Search
3,911 CVEs · High severity
CVEs (3,911, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 3,911 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16584 | HIGH | Patched | 7.0 | 2026-07-23 | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execu… |
| CVE-2026-61120 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficu… | |
| CVE-2026-61061 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2… | |
| CVE-2026-60833 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability all… | |
| CVE-2026-60705 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Diff… | |
| CVE-2026-60494 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Diffi… | |
| CVE-2026-46999 | HIGH | 7.0 | 2026-07-21 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected ar… | |
| CVE-2026-58598 | HIGH | Patched | 7.0 | 2026-07-16 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. |
| CVE-2026-53410 | HIGH | 7.0 | 2026-07-16 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local… | |
| CVE-2026-61389 | HIGH | 7.0 | 2026-07-16 | An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially result… | |
| CVE-2026-60063 | HIGH | 7.0 | 2026-07-16 | An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially result… | |
| CVE-2026-9046 | HIGH | 7.0 | 2026-07-16 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, tha… | |
| CVE-2026-54684 | HIGH | Patched | 7.0 | 2026-07-14 | jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlled archive entry contents outside the intended XAPK p… |
| CVE-2026-50526 | HIGH | Patched | 7.0 | 2026-07-14 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. |
| CVE-2026-58629 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
| CVE-2026-58637 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-58619 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-58544 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
| CVE-2026-57093 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
| CVE-2026-56183 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
| CVE-2026-56187 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
| CVE-2026-56173 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
| CVE-2026-50672 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |
| CVE-2026-50674 | HIGH | Patched | 7.0 | 2026-07-14 | Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2026-50669 | HIGH | Patched | 7.0 | 2026-07-14 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges… |