Security Risk Severity

High Security Risks — Page 5

Published vulnerability pages grouped by high severity. Use this page to review risks that need similar prioritization.

872 published high risks

High severity

Showing 145–180 of 872 published risks.

Clear
highEPSS 0.003

CVE-2026-56650 windows 10 1607 vulnerability

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

CVE-2026-56650windowsmemory-corruption

Updated Jul 19, 2026

highEPSS 0.008

CVE-2026-57087 windows 10 1607 vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57087windowsmicrosoftmemory-corruption

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-57088 windows 10 1809 vulnerability

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

CVE-2026-57088windowsauthorization-bypass

Updated Jul 19, 2026

highEPSS 0.006

CVE-2026-57089 windows 10 1607 vulnerability

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.

CVE-2026-57089windowsmemory-corruption

Updated Jul 19, 2026

highEPSS 0.008

CVE-2026-57090 windows 10 1607 vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57090windowsmicrosoftmemory-corruption

Updated Jul 19, 2026

highEPSS 0.004

CVE-2026-57091 windows 10 1607 vulnerability

Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-57091windowsmemory-corruption

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-57093 windows 10 1607 vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-57093windowsmemory-corruption

Updated Jul 19, 2026

highEPSS 0.008

CVE-2026-57094 windows 10 1607 vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57094windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 19, 2026

highEPSS 0.004

CVE-2026-48252 experience manager vulnerability

Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48252authentication-bypass

Updated Jul 19, 2026

highEPSS 0.006

CVE-2026-48310 experience manager vulnerability

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48310path-traversalfile-write

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-52869 mcp python sdk vulnerability

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.

CVE-2026-52869pythonidor

Updated Jul 19, 2026

highEPSS 0.002

CVE-2026-52870 mcp python sdk vulnerability

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.

CVE-2026-52870pythonauthorization-bypass

Updated Jul 19, 2026

highEPSS 0.002

CVE-2026-59950 mcp python sdk vulnerability

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.

CVE-2026-59950python

Updated Jul 19, 2026

highEPSS 0.002

Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form-submission nonce is publicly available on any page containing the form shortcode, making this exploitable by fully unauthenticated attackers without any precondition beyond the form being published.

CVE-2026-15395wordpressxss

Updated Jul 19, 2026

high

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-product upload contexts. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable, which makes remote code execution possible. This filter is registered globally on every request regardless of whether the digital products feature is configured or in use, meaning the expanded MIME allowlist affects all WordPress upload contexts site-wide.

CVE-2026-13352wordpressremote-code-executionfile-uploadfile-write

Updated Jul 19, 2026

highEPSS 0.004

LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including questions belonging to paid courses the attacker is not enrolled in.

CVE-2026-13765wordpressauthorization-bypassinformation-disclosure

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-60114 sustainable irrigation platform vulnerability

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase 'opendoor', to write arbitrary JSON files outside the intended data directory.

CVE-2026-60114path-traversal

Updated Jul 17, 2026

high

CVE-2026-40378 windows 10 1607 vulnerability

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVE-2026-40378windows

Updated Jul 17, 2026

highEPSS 0.006

CVE-2026-40400 windows 10 1607 vulnerability

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-40400windowspath-traversal

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-42900 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-42900windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-42975 windows 10 1607 vulnerability

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-42975windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-42982 windows 10 1607 vulnerability

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-42982linuxwindows

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-44800 windows 11 23h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-44800windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.008

CVE-2026-45646 asp.net core odata vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVE-2026-45646dotnetdenial-of-service

Updated Jul 17, 2026

highEPSS 0.006

CVE-2026-47296 sql server 2016 vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

CVE-2026-47296sql-injection

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-47632 azure connected machine agent vulnerability

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-47632cryptography

Updated Jul 17, 2026

highEPSS 0.008

CVE-2026-48564 windows 10 1607 vulnerability

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-48564windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48571 windows 11 23h2 vulnerability

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-48571windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48572 windows 11 23h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-48572windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-49162 windows 11 24h2 vulnerability

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-49162windowsmicrosoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.006

CVE-2026-49164 windows 10 1607 vulnerability

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

CVE-2026-49164windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-49165 windows 10 1607 vulnerability

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVE-2026-49165windowsmicrosoft

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-49166 windows 11 24h2 vulnerability

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-49166windowsmicrosoftmemory-corruption

Updated Jul 17, 2026

highEPSS 0.005

CVE-2026-49169 windows server 2025 vulnerability

Use after free in DNS Server allows an authorized attacker to execute code over a network.

CVE-2026-49169windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.025

CVE-2026-49170 windows 10 1809 vulnerability

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVE-2026-49170windowsapi-securityauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-49171 windows 10 1607 vulnerability

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVE-2026-49171windowsmicrosoftmemory-corruption

Updated Jul 17, 2026