Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-59128] Windows Encrypting File System (EFS) Information Disclosure Vulnerability
Windows Encrypting File System (EFS) Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-63512] Microsoft SharePoint Server Tampering Vulnerability
Microsoft SharePoint Server Tampering Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-62837] Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-62829] Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability Affected products named by the advisory: Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-32791] Escalation of Privilege via Untrusted Search Path
Escalation of Privilege via Untrusted Search Path. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-426. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: pcm.
Medium [CVE-2025-31936] Privilege escalation via improper memory range handling in SMM
Privilege escalation via improper memory range handling in SMM. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: microcode_ctl.
Medium [CVE-2026-21399] Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow
Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120.
Medium [CVE-2026-20908] Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition
Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367.
Medium [CVE-2026-20786] Denial of service via out-of-bounds read
Denial of service via out-of-bounds read. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.
Medium [CVE-2026-20783] Denial of Service via improper conditions check
Denial of Service via improper conditions check. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-606.
Medium [CVE-2026-20731] Denial of Service via Improper Buffer Restrictions
Denial of Service via Improper Buffer Restrictions. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-131.
Medium [CVE-2026-73075] Out-of-bounds Access in Popup Opacity Handling
Out-of-bounds Access in Popup Opacity Handling. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-125.
Medium [CVE-2026-73074] Heap buffer overflow via integer wraparound in text property handling
Heap buffer overflow via integer wraparound in text property handling. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190.
Medium [CVE-2026-19078] Open redirect vulnerability enables phishing via unvalidated parameter.
Open redirect vulnerability enables phishing via unvalidated parameter. Red Hat rates this low (CVSS 4.3). Weakness: CWE-601. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-14180] Undertow:HTTP request smuggling via oversized chunk-size bit overlap
Undertow:HTTP request smuggling via oversized chunk-size bit overlap. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat Data Grid 8; Red Hat Enterprise Linux 10; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 5 more.
Medium [CVE-2026-73070] Stack Buffer Overflow via unbounded socket connections
Stack Buffer Overflow via unbounded socket connections. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:56636 with package vim-main-9.2.967-1.hum1.
Medium [CVE-2026-9214] Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Medium [CVE-2026-11738] Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. Affected products named by the advisory: R7000; RAXE500; RS700.
Medium [CVE-2026-11739] command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. Affected products named by the advisory: MR60; MR70; MR90; MS60; and 4 more. Affected products named by the advisory: MS70; MS90; RAX20; RAX200.
Medium [CVE-2026-11737] Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software functionality. Affected products named by the advisory: RAX20; RAX41; RAX41v2; RAX42; and 4 more. Affected products named by the advisory: RAX42v2; RAX43; RAX43v2; RAX45.