2026-07-14
2026-07-14 18:17Z
CRIT

CVE-2026-15747 — Mojolicious: versions from 4.59 before 9.48 for Perl expose a stable representation of the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15747

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. CVSSv3.1 9.1 (CRITICAL)

CWECWE 352CWECWE 204VNDMojoliciousTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 17:17Z
CRIT

CVE-2026-59891 — JavaScript: sigstore-js provides JavaScript libraries for interacting with Sigstore services.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59891

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because this is a substring match rather than an exact host match, credentials configured for one registry can be selected for and transmitted to a different registry whose hostname has a substring relationshi CVSSv3.1 9.6 (CRITICAL)

CWECWE 522TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-59197 — Pillow: Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59197

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0. CVSSv3.1 8.2 (HIGH)

CWECWE 787CWECWE 190VNDPillowTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-58647 — Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58647

Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 79TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-14
2026-07-14 17:17Z
CRIT

CVE-2026-58644 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58644

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-58608 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58608

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-58595 — Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58595

Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 1021TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-57969 — Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57969

Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-56169 — Windows: Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56169

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 287TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-56155 — Microsoft Windows_10_1607: Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56155in the wild

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. CVSSv3.1 7.8 (HIGH)

CWECWE 1220VNDMicrosoftTYPVulnerabilitySTAitw exploited
7.8
CVSS v3.1
89
Edit Score
2026-07-14
2026-07-14 17:17Z
CRIT

CVE-2026-55008 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55008

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 79TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-55005 — Heap: Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55005

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-55002 — Microsoft Sql_server_2016: External control of file name or path in SQL Server allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55002

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 73VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-54999 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54999

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network. CVSSv3.1 8.8 (HIGH)

CWECWE 362VNDConcurrentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-54995 — Use: after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54995

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-54992 — Heap: Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54992

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 17:17Z
CRIT

CVE-2026-54990 — Heap: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54990

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-54982 — Integer: underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54982

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. CVSSv3.1 8.8 (HIGH)

CWECWE 191TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-54122 — Heap: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54122

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-54118 — Deserialization: of untrusted data in SQL Server allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54118

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-54117 — Deserialization: of untrusted data in SQL Server allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54117

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-54107 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54107

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 362VNDConcurrentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
CRIT

CVE-2026-54058 — Python Pillow: Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54058

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0. CVSSv3.1 9.1 (CRITICAL) · EPSS 31th percentile

CWECWE 125VNDPillowTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-50694 — Use: after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50694

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-50663 — Relative: path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50663

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 23VNDRelativeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score