Security Risk Severity
High Security Risks — Page 5
Published vulnerability pages grouped by high severity. Use this page to review risks that need similar prioritization.
872 published high risks
High severity
Showing 145–180 of 872 published risks.
CVE-2026-56650 windows 10 1607 vulnerability
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
Updated Jul 19, 2026
CVE-2026-57087 windows 10 1607 vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-57088 windows 10 1809 vulnerability
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
Updated Jul 19, 2026
CVE-2026-57089 windows 10 1607 vulnerability
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-57090 windows 10 1607 vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-57091 windows 10 1607 vulnerability
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
Updated Jul 19, 2026
CVE-2026-57093 windows 10 1607 vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Updated Jul 19, 2026
CVE-2026-57094 windows 10 1607 vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Updated Jul 19, 2026
CVE-2026-48252 experience manager vulnerability
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
Updated Jul 19, 2026
CVE-2026-48310 experience manager vulnerability
Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Updated Jul 19, 2026
CVE-2026-52869 mcp python sdk vulnerability
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.
Updated Jul 19, 2026
CVE-2026-52870 mcp python sdk vulnerability
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.
Updated Jul 19, 2026
CVE-2026-59950 mcp python sdk vulnerability
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.
Updated Jul 19, 2026
Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form-submission nonce is publicly available on any page containing the form shortcode, making this exploitable by fully unauthenticated attackers without any precondition beyond the form being published.
Updated Jul 19, 2026
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-product upload contexts. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable, which makes remote code execution possible. This filter is registered globally on every request regardless of whether the digital products feature is configured or in use, meaning the expanded MIME allowlist affects all WordPress upload contexts site-wide.
Updated Jul 19, 2026
LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including questions belonging to paid courses the attacker is not enrolled in.
Updated Jul 19, 2026
CVE-2026-60114 sustainable irrigation platform vulnerability
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase 'opendoor', to write arbitrary JSON files outside the intended data directory.
Updated Jul 17, 2026
CVE-2026-40378 windows 10 1607 vulnerability
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
Updated Jul 17, 2026
CVE-2026-40400 windows 10 1607 vulnerability
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Updated Jul 17, 2026
CVE-2026-42900 windows 10 1607 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
Updated Jul 17, 2026
CVE-2026-42975 windows 10 1607 vulnerability
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
Updated Jul 17, 2026
CVE-2026-42982 windows 10 1607 vulnerability
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-44800 windows 11 23h2 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-45646 asp.net core odata vulnerability
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Updated Jul 17, 2026
CVE-2026-47296 sql server 2016 vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-47632 azure connected machine agent vulnerability
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Updated Jul 17, 2026
CVE-2026-48564 windows 10 1607 vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
Updated Jul 17, 2026
CVE-2026-48571 windows 11 23h2 vulnerability
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-48572 windows 11 23h2 vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-49162 windows 11 24h2 vulnerability
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-49164 windows 10 1607 vulnerability
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
Updated Jul 17, 2026
CVE-2026-49165 windows 10 1607 vulnerability
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-49166 windows 11 24h2 vulnerability
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-49169 windows server 2025 vulnerability
Use after free in DNS Server allows an authorized attacker to execute code over a network.
Updated Jul 17, 2026
CVE-2026-49170 windows 10 1809 vulnerability
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-49171 windows 10 1607 vulnerability
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
