Total CVEs

150,798

Critical Severity

4,991

High Severity

17,614

Last 7 Days

2,037
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 28,021 - 28,040 of 47,203 CVEs
CVE-2026-26160 HIGH - 7.8

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26159 HIGH - 7.8

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26156 HIGH - 7.8

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26155 MEDIUM - 6.5

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

Published: Apr 14, 2026
Source: NVD
CVE-2026-26154 HIGH - 7.5

Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26153 HIGH - 7.8

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26152 HIGH - 7.0

Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26151 HIGH - 7.1

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26149 CRITICAL - 9.0

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to bypass a security feature over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26143 HIGH - 7.8

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-25184 HIGH - 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-24907 MEDIUM - 5.4

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail preview feature. When viewing logged mail messages, HTML content was rendered in an iframe without proper sandboxing, all...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-24906 MEDIUM - 5.4

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup Classes fields (used for paragraph styles, inline styles, table styles, etc.) did not sanitize input...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-23670 MEDIUM - 5.7

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-23666 HIGH - 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-23657 HIGH - 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-23653 MEDIUM - 5.7

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-21331 MEDIUM - 6.1

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browse...

Vendor: Adobe
Product: Adobe Connect
Published: Apr 14, 2026
Source: NVD
CVE-2026-20945 MEDIUM - 4.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-20930 HIGH - 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD