Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
Showing 3,661 - 3,680 of 13,622 CVEs
CVE-2026-23822 MEDIUM - 5.3

A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption o...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-5146 MEDIUM - 4.3

Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions Server 2026.1.6.0 throu...

Published: May 12, 2026
Source: NVD
CVE-2026-44279 MEDIUM - 5.5

A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to improper access control via <insert attack vector here>

Vendor: Fortinet
Product: FortiTokenAndroid
Published: May 12, 2026
Source: NVD
CVE-2026-44204 MEDIUM - 6.5

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role) to execute arbitrary SQL and read data from any table in the database, including data belonging to o...

Vendor: Shelf-nu
Product: shelf.nu
Published: May 12, 2026
Source: NVD
CVE-2026-42891 MEDIUM - 6.5

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 12, 2026
Source: NVD
CVE-2026-42838 MEDIUM - 5.4

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 12, 2026
Source: NVD
CVE-2026-42830 MEDIUM - 6.5

Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: azure_monitor_agent
Published: May 12, 2026
Source: NVD
CVE-2026-42177 MEDIUM - 5.3

linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + "/*", i.e. "https://login.microsoftonline.com/*". Chrome...

Vendor: siemens
Product: linux-entra-sso
Published: May 12, 2026
Source: NVD
CVE-2026-41614 MEDIUM - 6.2

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

Vendor: microsoft
Product: 365_copilot
Published: May 12, 2026
Source: NVD
CVE-2026-41612 MEDIUM - 5.5

Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.

Vendor: microsoft
Product: live_preview
Published: May 12, 2026
Source: NVD
CVE-2026-41610 MEDIUM - 6.3

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: visual_studio_code
Published: May 12, 2026
Source: NVD
CVE-2026-41100 MEDIUM - 4.4

Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

Vendor: microsoft
Product: 365_copilot
Published: May 12, 2026
Source: NVD
CVE-2026-41097 MEDIUM - 6.7

Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1809
Published: May 12, 2026
Source: NVD
CVE-2026-40421 MEDIUM - 4.3

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: 365_apps
Published: May 12, 2026
Source: NVD
CVE-2026-40416 MEDIUM - 4.3

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 12, 2026
Source: NVD
CVE-2026-40380 MEDIUM - 6.2

Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD
CVE-2026-40374 MEDIUM - 6.5

Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.

Vendor: microsoft
Product: power_automate_for_desktop
Published: May 12, 2026
Source: NVD
CVE-2026-35440 MEDIUM - 5.5

Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Vendor: microsoft
Product: 365_apps
Published: May 12, 2026
Source: NVD
CVE-2026-35429 MEDIUM - 4.3

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: edge
Published: May 12, 2026
Source: NVD
CVE-2026-35423 MEDIUM - 5.4

Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD