CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2026-54129

    Last Modified: 14 Jul 2026

    Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50695

    Last Modified: 14 Jul 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-54983

    Last Modified: 14 Jul 2026

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-50663

    Last Modified: 15 Jul 2026

    Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-45496

    Last Modified: 16 Jul 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-47282

    Last Modified: 15 Jul 2026

    Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50506

    Last Modified: 14 Jul 2026

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-49784

    Last Modified: 16 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-49177

    Last Modified: 12 Aug 2026

    Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    6.1
    Medium

    CVE-2026-49174

    Last Modified: 14 Jul 2026

    Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-49173

    Last Modified: 15 Jul 2026

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-49172

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-49175

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-49176

    Last Modified: 15 Jul 2026

    Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-49171

    Last Modified: 15 Jul 2026

    Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-49170

    Last Modified: 15 Jul 2026

    Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8
    High

    CVE-2026-49169

    Last Modified: 15 Jul 2026

    Use after free in DNS Server allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    6.8
    Medium

    CVE-2026-49168

    Last Modified: 14 Jul 2026

    Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

    Published: 14 Jul 2026
    4.7
    Medium

    CVE-2026-49167

    Last Modified: 15 Jul 2026

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-49166

    Last Modified: 14 Jul 2026

    Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.1
    High

    CVE-2026-49165

    Last Modified: 29 Jul 2026

    Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-49164

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-49162

    Last Modified: 15 Jul 2026

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-48571

    Last Modified: 14 Jul 2026

    Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-48572

    Last Modified: 15 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-42990

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    8
    High

    CVE-2026-42975

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-42900

    Last Modified: 16 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-34346

    Last Modified: 15 Jul 2026

    Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-34349

    Last Modified: 14 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-47296

    Last Modified: 3 Aug 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-42982

    Last Modified: 15 Jul 2026

    Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    9.6
    Critical

    CVE-2026-48561

    Last Modified: 26 Jul 2026

    Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    5.1
    Medium

    CVE-2026-15429

    Last Modified: 27 Jul 2026

    A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data.  An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges.

    Published: 14 Jul 2026
    8.5
    High

    CVE-2026-15428

    Last Modified: 27 Jul 2026

    An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device.

    Published: 14 Jul 2026
    8.6
    High

    CVE-2026-15427

    Last Modified: 27 Jul 2026

    An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-15703

    Last Modified: 15 Jul 2026

    A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

    Published: 14 Jul 2026
    9.6
    Critical

    CVE-2026-59891

    Last Modified: 21 Jul 2026

    sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because this is a substring match rather than an exact host match, credentials configured for one registry can be selected for and transmitted to a different registry whose hostname has a substring relationship with a configured auth key. This issue is fixed in version 0.7.1.

    Published: 14 Jul 2026
    4.9
    Medium

    CVE-2026-14646

    Last Modified: 16 Jul 2026

    Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials.

    Published: 14 Jul 2026
    2.1
    Low

    CVE-2026-15702

    Last Modified: 15 Jul 2026

    A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Such manipulation leads to improperly controlled modification of object prototype attributes. The attack may be performed from remote. Upgrading to version 2.3.1 is able to mitigate this issue. The name of the patch is e46af9879b7627934ea4d6d6e46e65cea53abb3d. The affected component should be upgraded.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-59888

    Last Modified: 25 Jul 2026

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-59884

    Last Modified: 16 Jul 2026

    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-59885

    Last Modified: 17 Jul 2026

    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-59886

    Last Modified: 15 Jul 2026

    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.

    Published: 14 Jul 2026
    5.1
    Medium

    CVE-2026-14645

    Last Modified: 16 Jul 2026

    Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.

    Published: 14 Jul 2026
    8.9
    High

    CVE-2026-15701

    Last Modified: 14 Jul 2026

    A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 14 Jul 2026
    8.3
    High

    CVE-2026-54058

    Last Modified: 14 Jul 2026

    Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.

    Published: 14 Jul 2026
    8.2
    High

    CVE-2026-59197

    Last Modified: 21 Jul 2026

    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

    Published: 14 Jul 2026
    4.7
    Medium

    CVE-2026-54432

    Last Modified: 1 Aug 2026

    Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.

    Published: 14 Jul 2026
    7.2
    High

    CVE-2026-54433

    Last Modified: 31 Jul 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

    Published: 14 Jul 2026