Total CVEs

149,960

Critical Severity

4,910

High Severity

17,395

Last 7 Days

1,772
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 27,021 - 27,040 of 46,365 CVEs
CVE-2026-40245 HIGH - 7.5

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disclosure vulnerability in the UDR (Unified Data Repository) service. The handler for GET /nudr-dr/v2/application-data/influenceData/subs-to-notify sends ...

Vendor: go
Product: github.com/free5gc/udr
Published: Apr 14, 2026
Source: GitHub
CVE-2026-34625 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-34624 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-34623 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-5756 HIGH - 7.5

Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfiltration, malicious traffic interception, or disruption of testing services.

Published: Apr 14, 2026
Source: NVD
CVE-2026-5754 MEDIUM - 6.1

Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.

Published: Apr 14, 2026
Source: NVD
CVE-2026-5752 CRITICAL - 9.3

Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal.

Published: Apr 14, 2026
Source: NVD
CVE-2026-34629 HIGH - 7.8

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-34628 HIGH - 7.8

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-34627 HIGH - 7.8

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-34617 HIGH - 8.7

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or contro...

Vendor: Adobe
Product: Adobe Connect
Published: Apr 14, 2026
Source: NVD
CVE-2026-34615 CRITICAL - 9.3

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Vendor: Adobe
Product: Adobe Connect
Published: Apr 14, 2026
Source: NVD
CVE-2026-34614 MEDIUM - 6.1

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browse...

Vendor: Adobe
Product: Adobe Connect
Published: Apr 14, 2026
Source: NVD
CVE-2026-33829 MEDIUM - 4.3

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-33827 HIGH - 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-33826 HIGH - 8.0

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

Vendor: microsoft
Product: windows_server_2012
Published: Apr 14, 2026
Source: NVD
CVE-2026-33825 HIGH - 7.8

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: defender_antimalware_platform
Published: Apr 14, 2026
Source: NVD
CVE-2026-33824 CRITICAL - 9.8

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-33822 MEDIUM - 6.1

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-33120 HIGH - 8.8

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

Published: Apr 14, 2026
Source: NVD