Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,385
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,981 - 2,000 of 33,671 CVEs
CVE-2026-41092 HIGH - 7.8

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40409 HIGH - 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40404 HIGH - 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40376 HIGH - 7.5

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: visual_studio_code
Published: Jun 09, 2026
Source: NVD
CVE-2026-40371 HIGH - 8.8

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

Published: Jun 09, 2026
Source: NVD

Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

Published: Jun 09, 2026
Source: NVD
CVE-2026-38615 CRITICAL - 9.8

DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

Published: Jun 09, 2026
Source: NVD
CVE-2026-35188 MEDIUM - 5.0

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path. Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-34692 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Explo...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-34335 HIGH - 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-34183 HIGH - 7.5

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUI...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-34182 CRITICAL - 9.1

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these vulnerabilities may achieve key-eq...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-34181 HIGH - 7.4

Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery. Impact Summary: An attacker impersonating a user can cause a service r...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-34180 HIGH - 7.5

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to l...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-33828 HIGH - 7.8

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-33113 MEDIUM - 5.4

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: sharepoint_server
Published: Jun 09, 2026
Source: NVD
CVE-2026-32193 HIGH - 8.8

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

Published: Jun 09, 2026
Source: NVD
CVE-2026-28301 MEDIUM - 4.8

A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.

Vendor: SolarWinds
Product: Observability Self-Hosted
Published: Jun 09, 2026
Source: NVD
CVE-2026-26142 CRITICAL - 9.8

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

Published: Jun 09, 2026
Source: NVD
CVE-2026-24181 HIGH - 7.3

NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

Vendor: NVIDIA
Product: DALI
Published: Jun 09, 2026
Source: NVD