Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-47647

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Dynamics 365
Provider severity
CRITICAL
Conflicts
0

CVE-2026-47646

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Dynamics 365 Customer Voice
Provider severity
CRITICAL
Conflicts
0

CVE-2026-47645

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot
Provider severity
HIGH
Conflicts
0

CVE-2026-47644

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Copilot Chat (Microsoft Edge)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47643

External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Stack Edge
Provider severity
CRITICAL
Conflicts
0

CVE-2026-47642

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Office Online Server, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-47641

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-47640

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4764

A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously crafted playbook import. This vulnerability was patched on 15 March 2026, and no customer action is needed.

PUBLISHED
Vendor
Google Cloud
Product
Dialogflow CX
Provider severity
CRITICAL
Conflicts
0

CVE-2026-47639

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition
Provider severity
MEDIUM
Conflicts
1

CVE-2026-47638

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Provider severity
MEDIUM
Conflicts
1

CVE-2026-47637

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-47636

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-47635

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
0

CVE-2026-47634

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Provider severity
HIGH
Conflicts
1

CVE-2026-47633

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Cost Management
Provider severity
HIGH
Conflicts
0

CVE-2026-47632

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

PUBLISHED
Vendor
Microsoft
Product
Azure Monitor Agent Metrics Extension
Provider severity
HIGH
Conflicts
0

CVE-2026-47631

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 14
Provider severity
HIGH
Conflicts
1

CVE-2026-4761

When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable Please refer to security bulletin BS-036, available on the Panor

PUBLISHED
Vendor
CODRA
Product
Panorama Suite
Provider severity
LOW
Conflicts
0

CVE-2026-4760

From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or high

PUBLISHED
Vendor
CODRA
Product
Panorama Suite
Provider severity
HIGH
Conflicts
0

CVE-2026-4758

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PUBLISHED
Vendor
wpjobportal
Product
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
Provider severity
HIGH
Conflicts
0

CVE-2026-4756

Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

PUBLISHED
Vendor
MolotovCherry
Product
Android-ImageMagick7
Provider severity
HIGH
Conflicts
0

CVE-2026-4755

CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

PUBLISHED
Vendor
MolotovCherry
Product
Android-ImageMagick7
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4754

CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

PUBLISHED
Vendor
MolotovCherry
Product
Android-ImageMagick7
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4753

Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.

PUBLISHED
Vendor
slajerek
Product
RetroDebugger
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4752

Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329.

PUBLISHED
Vendor
No-Chicken
Product
Echo-Mate
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4751

NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0.

PUBLISHED
Vendor
tmate-io
Product
tmate
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4750

Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.

PUBLISHED
Vendor
fabiangreffrath
Product
woof
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4749

NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0.

PUBLISHED
Vendor
albfan
Product
miraclecast
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47483

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

PUBLISHED
Vendor
NVIDIA, NVIDIA
Product
DCGM Exporter, DCGM
Provider severity
HIGH
Conflicts
1

CVE-2026-47482

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-47481

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47480

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-4748

A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently dropped as duplicates. Only the first of such rules is actually loaded into pf. Ranges expressed using the address[/mask-bits] syntax were not affected. Some keywords representing actions taken on a packet-matching rule, such as 'log', 'return tll', or 'dnpipe', may suffer from the same issue. It is unlikely that

PUBLISHED
Vendor
FreeBSD
Product
FreeBSD
Provider severity
HIGH
Conflicts
1

CVE-2026-47479

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-47478

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-47477

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-47476

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-47475

NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT-LLM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47473

NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT-LLM
Provider severity
HIGH
Conflicts
0

CVE-2026-47472

NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT-LLM
Provider severity
HIGH
Conflicts
0

CVE-2026-47471

NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT-LLM
Provider severity
HIGH
Conflicts
0

CVE-2026-47470

NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT-LLM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4747

Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to authenticate itself first. As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote code execution in the kernel is possible by an authenticated user that is able to send pac

PUBLISHED
Vendor
FreeBSD
Product
FreeBSD
Provider severity
HIGH
Conflicts
0

CVE-2026-4746

Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules). This vulnerability is associated with program files inflate.C. This issue affects proton: before 1.6.16.

PUBLISHED
Vendor
timeplus-io
Product
proton
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4745

Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This vulnerability is associated with program files ldo.C. This issue affects perf-ninja.

PUBLISHED
Vendor
dendibakh
Product
perf-ninja
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4744

Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules). This vulnerability is associated with program files regcomp.C‎. This issue affects Notepad3: before 6.25.714.1.

PUBLISHED
Vendor
rizonesoft
Product
Notepad3
Provider severity
CRITICAL
Conflicts
0

CVE-2026-47430

## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser can fire any pending Cordova callback in the host app by posting a message whose `id` field is a guessable or enumerated callback identifier. An attack abusing this weakness must be tailored to the specific plugins and callb

PUBLISHED
Vendor
Apache Software Foundation
Product
Cordova Plugin InAppBrowser
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4743

NULL Pointer Dereference vulnerability in taurusxin ncmdump (‎src/utils‎ modules). This vulnerability is associated with program files cJSON.Cpp‎. This issue affects ncmdump: before 1.4.0.

PUBLISHED
Vendor
taurusxin
Product
ncmdump
Provider severity
MEDIUM
Conflicts
0

CVE-2026-47429

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.

PUBLISHED
Vendor
vitest-dev
Product
vitest
Provider severity
CRITICAL
Conflicts
0