21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 9901-9950 of 21553 CVEs Page 199 of 432
CVE-2026-21259
Analyzed
7.8
Microsoft Office Excel

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally

2026-02-11
CVE-2026-21257
8
GitHub Copilot and

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker...

2026-02-11
CVE-2026-21256
8.8
GitHub Copilot and

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacke...

2026-02-11
CVE-2026-21255
8.8
Microsoft Multiple Products

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally

2026-02-11
CVE-2026-21251
7.8
Microsoft Multiple Products

Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally

2026-02-11
CVE-2026-21250
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows HTTP

2026-02-11
CVE-2026-21246
Analyzed
7.8
Microsoft Graphics Component

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally

2026-02-11
CVE-2026-21245
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally

2026-02-11
CVE-2026-21240
7.8
Microsoft Multiple Products

Time-of-check time-of-use (toctou) race condition in Windows HTTP

2026-02-11
CVE-2026-21239
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally

2026-02-11
CVE-2026-21238
7.8
Microsoft Multiple Products

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2026-02-11
CVE-2026-21236
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2026-02-11
CVE-2026-21232
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows HTTP

2026-02-11
CVE-2026-21231
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate...

2026-02-11
CVE-2026-21229
8
Unknown Multiple Products

Improper input validation in Power BI allows an authorized attacker to execute code over a network

2026-02-11
CVE-2026-21228
Analyzed
8.1
Microsoft Local allows

Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network

2026-02-11
CVE-2026-21227
Analyzed
8.2
Microsoft Multiple Products

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileg...

2026-01-23
CVE-2026-2120
7.2
D-Link DIR

A vulnerability was identified in D-Link DIR-823X 250416

2026-02-08
CVE-2026-2118
7.2
UTT Multiple Products

A vulnerability was determined in UTT HiPER 810 1

2026-02-08
CVE-2026-2117
7.3
HP Multiple Products

A vulnerability was found in itsourcecode Society Management System 1

2026-02-08
CVE-2026-2116
7.3
HP Multiple Products

A vulnerability has been found in itsourcecode Society Management System 1

2026-02-08
CVE-2026-2115
7.3
HP Multiple Products

A flaw has been found in itsourcecode Society Management System 1

2026-02-08
CVE-2026-2114
Analyzed
7.3
HP Multiple Products

A vulnerability was detected in itsourcecode Society Management System 1

2026-02-08
CVE-2026-2113
7.3
HP of the

A security vulnerability has been detected in yuan1994 tpadmin up to 1

2026-02-08
CVE-2026-21079
Analyzed
7
Samsung Smart Switch

Missing encryption of sensitive data in Smart Switch prior to version 3

2026-08-10
CVE-2026-21074
Analyzed
7.2
Samsung Bixby

Incorrect default permissions in Bixby prior to version 4

2026-08-10
CVE-2026-21068
Analyzed
8.4
Samsung Samsung Mobile Devices

Stack-based buffer overflow in libril_sem

2026-08-10
CVE-2026-21064
Analyzed
7
Samsung Mobile Devices

Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability

2026-08-10
CVE-2026-21055
Analyzed
8.5
Samsung Bixby

Improper export of android application components in Bixby prior to version 4

2026-07-10
CVE-2026-21049
Analyzed
8.4
Samsung Mobile Devices

Out-of-bounds write in libpadm

2026-07-10
CVE-2026-21048
Analyzed
8.4
Samsung Mobile Devices

Out-of-bounds write in parsing DNG format in libimagecodec

2026-07-10
CVE-2026-21047
Analyzed
8.3
Samsung Mobile Devices

Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code

2026-07-30
CVE-2026-21046
Analyzed
8.4
Samsung Mobile Devices

Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbi...

2026-07-10
CVE-2026-21045
Analyzed
8.4
Samsung Mobile Devices

Out-of-bounds write in parsing TIFF format in libimagecodec

2026-07-10
CVE-2026-21042
Analyzed
8.4
Samsung Mobile Devices

Out-of-bounds write in libsavsac

2026-07-10
CVE-2026-2103
7.1
Infor SyteLine ERP

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and...

2026-02-07
CVE-2026-2101
Analyzed
8.7
Intel ENOVIAvpm

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Re...

2026-02-17
CVE-2026-2097
8.8
Unknown Multiple Products

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell ba...

2026-02-10
CVE-2026-20967
8.8
Operations Multiple Products

Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network

2026-03-11
CVE-2026-20963
KEV Analyzed
8.8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-01-14
CVE-2026-20960
Analyzed
8
Microsoft Multiple Products

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network

2026-01-17
CVE-2026-2096
Analyzed
9.8
Agentflow Agentflow

Agentflow by Flowring contains a missing authentication vulnerability, allowing unauthenticated remote attackers to read, modify, or delete database c...

2026-02-10
CVE-2026-20953
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2026-01-14
CVE-2026-20952
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2026-01-14
CVE-2026-2095
Analyzed
9.8
Agentflow Agentflow

Agentflow by Flowring suffers from an authentication bypass vulnerability, allowing unauthenticated attackers to obtain arbitrary user tokens and impe...

2026-02-10
CVE-2026-20947
Analyzed
8.8
Microsoft Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to e...

2026-01-14
CVE-2026-20944
Analyzed
8.4
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally

2026-01-14
CVE-2026-2094
8.8
Docpedia Multiple Products

Docpedia developed by Flowring has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, mo...

2026-02-10
CVE-2026-20931
8
Microsoft Multiple Products

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network

2026-01-14
CVE-2026-20930
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attack...

2026-04-15