Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,443
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,701 - 1,720 of 33,646 CVEs
CVE-2026-49472 MEDIUM - 5.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable function, PREFIX(prologTok)(), in libs/xmlrpc-c/lib/expat/x...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49161 HIGH - 7.8

Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: pc_manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-49160 HIGH - 7.5

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48583 HIGH - 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48578 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48576 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48575 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48574 HIGH - 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48573 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48570 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48569 HIGH - 7.1

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: visual_studio_code
Published: Jun 09, 2026
Source: NVD
CVE-2026-48568 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48566 MEDIUM - 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_11_24h2
Published: Jun 09, 2026
Source: NVD
CVE-2026-48565 HIGH - 7.8

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_narrator_braille
Published: Jun 09, 2026
Source: NVD
CVE-2026-48563 HIGH - 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_10_1809
Published: Jun 09, 2026
Source: NVD
CVE-2026-48562 MEDIUM - 4.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: sharepoint_server
Published: Jun 09, 2026
Source: NVD
CVE-2026-48560 MEDIUM - 5.4

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: sharepoint_server
Published: Jun 09, 2026
Source: NVD
CVE-2026-48304 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's ...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-48301 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's ...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-48300 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's ...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Jun 09, 2026
Source: NVD