Export limit exceeded: 377282 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 26367 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (26367 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-57990 | 1 Microsoft | 1 Edge Chromium | 2026-07-27 | 7.4 High |
| Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-48275 | 2 Adobe, Microsoft | 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more | 2026-07-27 | 8.6 High |
| Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | ||||
| CVE-2026-48334 | 2 Adobe, Microsoft | 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more | 2026-07-27 | 9.3 Critical |
| Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | ||||
| CVE-2026-48337 | 2 Adobe, Microsoft | 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more | 2026-07-27 | 7.8 High |
| Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-48335 | 2 Adobe, Microsoft | 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more | 2026-07-27 | 7.8 High |
| Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-48336 | 2 Adobe, Microsoft | 4 Illustrator, Illustrator Desktop 2025, Illustrator Desktop 2026 and 1 more | 2026-07-27 | 7.8 High |
| Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-48561 | 1 Microsoft | 4 365 Copilot, 365 Copilot Android, 365 Copilot Ios and 1 more | 2026-07-26 | 9.6 Critical |
| Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-57211 | 3 Broadcom, Microsoft, Rabbitmq | 3 Rabbitmq Server, Windows, Rabbitmq-server | 2026-07-26 | 6.5 Medium |
| RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6. | ||||
| CVE-2026-15773 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-07-26 | 9.6 Critical |
| Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-7755 | 5 Apple, Ibm, Langflow and 2 more | 5 Macos, Langflow Oss, Langflow and 2 more | 2026-07-26 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. | ||||
| CVE-2026-13448 | 5 Apple, Ibm, Langflow and 2 more | 5 Macos, Langflow Oss, Langflow and 2 more | 2026-07-26 | 8.1 High |
| IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components including OpenDsStarAgent, CodeActAgentSmolagents, and CSVAgent. | ||||
| CVE-2026-13783 | 4 Apple, Google, Linux and 1 more | 4 Macos, Chrome, Linux Kernel and 1 more | 2026-07-26 | 9.6 Critical |
| Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-15767 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-07-25 | 8.8 High |
| Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) | ||||
| CVE-2026-62835 | 1 Microsoft | 1 Azure Portal | 2026-07-25 | 9.3 Critical |
| Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-56191 | 1 Microsoft | 1 Exchange Online | 2026-07-24 | 10 Critical |
| Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | ||||
| CVE-2026-49159 | 1 Microsoft | 1 Graph | 2026-07-24 | 6.5 Medium |
| Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-58630 | 1 Microsoft | 2 Azure App Service, Azure App Service For Linux | 2026-07-24 | 10 Critical |
| Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-58275 | 1 Microsoft | 1 Azure Dns | 2026-07-24 | 10 Critical |
| Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62825 | 1 Microsoft | 1 Azure Key Vault | 2026-07-24 | 10 Critical |
| Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-57106 | 1 Microsoft | 2 Office Purview Data Governance, Purview Data Governance | 2026-07-24 | 10 Critical |
| Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | ||||