Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52341
Total
4150
Critical
15505
High
15208
Medium
CVE ID Severity Score Description Published
CVE-2026-42900 HIGH 8.1 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. Jul 14, 2026
CVE-2026-41087 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-40422 MEDIUM 5.5 Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-40400 HIGH 8.0 Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. Jul 14, 2026
CVE-2026-40378 HIGH 7.5 Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. Jul 14, 2026
CVE-2026-36214 MEDIUM 5.4 osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip … Jul 14, 2026
CVE-2026-34349 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-34348 MEDIUM 6.5 Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. Jul 14, 2026
CVE-2026-34346 MEDIUM 5.5 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-34328 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-33842 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-15703 HIGH 7.3 A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation … Jul 14, 2026
CVE-2026-15702 MEDIUM 6.3 A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Such manipulation leads to improperly … Jul 14, 2026
CVE-2026-15701 CRITICAL 9.8 A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. … Jul 14, 2026
CVE-2026-15700 MEDIUM 4.7 A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album … Jul 14, 2026
CVE-2026-15429 UNKNOWN — A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be … Jul 14, 2026
CVE-2026-15428 UNKNOWN — An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can … Jul 14, 2026
CVE-2026-15427 UNKNOWN — An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of … Jul 14, 2026
CVE-2026-14646 UNKNOWN — Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user … Jul 14, 2026
CVE-2026-14645 UNKNOWN — Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding … Jul 14, 2026
CVE-2026-9636 UNKNOWN — A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from … Jul 14, 2026
CVE-2026-9292 UNKNOWN — A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. … Jul 14, 2026
CVE-2026-9128 UNKNOWN — A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths … Jul 14, 2026
CVE-2026-9127 UNKNOWN — A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated … Jul 14, 2026
CVE-2026-9108 UNKNOWN — A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does … Jul 14, 2026