Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,669
Quick preset (or use dates below)
Clear Filters
Showing 6,781 - 6,800 of 13,543 CVEs
CVE-2026-26162 HIGH - 7.8

Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26161 HIGH - 7.8

Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26160 HIGH - 7.8

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26159 HIGH - 7.8

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26156 HIGH - 7.8

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26154 HIGH - 7.5

Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26153 HIGH - 7.8

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26152 HIGH - 7.0

Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26151 HIGH - 7.1

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26143 HIGH - 7.8

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-25184 HIGH - 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-23666 HIGH - 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-23657 HIGH - 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-20930 HIGH - 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-34622 HIGH - 8.6

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploita...

Vendor: Adobe
Product: Acrobat Reader
Published: Apr 14, 2026
Source: NVD
CVE-2026-27291 HIGH - 7.8

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-27284 HIGH - 7.8

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current ...

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-27283 HIGH - 7.8

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-27238 HIGH - 7.8

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-39815 HIGH - 8.8

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests

Vendor: Fortinet
Product: FortiDDoS-F
Published: Apr 14, 2026
Source: NVD