21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 7701-7750 of 21637 CVEs Page 155 of 433
CVE-2026-32225
8.8
Microsoft Multiple Products

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network

2026-04-15
CVE-2026-32221
8.4
Microsoft Graphics Component

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally

2026-04-15
CVE-2026-32213
Analyzed
10
Microsoft AI Foundry

Improper authorization in Azure AI Foundry allows unauthenticated network attackers to escalate privileges, potentially compromising AI models and sen...

2026-04-03
CVE-2026-32211
Analyzed
9.1
Microsoft MCP Server

A missing authentication vulnerability in Azure MCP Server allows unauthenticated attackers to disclose sensitive information over a network.

2026-04-03
CVE-2026-32210
Analyzed
9.3
Microsoft Dynamics

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a netwo...

2026-04-24
CVE-2026-32208
Analyzed
8.8
Microsoft Edge

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker...

2026-06-20
CVE-2026-32207
8.8
Microsoft Machine Learning

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perf...

2026-05-08
CVE-2026-32202
KEV
9.5
Microsoft Windows

Microsoft Windows Protection Mechanism Failure Vulnerability - Active in CISA KEV catalog.

2026-04-29
CVE-2026-32201
KEV
9.5
Microsoft SharePoint Server

Microsoft SharePoint Server Improper Input Validation Vulnerability - Active in CISA KEV catalog.

2026-04-15
CVE-2026-3220
Analyzed
8.8
WordPress plugin before

The Autoptimize WordPress plugin before 3

2026-05-19
CVE-2026-32194
Analyzed
9.8
Microsoft Bing Images

A command injection vulnerability in Microsoft Bing Images allows an unauthorized attacker to execute arbitrary code via network-based requests.

2026-03-20
CVE-2026-32193
Analyzed
8.8
Microsoft Azure Kubernetes Service

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to...

2026-06-10
CVE-2026-32191
Analyzed
9.8
Microsoft Bing Images

An OS command injection vulnerability in Microsoft Bing Images allows an unauthenticated attacker to execute arbitrary code over a network.

2026-03-20
CVE-2026-32190
8.4
Microsoft Office allows

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2026-04-15
CVE-2026-32173
Analyzed
8.6
Microsoft SRE Agent

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network

2026-04-03
CVE-2026-32172
8
Microsoft Power Apps

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network

2026-04-24
CVE-2026-32171
8.8
Microsoft Logic Apps

Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network

2026-04-15
CVE-2026-32169
Analyzed
10
Microsoft Cloud Shell

A server-side request forgery (SSRF) vulnerability in Azure Cloud Shell allows an unauthenticated attacker to elevate privileges over a network.

2026-03-20
CVE-2026-32162
8.4
Microsoft Multiple Products

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32160
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacke...

2026-04-15
CVE-2026-32159
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacke...

2026-04-15
CVE-2026-32158
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacke...

2026-04-15
CVE-2026-32157
8.8
Unknown Multiple Products

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2026-04-15
CVE-2026-32155
7.8
Window Multiple Products

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32154
7.8
Window Multiple Products

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32153
7.8
Microsoft Windows Speech

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32152
7.8
Window Multiple Products

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32141
7.5
Unknown Multiple Products

flatted is a circular JSON parser

2026-03-14
CVE-2026-32140
8.8
Arch Multiple Products

Dataease is an open source data visualization analysis tool

2026-03-14
CVE-2026-32138
8.2
Unknown Multiple Products

NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester

2026-03-13
CVE-2026-32137
8.8
Unknown Multiple Products

Dataease is an open source data visualization analysis tool

2026-03-14
CVE-2026-32136
Analyzed
9.8
AdGuard AdGuard Home

AdGuard Home is vulnerable to an unauthenticated authentication bypass via HTTP/2 cleartext (h2c) upgrades, allowing attackers to process requests as...

2026-03-12
CVE-2026-32127
8.8
Unknown Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application

2026-03-12
CVE-2026-32110
8.3
Unknown Multiple Products

SiYuan is a personal knowledge management system

2026-03-12
CVE-2026-32107
8.8
RDP Multiple Products

xrdp is an open source RDP server

2026-04-18
CVE-2026-32096
Analyzed
9.3
AWS SES

Plunk contains an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in its SNS webhook handler, allowing attackers to make arbitrary ou...

2026-03-12
CVE-2026-32091
8.4
Microsoft Brokering File

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized...

2026-04-15
CVE-2026-32090
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered Api allows an authorized attack...

2026-04-15
CVE-2026-32089
7.8
Microsoft Multiple Products

Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32078
7.8
Microsoft Multiple Products

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32077
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32076
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32074
7.8
Microsoft Multiple Products

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32069
7.8
Microsoft Multiple Products

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally

2026-04-15
CVE-2026-32064
7.7
Unknown Multiple Products

OpenClaw versions prior to 2026

2026-03-21
CVE-2026-32060
8.8
Unknown Multiple Products

OpenClaw versions prior to 2026

2026-03-12
CVE-2026-32059
8.8
OpenClaw Multiple Products

OpenClaw version 2026

2026-03-12
CVE-2026-32056
7.5
Unknown Multiple Products

OpenClaw versions prior to 2026

2026-03-22
CVE-2026-32055
7.6
Unknown Multiple Products

OpenClaw versions prior to 2026

2026-03-21
CVE-2026-32051
8.8
Unknown Multiple Products

OpenClaw versions prior to 2026

2026-03-21