U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-42990 - Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
    Published: July 14, 2026; 1:16:48 PM -0400

  • CVE-2026-44800 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 1:16:48 PM -0400

  • CVE-2026-44806 - Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
    Published: July 14, 2026; 1:16:48 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-45496 - Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
    Published: July 14, 2026; 1:16:49 PM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-45646 - Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
    Published: July 14, 2026; 1:16:49 PM -0400

  • CVE-2026-47282 - Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
    Published: July 14, 2026; 1:16:49 PM -0400

  • CVE-2026-47296 - Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 1:16:49 PM -0400

  • CVE-2026-56690 - Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnera... read CVE-2026-56690
    Published: July 10, 2026; 8:17:23 AM -0400

  • CVE-2026-56689 - Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnera... read CVE-2026-56689
    Published: July 10, 2026; 8:17:23 AM -0400

  • CVE-2026-56688 - Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this ... read CVE-2026-56688
    Published: July 10, 2026; 8:17:23 AM -0400

  • CVE-2026-47632 - Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
    Published: July 14, 2026; 1:16:49 PM -0400

  • CVE-2026-54468 - Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.
    Published: July 10, 2026; 8:17:23 AM -0400

  • CVE-2026-48561 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
    Published: July 14, 2026; 1:16:49 PM -0400

  • CVE-2026-44342 - New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requ... read CVE-2026-44342
    Published: July 09, 2026; 7:17:05 PM -0400

  • CVE-2026-33655 - New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabl... read CVE-2026-33655
    Published: July 09, 2026; 7:17:04 PM -0400

  • CVE-2026-48564 - Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
    Published: July 14, 2026; 1:16:49 PM -0400

  • CVE-2026-55471 - HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() ... read CVE-2026-55471
    Published: July 08, 2026; 6:17:15 PM -0400

    V3.1: 9.1 CRITICAL

  • CVE-2026-55470 - HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/util... read CVE-2026-55470
    Published: July 08, 2026; 6:17:15 PM -0400

  • CVE-2026-33444 - CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.
    Published: July 15, 2026; 5:16:36 PM -0400

    V3.1: 3.7 LOW

  • CVE-2026-33445 - CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.
    Published: July 15, 2026; 5:16:36 PM -0400

    V3.1: 5.9 MEDIUM

Created September 20, 2022 , Updated August 27, 2024