Search Results (26367 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57990 1 Microsoft 1 Edge Chromium 2026-07-27 7.4 High
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-48275 2 Adobe, Microsoft 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more 2026-07-27 8.6 High
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVE-2026-48334 2 Adobe, Microsoft 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more 2026-07-27 9.3 Critical
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVE-2026-48337 2 Adobe, Microsoft 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more 2026-07-27 7.8 High
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-48335 2 Adobe, Microsoft 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more 2026-07-27 7.8 High
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-48336 2 Adobe, Microsoft 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more 2026-07-27 7.8 High
Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-48561 1 Microsoft 4 365 Copilot, 365 Copilot Android, 365 Copilot Ios and 1 more 2026-07-26 9.6 Critical
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
CVE-2026-57211 3 Broadcom, Microsoft, Rabbitmq 3 Rabbitmq Server, Windows, Rabbitmq-server 2026-07-26 6.5 Medium
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6.
CVE-2026-15773 2 Google, Microsoft 2 Chrome, Windows 2026-07-26 9.6 Critical
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7755 5 Apple, Ibm, Langflow and 2 more 5 Macos, Langflow Oss, Langflow and 2 more 2026-07-26 8.8 High
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
CVE-2026-13448 5 Apple, Ibm, Langflow and 2 more 5 Macos, Langflow Oss, Langflow and 2 more 2026-07-26 8.1 High
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components including OpenDsStarAgent, CodeActAgentSmolagents, and CSVAgent.
CVE-2026-13783 4 Apple, Google, Linux and 1 more 4 Macos, Chrome, Linux Kernel and 1 more 2026-07-26 9.6 Critical
Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-15767 2 Google, Microsoft 2 Chrome, Windows 2026-07-25 8.8 High
Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
CVE-2026-62835 1 Microsoft 1 Azure Portal 2026-07-25 9.3 Critical
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-56191 1 Microsoft 1 Exchange Online 2026-07-24 10 Critical
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVE-2026-49159 1 Microsoft 1 Graph 2026-07-24 6.5 Medium
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
CVE-2026-58630 1 Microsoft 2 Azure App Service, Azure App Service For Linux 2026-07-24 10 Critical
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275 1 Microsoft 1 Azure Dns 2026-07-24 10 Critical
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62825 1 Microsoft 1 Azure Key Vault 2026-07-24 10 Critical
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-57106 1 Microsoft 2 Office Purview Data Governance, Purview Data Governance 2026-07-24 10 Critical
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.