U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-56164 - Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
    Published: July 14, 2026; 1:17:09 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-56155 - Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 1:17:09 PM -0400

  • CVE-2026-47967 - Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
    Published: July 14, 2026; 2:17:18 PM -0400

  • CVE-2026-47968 - Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
    Published: July 14, 2026; 2:17:18 PM -0400

  • CVE-2026-15681 - AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute l... read CVE-2026-15681
    Published: July 13, 2026; 6:16:45 PM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-15682 - AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execut... read CVE-2026-15682
    Published: July 13, 2026; 6:16:45 PM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-15685 - Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to explo... read CVE-2026-15685
    Published: July 13, 2026; 6:16:46 PM -0400

  • CVE-2026-62199 - OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust caller or configured input path can supply crafted e... read CVE-2026-62199
    Published: July 13, 2026; 6:16:51 PM -0400

  • CVE-2026-62200 - OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or... read CVE-2026-62200
    Published: July 13, 2026; 6:16:51 PM -0400

  • CVE-2024-7708 - For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.
    Published: July 14, 2026; 5:16:39 AM -0400

  • CVE-2026-12606 - Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.
    Published: July 14, 2026; 5:16:39 AM -0400

    V3.1: 5.3 MEDIUM

  • CVE-2026-13699 - In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. When a request contains a valid signal_id but omits data_point, the ... read CVE-2026-13699
    Published: July 14, 2026; 5:16:40 AM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-15075 - In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin ... read CVE-2026-15075
    Published: July 14, 2026; 5:16:40 AM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-15076 - In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating server's do... read CVE-2026-15076
    Published: July 14, 2026; 5:16:40 AM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-44787 - Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership ... read CVE-2026-44787
    Published: July 09, 2026; 6:17:04 PM -0400

    V3.1: 7.1 HIGH

  • CVE-2026-45780 - Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entit... read CVE-2026-45780
    Published: July 09, 2026; 6:17:04 PM -0400

    V3.1: 4.3 MEDIUM

  • CVE-2026-45788 - Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was ena... read CVE-2026-45788
    Published: July 09, 2026; 6:17:04 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-46413 - Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions ... read CVE-2026-46413
    Published: July 09, 2026; 6:17:05 PM -0400

  • CVE-2026-49256 - Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could lea... read CVE-2026-49256
    Published: July 09, 2026; 6:17:05 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-53961 - Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn value... read CVE-2026-53961
    Published: July 09, 2026; 6:17:05 PM -0400

Created September 20, 2022 , Updated August 27, 2024