Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49358
Total
3967
Critical
14633
High
14397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19195 | HIGH | 7.8 | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel … | Aug 07, 2026 |
| CVE-2026-19193 | HIGH | 7.8 | A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a … | Aug 07, 2026 |
| CVE-2026-19192 | HIGH | 7.8 | A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access … | Aug 07, 2026 |
| CVE-2026-19191 | HIGH | 7.8 | A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such … | Aug 07, 2026 |
| CVE-2026-14365 | CRITICAL | 9.8 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This … | Aug 07, 2026 |
| CVE-2026-14364 | CRITICAL | 9.8 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up … | Aug 07, 2026 |
| CVE-2026-12801 | MEDIUM | 6.4 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in … | Aug 07, 2026 |
| CVE-2026-11907 | MEDIUM | 6.5 | The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not … | Aug 07, 2026 |
| CVE-2026-19190 | HIGH | 7.8 | A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This … | Aug 07, 2026 |
| CVE-2026-49746 | HIGH | 7.1 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases … | Aug 07, 2026 |
| CVE-2026-45204 | MEDIUM | 5.5 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference in an … | Aug 07, 2026 |
| CVE-2026-45198 | HIGH | 7.8 | Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from … | Aug 07, 2026 |
| CVE-2026-19189 | HIGH | 7.8 | A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the … | Aug 07, 2026 |
| CVE-2026-70332 | CRITICAL | 9.6 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Aug 07, 2026 |
| CVE-2026-68823 | CRITICAL | 9.1 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | Aug 07, 2026 |
| CVE-2026-65668 | HIGH | 8.8 | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-65667 | CRITICAL | 10.0 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-63508 | CRITICAL | 10.0 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-62918 | HIGH | 7.5 | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. | Aug 07, 2026 |
| CVE-2026-62896 | CRITICAL | 9.6 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-62873 | CRITICAL | 9.8 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-62836 | HIGH | 8.7 | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-62830 | CRITICAL | 9.9 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-59118 | CRITICAL | 9.3 | Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-59115 | CRITICAL | 9.9 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | Aug 07, 2026 |