OCTOBER 8, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

37,169 records on file
Page 50 of 1,239
CVE ID Score Description
Exploit 1h ago
9.9

Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

Exploit 1h ago
10

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

1h ago
9.3

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

1h ago
9.3

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

1h ago
9.8

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Exploit 1h ago
9.8

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploit 1h ago
9.8

In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploit 1h ago
9.8

In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for exploitation.

1h ago
9.9

Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.

1h ago
9.6

Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

1h ago
9.8

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

1h ago
9.8

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

1h ago
9

Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.

1h ago
9.8

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

1h ago
9.8

Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.