Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 181 - 200 of 34,871 CVEs
CVE-2020-37252 HIGH - 7.8

Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSyst...

Vendor: Realtek
Product: Realtek Audio Service
Published: Jun 19, 2026
Source: NVD
CVE-2020-37251 HIGH - 7.8

RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service st...

Vendor: Real
Product: RealTimes Desktop Service
Published: Jun 19, 2026
Source: NVD
CVE-2020-37250 HIGH - 7.8

TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can place a malicious executable in the Program Files directory path that will be executed during service ...

Vendor: Weird-Solutions
Product: TFTP Broadband
Published: Jun 19, 2026
Source: NVD
CVE-2019-25747 HIGH - 7.8

Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary c...

Vendor: Network-Inventory-Advisor
Product: Network Inventory Advisor
Published: Jun 19, 2026
Source: NVD
CVE-2016-20095 HIGH - 7.8

Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory...

Vendor: Matrix42
Product: Matrix42 Remote Control Host
Published: Jun 19, 2026
Source: NVD
CVE-2016-20094 HIGH - 7.8

AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application s...

Vendor: Anydesk
Product: AnyDesk
Published: Jun 19, 2026
Source: NVD
CVE-2016-20093 HIGH - 7.8

Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that ex...

Vendor: Wise
Product: Wisecleaner
Published: Jun 19, 2026
Source: NVD
CVE-2016-20092 HIGH - 7.8

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or syst...

Vendor: Netdrive
Product: NetDrive
Published: Jun 19, 2026
Source: NVD
CVE-2016-20091 HIGH - 7.8

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with Lo...

Vendor: Binisoft
Product: Windows Firewall Control
Published: Jun 19, 2026
Source: NVD
CVE-2016-20090 HIGH - 7.8

Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated ...

Vendor: Comodo
Product: Dragon Browser
Published: Jun 19, 2026
Source: NVD
CVE-2016-20089 HIGH - 7.8

Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation path. When installed from directories containing spaces, attackers can place malicious executables in the path to be ex...

Vendor: Iperiusremote
Product: Iperius Remote
Published: Jun 19, 2026
Source: NVD
CVE-2016-20088 HIGH - 7.8

Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or sys...

Vendor: Comodo
Product: Chromodo Browser
Published: Jun 19, 2026
Source: NVD
CVE-2016-20087 HIGH - 7.8

Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the service binary path. Attackers can insert malicious executables in the system root path that execute with SYSTEM privileges during servi...

Vendor: Networkdls
Product: Fortitude HTTP
Published: Jun 19, 2026
Source: NVD
CVE-2016-20086 HIGH - 7.8

Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and restart the service to execute code with LocalSystem pri...

Vendor: Vembu
Product: Vembu StoreGrid
Published: Jun 19, 2026
Source: NVD
CVE-2016-20085 HIGH - 7.8

Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by placing a malicious executable in the service path. Attackers can insert an executable file in the unquoted path and restart the service to execute co...

Vendor: Realtek
Product: Realtek High Definition Audio Driver
Published: Jun 19, 2026
Source: NVD
CVE-2026-55832 MEDIUM - 6.1

tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx

Vendor: rust
Product: tract-onnx
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55773 HIGH - 8.8

CedarJava has policy injection vulnerability

Vendor: maven
Product: com.cedarpolicy:cedar-java
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55772 HIGH - 8.8

CedarJava has type confusion vulnerability

Vendor: maven
Product: com.cedarpolicy:cedar-java
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55767 MEDIUM - 5.8

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

Vendor: composer
Product: guzzlehttp/guzzle
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55766 MEDIUM - 4.8

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

Vendor: composer
Product: guzzlehttp/psr7
Published: Jun 19, 2026
Source: GitHub