Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
47,488 matching · page 603/950Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-49184(opens NVD record) | High | 8.4 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | Jul 14, 2026 |
| CVE-2026-49183(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-49181(opens NVD record) | High | 7.5 | Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. | Jul 14, 2026 |
| CVE-2026-49180(opens NVD record) | Medium | 5.5 | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-49178(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | Jul 14, 2026 |
| CVE-2026-49176(opens NVD record) | High | 7.8 | Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-49175(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-49174(opens NVD record) | Medium | 6.1 | Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | Jul 14, 2026 |
| CVE-2026-49173(opens NVD record) | High | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-49172(opens NVD record) | Critical | 9.8 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | Jul 14, 2026 |
| CVE-2026-49171(opens NVD record) | High | 7.5 | Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-49170(opens NVD record) | High | 7.8 | Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-49169(opens NVD record) | High | 8.0 | Use after free in DNS Server allows an authorized attacker to execute code over a network. | Jul 14, 2026 |
| CVE-2026-49168(opens NVD record) | Medium | 6.8 | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. | Jul 14, 2026 |
| CVE-2026-49167(opens NVD record) | Medium | 4.7 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-49166(opens NVD record) | High | 7.8 | Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-49165(opens NVD record) | High | 7.1 | Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-49164(opens NVD record) | High | 8.1 | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | Jul 14, 2026 |
| CVE-2026-49162(opens NVD record) | High | 7.0 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-48581(opens NVD record) | High | 7.8 | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-48572(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-48571(opens NVD record) | High | 7.0 | Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-48564(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | Jul 14, 2026 |
| CVE-2026-48561(opens NVD record) | Critical | 9.6 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | Jul 14, 2026 |
| CVE-2026-47632(opens NVD record) | High | 8.8 | Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. | Jul 14, 2026 |
| CVE-2026-47296(opens NVD record) | High | 7.5 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 |
| CVE-2026-47282(opens NVD record) | Medium | 6.5 | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | Jul 14, 2026 |
| CVE-2026-45646(opens NVD record) | High | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | Jul 14, 2026 |
| CVE-2026-45496(opens NVD record) | Medium | 5.5 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | Jul 14, 2026 |
| CVE-2026-44806(opens NVD record) | Medium | 5.3 | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | Jul 14, 2026 |
| CVE-2026-44800(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-42990(opens NVD record) | Critical | 9.8 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | Jul 14, 2026 |
| CVE-2026-42982(opens NVD record) | High | 7.8 | Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 |
| CVE-2026-42975(opens NVD record) | High | 8.0 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | Jul 14, 2026 |
| CVE-2026-42900(opens NVD record) | High | 8.1 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. | Jul 14, 2026 |
| CVE-2026-41087(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-40422(opens NVD record) | Medium | 5.5 | Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-40400(opens NVD record) | High | 8.0 | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | Jul 14, 2026 |
| CVE-2026-40378(opens NVD record) | High | 7.5 | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | Jul 14, 2026 |
| CVE-2026-36214(opens NVD record) | Medium | 6.4 | osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or Admin sessions. | Jul 14, 2026 |
| CVE-2026-34349(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-34348(opens NVD record) | Medium | 6.5 | Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | Jul 14, 2026 |
| CVE-2026-34346(opens NVD record) | Medium | 5.5 | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-34328(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-33842(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-15703(opens NVD record) | High | 7.3 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | Jul 14, 2026 |
| CVE-2026-15702(opens NVD record) | Medium | 6.3 | A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Such manipulation leads to improperly controlled modification of object prototype attributes. The attack may be performed from remote. Upgrading to version 2.3.1 is able to mitigate this issue. The name of the patch is e46af9879b7627934ea4d6d6e46e65cea53abb3d. The affected component should be upgraded. | Jul 14, 2026 |
| CVE-2026-15701(opens NVD record) | Critical | 9.8 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. | Jul 14, 2026 |
| CVE-2026-15700(opens NVD record) | Medium | 4.7 | A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | Jul 14, 2026 |
| CVE-2026-15429(opens NVD record) | High | 8.8 | A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges. | Jul 14, 2026 |