Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,297
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,681 - 3,700 of 13,241 CVEs
CVE-2026-35422 MEDIUM - 6.5

Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD
CVE-2026-35419 MEDIUM - 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_11_24h2
Published: May 12, 2026
Source: NVD
CVE-2026-34663 MEDIUM - 5.5

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim ...

Vendor: Adobe
Product: Illustrator
Published: May 12, 2026
Source: NVD
CVE-2026-34662 MEDIUM - 5.5

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue re...

Vendor: Adobe
Product: Illustrator
Published: May 12, 2026
Source: NVD
CVE-2026-34350 MEDIUM - 6.5

Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.

Vendor: microsoft
Product: windows_server_2025
Published: May 12, 2026
Source: NVD
CVE-2026-34339 MEDIUM - 5.5

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD
CVE-2026-32209 MEDIUM - 4.4

Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD
CVE-2026-32185 MEDIUM - 5.5

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

Vendor: microsoft
Product: teams
Published: May 12, 2026
Source: NVD
CVE-2026-32175 MEDIUM - 4.3

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the dest...

Vendor: nuget
Product: Microsoft.NetCore.App.Runtime.win-arm
Published: May 12, 2026
Source: NVD
CVE-2026-32170 MEDIUM - 6.7

Double free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD
CVE-2026-31245 MEDIUM - 5.3

The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this by sending una...

Vendor: mem0
Product: mem0
Published: May 12, 2026
Source: NVD
CVE-2026-31244 MEDIUM - 6.5

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrary memory records without verifying their identity or permissions. A remote attacker can exploit this ...

Vendor: mem0
Product: mem0
Published: May 12, 2026
Source: NVD
CVE-2026-31243 MEDIUM - 6.5

The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, leading to the execution of a CREATE TAB...

Vendor: mem0
Product: mem0
Published: May 12, 2026
Source: NVD
CVE-2026-31241 MEDIUM - 6.5

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g., user_id, run_id, agent_id) in the request query parameters...

Vendor: mem0
Product: mem0
Published: May 12, 2026
Source: NVD
CVE-2026-25690 MEDIUM - 4.3

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow ...

Vendor: Fortinet
Product: FortiDeceptor
Published: May 12, 2026
Source: NVD
CVE-2026-25088 MEDIUM - 5.4

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions may allow an authenticated attacker ...

Vendor: Fortinet
Product: FortiNDR
Published: May 12, 2026
Source: NVD
CVE-2026-21530 MEDIUM - 6.7

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD
CVE-2025-67604 MEDIUM - 5.3

A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, ...

Vendor: Fortinet
Product: FortiAnalyzer, FortiManager
Published: May 12, 2026
Source: NVD
CVE-2025-53870 MEDIUM - 6.7

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-W2 7.4.0 through 7.4.4, Fo...

Vendor: Fortinet
Product: FortiAP, FortiAP-W2
Published: May 12, 2026
Source: NVD
CVE-2025-53680 MEDIUM - 6.7

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-U 7...

Vendor: Fortinet
Product: FortiAP, FortiAP-W2, FortiAP-U
Published: May 12, 2026
Source: NVD