🛡️ CVE Intelligence Center
Common Vulnerabilities & Exposures — Security Intelligence Database
| CVE ID | Severity | CVSS | Description | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-3909 | Critical | 9.8 |
Google Skia — CVE-2026-3909
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker…
|
— | Mar 13, 2026 |
| CVE-2026-3910 | Critical | 9.8 |
Google Chromium V8 — CVE-2026-3910
Google Chromium V8 contains an improper restriction of operations within the bounds o…
|
— | Mar 13, 2026 |
| CVE-2025-68613 | Critical | 9.8 |
n8n n8n — CVE-2025-68613
n8n contains an improper control of dynamically managed code resources vulnerability in its wor…
|
— | Mar 11, 2026 |
| CVE-2026-28495 | Critical | 9.6 |
GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allo…
|
⚡ Exploit ✅ Patch | Mar 10, 2026 |
| CVE-2026-20967 | High | 8.8 |
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a…
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-26106 | High | 8.8 |
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-3854 | High | 8.8 |
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an …
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-25188 | High | 8.8 |
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an ad…
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-26118 | High | 8.8 |
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a networ…
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-25177 | High | 8.8 |
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized att…
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-23669 | High | 8.8 |
Use after free in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-23654 | High | 8.8 |
Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to…
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-24283 | High | 8.8 |
Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-26116 | High | 8.8 |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized …
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-26114 | High | 8.8 |
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne…
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-28513 | High | 8.5 |
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, th…
|
⚡ Exploit ✅ Patch | Mar 10, 2026 |
| CVE-2026-26113 | High | 8.4 |
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-26109 | High | 8.4 |
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-26110 | High | 8.4 |
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe…
|
✅ Patch | Mar 10, 2026 |
| CVE-2026-26148 | High | 8.1 |
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate…
|
✅ Patch | Mar 10, 2026 |