Total
10319 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-5281 | 4 Apple, Google, Linux and 1 more | 4 Macos, Chrome, Linux Kernel and 1 more | 2026-07-24 | N/A | 8.8 HIGH |
| Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-35560 | 4 Amazon, Apple, Linux and 1 more | 4 Athena Odbc, Macos, Linux Kernel and 1 more | 2026-07-24 | N/A | 7.4 HIGH |
| Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena. To remediate this issue, users should upgrade to version 2.1.0.0. | |||||
| CVE-2026-39844 | 2 Microsoft, Zauberzeug | 2 Windows, Nicegui | 2026-07-24 | N/A | 5.9 MEDIUM |
| NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern demonstrated in NiceGUI's bundled examples) are vulnerable to arbitrary file write on Windows. This vulnerability is fixed in 3.10.0. | |||||
| CVE-2026-35561 | 4 Amazon, Apple, Linux and 1 more | 4 Athena Odbc, Macos, Linux Kernel and 1 more | 2026-07-24 | N/A | 7.4 HIGH |
| Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users should upgrade to version 2.1.0.0. | |||||
| CVE-2026-35558 | 4 Amazon, Apple, Linux and 1 more | 4 Athena Odbc, Macos, Linux Kernel and 1 more | 2026-07-24 | N/A | 7.8 HIGH |
| Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user-initiated authentication. To remediate this issue, users should upgrade to version 2.1.0.0. | |||||
| CVE-2026-35559 | 4 Amazon, Apple, Linux and 1 more | 4 Athena Odbc, Macos, Linux Kernel and 1 more | 2026-07-24 | N/A | 6.5 MEDIUM |
| Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations. To remediate this issue, users should upgrade to version 2.1.0.0. | |||||
| CVE-2025-7024 | 2 Airbus, Microsoft | 2 Tetra Connectivity Server, Windows | 2026-07-24 | N/A | 7.3 HIGH |
| Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the vulnerable directory. This issue affects TETRA connectivity Server: 7.0. Vulnerability fix is available and delivered to impacted customers. | |||||
| CVE-2026-35562 | 4 Amazon, Apple, Linux and 1 more | 4 Athena Odbc, Macos, Linux Kernel and 1 more | 2026-07-24 | N/A | 7.5 HIGH |
| Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate this issue, users should upgrade to version 2.1.0.0. | |||||
| CVE-2026-2123 | 2 Microfocus, Microsoft | 2 Operations Agent, Windows | 2026-07-24 | N/A | 7.8 HIGH |
| A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability | |||||
| CVE-2026-22561 | 2 Anthropic, Microsoft | 2 Claude, Windows | 2026-07-24 | N/A | 7.8 HIGH |
| Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from its own directory after UAC elevation, enabling arbitrary code execution if a malicious DLL is planted alongside the installer. | |||||
| CVE-2026-50650 | 1 Microsoft | 15 .net, .net Framework, Windows and 12 more | 2026-07-24 | N/A | 7.8 HIGH |
| Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |||||
| CVE-2026-50649 | 1 Microsoft | 16 .net, .net Framework, Visual Studio 2026 and 13 more | 2026-07-24 | N/A | 7.8 HIGH |
| Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-50646 | 1 Microsoft | 17 .net, .net Framework, Visual Studio 2022 and 14 more | 2026-07-24 | N/A | 7.8 HIGH |
| Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-47302 | 3 Apple, Linux, Microsoft | 19 Macos, Linux Kernel, .net and 16 more | 2026-07-24 | N/A | 7.5 HIGH |
| Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-47304 | 3 Apple, Linux, Microsoft | 22 Macos, Linux Kernel, .net and 19 more | 2026-07-24 | N/A | 8.1 HIGH |
| Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | |||||
| CVE-2026-50525 | 3 Apple, Linux, Microsoft | 19 Macos, Linux Kernel, .net and 16 more | 2026-07-24 | N/A | 7.5 HIGH |
| Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-50648 | 3 Apple, Linux, Microsoft | 19 Macos, Linux Kernel, .net and 16 more | 2026-07-24 | N/A | 7.5 HIGH |
| Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-50527 | 3 Apple, Linux, Microsoft | 19 Macos, Linux Kernel, .net and 16 more | 2026-07-24 | N/A | 7.5 HIGH |
| Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-50659 | 3 Apple, Linux, Microsoft | 19 Macos, Linux Kernel, .net and 16 more | 2026-07-24 | N/A | 6.5 MEDIUM |
| Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-5897 | 4 Apple, Google, Linux and 1 more | 4 Macos, Chrome, Linux Kernel and 1 more | 2026-07-24 | N/A | 4.3 MEDIUM |
| Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |||||
