2026-2075
CVSS 8.8
A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the function saveRolePermission of the file…
CVE-2026-20748CVE-2026-20748
CVSS 8.6
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifi…
CVE-2026-20742CVE-2026-20742
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on th…
CVE-2026-2072CVE-2026-2072
CVSS 8.2hitachi
Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hita…
CVE-2026-2071CVE-2026-2071
CVSS 8.8
A vulnerability was found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formP2PLimitConfig. Performing a manipul…
CVE-2026-20700Apple Multiple Buffer Overflow Vulnerability
KEVCVSS 7.8Apple
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow…
CVE-2026-2070CVE-2026-2070
CVSS 8.8
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/formPolicyRouteConf. Such manipulat…
CVE-2026-2068CVE-2026-2068
CVSS 8.8
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/formSyslogConf. The manipulation of the ar…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.