Tagged “nvd”
CVEs tagged nvd, newest first.
30179 CVEsRSS
CVE-2026-79721High· 8.6Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
CVE-2026-77109High· 8.6Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue d…
CVE-2026-76202High· 8.2Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue …
CVE-2026-66306Medium· 6.5Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-28656High· 7.3In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack
In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …
CVE-2026-9216Low· 3.5An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality o…
CVE-2026-9215Medium· 6.7A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations …
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations …
CVE-2026-86673High· 7.3PoCA vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf
A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connec…
CVE-2026-86672Medium· 5.3PoCA vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf
A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to info…
CVE-2026-86670Low· 3.7PoCA flaw has been found in aircheng-org iWebShop-5 up to 5.15
A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to passwo…
CVE-2026-86669High· 7.3PoCA vulnerability was detected in aircheng-org iWebShop-5 up to 5.15
A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possib…
CVE-2026-86074High· 7.1n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-co…
CVE-2026-85880High· 7.8CISA KEV0dayPoCHeap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-85877High· 8.8Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
CVE-2026-85875Medium· 5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-85360High· 7.0Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-84003High· 7.4Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-84001High· 7.5Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
CVE-2026-84000High· 7.8Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
CVE-2026-83999High· 7.0Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83998High· 8.8Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-83997High· 8.1Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-83996High· 8.8Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2026-83995High· 7.8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-83992High· 8.8Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-83991Medium· 5.5PoCMissing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
CVE-2026-83990High· 7.8Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-83989High· 7.5Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
CVE-2026-83988High· 7.8Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83987High· 7.8Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.