Security Risk Severity

High Security Risks — Page 9

Published vulnerability pages grouped by high severity. Use this page to review risks that need similar prioritization.

872 published high risks

High severity

Showing 289–324 of 872 published risks.

Clear
highEPSS 0.003

CVE-2026-58632 windows 10 1607 vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-58632windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-58637 windows 10 1607 vulnerability

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58637windowsmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-47305 visual studio 2022 vulnerability

Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

CVE-2026-47305microsoft

Updated Jul 17, 2026

highEPSS 0.009

CVE-2026-48345 animate vulnerability

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48345remote-code-execution

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48346 animate vulnerability

Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48346supply-chainremote-code-execution

Updated Jul 17, 2026

highEPSS 0.007

CVE-2026-48347 animate vulnerability

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48347remote-code-execution

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48348 animate vulnerability

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48348remote-code-executionauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48349 animate vulnerability

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48349remote-code-executionauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48350 animate vulnerability

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48350remote-code-executionpath-traversal

Updated Jul 17, 2026

high

CVE-2026-24238 tensorrt vulnerability

NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution.

CVE-2026-24238memory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-24268 tensorrt vulnerability

NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution.

CVE-2026-24268memory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-24272 tensorrt vulnerability

NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution.

CVE-2026-24272memory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-47971 media encoder vulnerability

Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47971remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-47976 media encoder vulnerability

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47976remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-48269 premiere pro vulnerability

Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48269remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48270 premiere pro vulnerability

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48270remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48272 creative cloud desktop application vulnerability

Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48272supply-chainremote-code-execution

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48274 after effects vulnerability

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48274remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48311 bridge vulnerability

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48311remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48339 bridge vulnerability

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48339remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48340 bridge vulnerability

Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48340remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48341 bridge vulnerability

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48341remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48342 bridge vulnerability

Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48342remote-code-executioninput-validation

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48343 bridge vulnerability

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48343remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48344 creative cloud desktop application vulnerability

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48344remote-code-executionrace-condition

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48366 media encoder vulnerability

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48366remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48367 after effects vulnerability

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48367remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48369 premiere pro vulnerability

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48369remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48370 media encoder vulnerability

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48370remote-code-executionmemory-corruption

Updated Jul 17, 2026

high

CVE-2025-56361 matter vulnerability

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a MoveToLevel command is executed and followed by a conflicting write to the OperationMode attribute (in the Pump Configuration and Control cluster), an invariant check (`minLevel < currentLevel`) fails and causes the device to abort. This leads to a denial of service condition. The issue is confirmed in SDK versions 1.3 and 1.4 (commit ab3d5ae), and is triggered remotely without authentication.

CVE-2025-56361denial-of-service

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48275 illustrator vulnerability

Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48275supply-chainremote-code-execution

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48287 c2pa vulnerability

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

CVE-2026-48287supply-chainremote-code-execution

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48290 c2pa vulnerability

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

CVE-2026-48290remote-code-executionssrf

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-48295 c2pa vulnerability

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction.

CVE-2026-48295information-disclosure

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48335 illustrator vulnerability

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48335remote-code-executionmemory-corruption

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48336 illustrator vulnerability

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-48336remote-code-executionmemory-corruption

Updated Jul 17, 2026