Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26990
Total
2034
Critical
8144
High
8390
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40376 | HIGH | 7.5 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | Jun 09, 2026 |
| CVE-2026-40371 | HIGH | 8.8 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. | Jun 09, 2026 |
| CVE-2026-3088 | UNKNOWN | — | Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests. | Jun 09, 2026 |
| CVE-2026-38615 | CRITICAL | 9.8 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. | Jun 09, 2026 |
| CVE-2026-35188 | UNKNOWN | — | Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's … | Jun 09, 2026 |
| CVE-2026-34692 | MEDIUM | 5.4 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue … | Jun 09, 2026 |
| CVE-2026-34335 | HIGH | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-34183 | HIGH | 7.5 | Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A … | Jun 09, 2026 |
| CVE-2026-34182 | UNKNOWN | — | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to … | Jun 09, 2026 |
| CVE-2026-34181 | UNKNOWN | — | Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing … | Jun 09, 2026 |
| CVE-2026-34180 | HIGH | 7.5 | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read … | Jun 09, 2026 |
| CVE-2026-33828 | HIGH | 7.8 | Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-33113 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Jun 09, 2026 |
| CVE-2026-32193 | HIGH | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-28301 | MEDIUM | 4.8 | A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website. | Jun 09, 2026 |
| CVE-2026-26142 | CRITICAL | 9.8 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. | Jun 09, 2026 |
| CVE-2026-24181 | HIGH | 7.3 | NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead … | Jun 09, 2026 |
| CVE-2026-24180 | HIGH | 7.3 | NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead … | Jun 09, 2026 |
| CVE-2026-22926 | HIGH | 7.8 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. | Jun 09, 2026 |
| CVE-2026-0420 | UNKNOWN | — | An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client app which can allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting … | Jun 09, 2026 |
| CVE-2026-0419 | UNKNOWN | — | Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to … | Jun 09, 2026 |
| CVE-2026-0418 | UNKNOWN | — | Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. | Jun 09, 2026 |
| CVE-2026-0417 | UNKNOWN | — | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. | Jun 09, 2026 |
| CVE-2026-0416 | UNKNOWN | — | Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface. | Jun 09, 2026 |
| CVE-2026-0415 | UNKNOWN | — | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and … | Jun 09, 2026 |