Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 23VNDRelativeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
CRIT
CVE-2026-50522 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH
CVE-2026-50520 — Improper neutralization of special elements used in a command ('command injection') in Visual Studio
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
CVSSv3.1 8.4 (HIGH)
CWECWE 77TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH
CVE-2026-50342 — Windows: Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
CVSSv3.1 9.6 (CRITICAL)
CWECWE 77TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH
CVE-2026-47632 — Azure: Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
CVSSv3.1 8.8 (HIGH)
CWECWE 295VNDAzureTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
CRIT
CVE-2026-42990 — Heap: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
CVSSv3.1 8.0 (HIGH)
CWECWE 122VNDHeapTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH
CVE-2026-42900 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows App Store
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
CVSSv3.1 8.1 (HIGH)
CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH
CVE-2026-40400 — Relative: path traversal in Windows PowerShell allows an authorized attacker to execute code over
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH
CVE-2026-15429 — Tp-link Archer_vx1800v_firmware: A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1.
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data.
An
authenticated user with sufficient privileges may be able to modify account
settings and gain elevated administrative privileges.
CVSSv3.1 8.8 (HIGH) · EPSS 32th percentile
CWECWE 93VNDTp LinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH
CVE-2026-15428 — Tp-link Archer_vx1800v_firmware: An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input
An OS
command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of
the domain name parameter. An adjacent attacker who can access the relevant
HTTP interface can modify the parameter to inject shell metacharacters, resulting
in arbitrary code execution with root privileges.
Successful
exploitation may allow remote code execution and complete compromise of the
device.
CVSSv3.1 8.8 (HIGH) · EPSS 56th percentile
CWECWE 78VNDTp LinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH
CVE-2026-15427 — Tp-link Archer_vx1800v_firmware: An OS command injection vulnerability exists in the TR-069 / CWMP management interface of
An OS command
injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of
parameters, allowing crafted input to be executed as system-level commands.
Exploitation requires specific conditions such as TR-069 being enabled and ability
to influence ACS-delivered commands, compromise or control an ACS server.
Successful
exploitation may allow arbitrary command execution with root privi
CVSSv3.1 8.1 (HIGH) · EPSS 40th percentile
CWECWE 78VNDTp LinkTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 16:17Z
CRIT
CVE-2026-60082 — DBI: versions before 1.651 for Perl do not enforce statement handle consistency with the
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.
When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.
This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
CVSSv3.1 9.1 (CRITICAL)