2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-50694 — Use: after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50694

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-50663 — Relative: path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50663

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 23VNDRelativeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
CRIT

CVE-2026-50522 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50522

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-50520 — Improper neutralization of special elements used in a command ('command injection') in Visual Studio

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50520

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 77TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-50342 — Windows: Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50342

Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:17Z
HIGH

CVE-2026-50338 — Azure: Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50338

Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 287VNDAzureTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:16Z
CRIT

CVE-2026-49798 — Use: after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49798

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. CVSSv3.1 9.3 (CRITICAL)

CWECWE 416TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-49795 — Use: after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49795

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-49184 — Heap: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49184

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-49178 — Heap: Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49178

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
CRIT

CVE-2026-49172 — Heap: Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49172

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-49169 — Use: after free in DNS Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49169

Use after free in DNS Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 416TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-49164 — Heap: Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49164

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-48564 — Heap: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48564

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
CRIT

CVE-2026-48561 — Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48561

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 77TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-47632 — Azure: Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47632

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network. CVSSv3.1 8.8 (HIGH)

CWECWE 295VNDAzureTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
CRIT

CVE-2026-42990 — Heap: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42990

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-42975 — Heap: Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42975

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. CVSSv3.1 8.0 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-42900 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows App Store

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42900

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-40400 — Relative: path traversal in Windows PowerShell allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40400

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 23VNDRelativeTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-14
2026-07-14 17:16Z
CRIT

CVE-2026-15701 — This manipulation of the argument Host causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15701

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-15429 — Tp-link Archer_vx1800v_firmware: A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15429

A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data.  An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges. CVSSv3.1 8.8 (HIGH) · EPSS 32th percentile

CWECWE 93VNDTp LinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-15428 — Tp-link Archer_vx1800v_firmware: An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15428

An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device. CVSSv3.1 8.8 (HIGH) · EPSS 56th percentile

CWECWE 78VNDTp LinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 17:16Z
HIGH

CVE-2026-15427 — Tp-link Archer_vx1800v_firmware: An OS command injection vulnerability exists in the TR-069 / CWMP management interface of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15427

An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. Successful exploitation may allow arbitrary command execution with root privi CVSSv3.1 8.1 (HIGH) · EPSS 40th percentile

CWECWE 78VNDTp LinkTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 16:17Z
CRIT

CVE-2026-60082 — DBI: versions before 1.651 for Perl do not enforce statement handle consistency with the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60082

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDDbiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score