CVE-2026-50416 Win32k Information Disclosure Vulnerability
Published on: 2026-08-03 07:00:00
Link: View Details
Acknowledgement Updated
CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability
Published on: 2026-08-03 07:00:00
Link: View Details
Acknowledgement Updated
CVE-2026-50493 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-08-03 07:00:00
Link: View Details
Acknowledgement Updated
CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability
Published on: 2026-07-30 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-30 07:00:00
Link: View Details
Acknowledgement Updated
CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Published on: 2026-07-30 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability
Published on: 2026-07-30 07:00:00
Link: View Details
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability
Published on: 2026-07-30 07:00:00
Link: View Details
Informational Change. CVE ID stays the same.
CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability
Published on: 2026-07-30 07:00:00
Link: View Details
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-28 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability
Published on: 2026-07-28 07:00:00
Link: View Details
Corrected Build Number in the Security Updates table. This is an informational change only.
CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability
Published on: 2026-07-28 07:00:00
Link: View Details
Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only.
Chromium: CVE-2026-13032 Use after free in WebGL
Published on: 2026-07-28 15:03:48
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Chromium: CVE-2026-13028 Use after free in WebGL
Published on: 2026-07-28 15:03:44
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Chromium: CVE-2026-13030 Uninitialized Use in GPU
Published on: 2026-07-28 15:03:47
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Chromium: CVE-2026-13037 Use after free in WebView
Published on: 2026-07-28 15:03:49
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability
Published on: 2026-07-27 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published on: 2026-07-27 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability
Published on: 2026-07-27 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability
Published on: 2026-07-27 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
Published on: 2026-07-27 01:43:51
Link: View Details
Information published.
CVE-2024-14040 net: nexthop: Increase weight to u16
Published on: 2026-07-27 01:04:21
Link: View Details
Information published.
CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
Published on: 2026-07-27 01:04:27
Link: View Details
Information published.
CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting
Published on: 2026-07-27 01:44:11
Link: View Details
Information published.
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
Published on: 2026-07-27 01:44:00
Link: View Details
Information published.
Chromium: CVE-2026-16804 Use after free in Input
Published on: 2026-07-25 00:29:49
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Chromium: CVE-2026-16805 Use after free in Blink
Published on: 2026-07-25 00:29:51
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Chromium: CVE-2026-16806 Use after free in WebMCP
Published on: 2026-07-25 00:29:52
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Chromium: CVE-2026-16807 Out of bounds write in Codecs
Published on: 2026-07-25 00:29:54
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
CVE-2026-62835 Azure Portal Information Disclosure Vulnerability
Published on: 2026-07-24 07:00:00
Link: View Details
Corrected the CVE description and title. This is an informational change only.
CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability
Published on: 2026-07-24 07:00:00
Link: View Details
Corrected the CVE description and title. This is an informational change only.
CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare
Published on: 2026-07-24 01:02:21
Link: View Details
Information published.
CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare
Published on: 2026-07-24 01:02:30
Link: View Details
Information published.
CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK
Published on: 2026-07-24 01:02:36
Link: View Details
Information published.
CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62835 Online Services Information Disclosure Vulnerability
Published on: 2026-07-23 07:00:00
Link: View Details
Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network.
CVE-2026-47729 Squid: Memory disclosure in FTP gateway
Published on: 2026-07-23 01:01:56
Link: View Details
Information published.
CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: 2026-07-23 01:02:25
Link: View Details
Information published.
CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service
Published on: 2026-07-23 01:02:31
Link: View Details
Information published.
CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: 2026-07-23 01:02:44
Link: View Details
Information published.
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils
Published on: 2026-07-23 01:02:58
Link: View Details
Information published.
CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow
Published on: 2026-07-23 01:03:05
Link: View Details
Information published.
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
Published on: 2026-07-23 01:03:11
Link: View Details
Information published.
CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Published on: 2026-07-23 01:03:24
Link: View Details
Information published.
CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'
Published on: 2026-07-23 01:03:36
Link: View Details
Information published.
CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
Published on: 2026-07-23 01:03:55
Link: View Details
Information published.
CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
Published on: 2026-07-23 01:04:01
Link: View Details
Information published.
CVE-2026-40691 Packet of death for DNSCrypt over TCP
Published on: 2026-07-23 01:04:07
Link: View Details
Information published.
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
Published on: 2026-07-23 01:04:13
Link: View Details
Information published.
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
Published on: 2026-07-23 01:04:32
Link: View Details
Information published.
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Published on: 2026-07-23 01:04:39
Link: View Details
Information published.
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
Published on: 2026-07-23 01:04:51
Link: View Details
Information published.
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound
Published on: 2026-07-23 01:04:57
Link: View Details
Information published.
CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
Published on: 2026-07-23 01:05:03
Link: View Details
Information published.
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
Published on: 2026-07-23 01:05:09
Link: View Details
Information published.
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread
Published on: 2026-07-23 01:05:16
Link: View Details
Information published.
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
Published on: 2026-07-23 01:05:28
Link: View Details
Information published.
CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files
Published on: 2026-07-23 01:05:35
Link: View Details
Information published.
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
Published on: 2026-07-23 01:05:41
Link: View Details
Information published.
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
Published on: 2026-07-23 01:05:48
Link: View Details
Information published.
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
Published on: 2026-07-23 01:05:54
Link: View Details
Information published.
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root
Published on: 2026-07-23 01:06:00
Link: View Details
Information published.
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
Published on: 2026-07-23 01:06:06
Link: View Details
Information published.
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
Published on: 2026-07-23 01:06:15
Link: View Details
Information published.
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.
Published on: 2026-07-23 01:06:22
Link: View Details
Information published.
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.
Published on: 2026-07-23 01:06:35
Link: View Details
Information published.
CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling
Published on: 2026-07-23 01:02:03
Link: View Details
Information published.
CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects
Published on: 2026-07-23 01:44:10
Link: View Details
Information published.
CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Published on: 2026-07-23 01:02:11
Link: View Details
Information published.
CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Published on: 2026-07-23 01:02:18
Link: View Details
Information published.
CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published on: 2026-07-23 01:02:38
Link: View Details
Information published.
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
Published on: 2026-07-23 01:02:50
Link: View Details
Information published.
CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts
Published on: 2026-07-23 01:03:17
Link: View Details
Information published.
CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
Published on: 2026-07-23 01:03:30
Link: View Details
Information published.
CVE-2026-52863 Memory corruption could lead to crash and denial of service
Published on: 2026-07-23 01:03:42
Link: View Details
Information published.
CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
Published on: 2026-07-23 01:03:48
Link: View Details
Information published.
CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
Published on: 2026-07-23 01:04:19
Link: View Details
Information published.
CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use
Published on: 2026-07-23 01:04:26
Link: View Details
Information published.
CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments
Published on: 2026-07-23 01:04:45
Link: View Details
Information published.
CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
Published on: 2026-07-23 01:05:22
Link: View Details
Information published.
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.
Published on: 2026-07-23 01:06:29
Link: View Details
Information published.
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header
Published on: 2026-07-22 01:39:39
Link: View Details
Information published.
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
Published on: 2026-07-22 01:39:47
Link: View Details
Information published.
CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
Published on: 2026-07-22 01:41:21
Link: View Details
Information published.
CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values
Published on: 2026-07-22 01:41:29
Link: View Details
Information published.
CVE-2026-42533 NGINX Map directive and Regex matching vulnerability
Published on: 2026-07-22 01:41:48
Link: View Details
Information published.
CVE-2026-56434 NGINX ngx_http_ssi_module vulnerability
Published on: 2026-07-22 01:41:55
Link: View Details
Information published.
CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
Published on: 2026-07-22 01:01:19
Link: View Details
Information published.
CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
Published on: 2026-07-22 01:01:38
Link: View Details
Information published.
CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize
Published on: 2026-07-22 01:02:03
Link: View Details
Information published.
CVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
Published on: 2026-07-22 01:02:10
Link: View Details
Information published.
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Published on: 2026-07-22 01:39:55
Link: View Details
Information published.
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
Published on: 2026-07-22 01:40:02
Link: View Details
Information published.
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
Published on: 2026-07-22 01:40:10
Link: View Details
Information published.
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
Published on: 2026-07-22 01:40:25
Link: View Details
Information published.
CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows
Published on: 2026-07-22 01:40:56
Link: View Details
Information published.
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
Published on: 2026-07-22 01:41:04
Link: View Details
Information published.
CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
Published on: 2026-07-22 01:41:14
Link: View Details
Information published.
CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
Published on: 2026-07-22 01:01:26
Link: View Details
Information published.
CVE-2026-64187 xfs: fail recovery on a committed log item with no regions
Published on: 2026-07-22 01:01:32
Link: View Details
Information published.
CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path
Published on: 2026-07-22 01:01:44
Link: View Details
Information published.
CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change
Published on: 2026-07-22 01:01:51
Link: View Details
Information published.
CVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
Published on: 2026-07-22 01:01:57
Link: View Details
Information published.
CVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid length
Published on: 2026-07-22 01:02:16
Link: View Details
Information published.
CVE-2026-39879 SQL injection in syslog-ng SQL destionation driver
Published on: 2026-07-22 01:02:23
Link: View Details
Information published.
CVE-2026-50407 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: 2026-07-22 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-50377 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-22 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-50466 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: 2026-07-22 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: 2026-07-22 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-50458 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: 2026-07-22 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-58640 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-21 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: 2026-07-21 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
Published on: 2026-07-21 01:40:55
Link: View Details
Information published.
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Published on: 2026-07-21 01:41:17
Link: View Details
Information published.
CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index
Published on: 2026-07-21 01:41:32
Link: View Details
Information published.
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record
Published on: 2026-07-21 01:41:42
Link: View Details
Information published.
CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Published on: 2026-07-21 01:41:54
Link: View Details
Information published.
CVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
Published on: 2026-07-21 01:42:10
Link: View Details
Information published.
CVE-2026-63796 ocfs2: reject oversized group bitmap descriptors
Published on: 2026-07-21 01:44:23
Link: View Details
Information published.
CVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
Published on: 2026-07-21 01:39:19
Link: View Details
Information published.
CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsg
Published on: 2026-07-21 01:39:26
Link: View Details
Information published.
CVE-2026-64133 ALSA: asihpi: Fix potential OOB array access at reading cache
Published on: 2026-07-21 01:01:42
Link: View Details
Information published.
CVE-2026-64097 drm/amd/display: Validate GPIO pin LUT table size before iterating
Published on: 2026-07-21 01:02:50
Link: View Details
Information published.
CVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0'
Published on: 2026-07-21 01:03:02
Link: View Details
Information published.
CVE-2026-64077 netfilter: ebtables: move to two-stage removal scheme
Published on: 2026-07-21 01:03:09
Link: View Details
Information published.
CVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pages
Published on: 2026-07-21 01:03:54
Link: View Details
Information published.
CVE-2026-63882 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
Published on: 2026-07-21 01:04:12
Link: View Details
Information published.
CVE-2026-64017 blk-mq: pop cached request if it is usable
Published on: 2026-07-21 01:04:46
Link: View Details
Information published.
CVE-2026-64146 erofs: fix metabuf leak in inode xattr initialization
Published on: 2026-07-21 01:05:10
Link: View Details
Information published.
CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
Published on: 2026-07-21 01:41:02
Link: View Details
Information published.
CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
Published on: 2026-07-21 01:41:10
Link: View Details
Information published.
CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
Published on: 2026-07-21 01:41:24
Link: View Details
Information published.
CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Published on: 2026-07-21 01:42:02
Link: View Details
Information published.
CVE-2026-63824 KEYS: fix overflow in keyctl_pkey_params_get_2()
Published on: 2026-07-21 01:44:03
Link: View Details
Information published.
CVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout()
Published on: 2026-07-21 01:44:14
Link: View Details
Information published.
CVE-2026-63831 mac802154: llsec: add skb_cow_data() before in-place crypto
Published on: 2026-07-21 01:44:33
Link: View Details
Information published.
CVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loop
Published on: 2026-07-21 01:39:47
Link: View Details
Information published.
CVE-2026-64038 hwmon: (lm90) Stop work before releasing hwmon device
Published on: 2026-07-21 01:01:22
Link: View Details
Information published.
CVE-2026-64036 cgroup/rstat: validate cpu before css_rstat_cpu() access
Published on: 2026-07-21 01:01:29
Link: View Details
Information published.
CVE-2026-64079 netfilter: x_tables: allocate hook ops while under mutex
Published on: 2026-07-21 01:01:35
Link: View Details
Information published.
CVE-2026-64001 ALSA: pcm: oss: Fix setup list UAF on proc write error
Published on: 2026-07-21 01:01:48
Link: View Details
Information published.
CVE-2026-64160 netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
Published on: 2026-07-21 01:01:54
Link: View Details
Information published.
CVE-2026-64138 ksmbd: validate SID in parent security descriptor during ACL inheritance
Published on: 2026-07-21 01:02:00
Link: View Details
Information published.
CVE-2026-63959 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
Published on: 2026-07-21 01:02:06
Link: View Details
Information published.
CVE-2026-64070 powerpc/hv-gpci: fix preempt count leak in sysfs show paths
Published on: 2026-07-21 01:02:13
Link: View Details
Information published.
CVE-2026-64015 security/keys: fix missed RCU read section on lookup
Published on: 2026-07-21 01:02:19
Link: View Details
Information published.
CVE-2026-63962 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()
Published on: 2026-07-21 01:02:25
Link: View Details
Information published.
CVE-2026-63958 usb: typec: ucsi: validate connector number in ucsi_connector_change()
Published on: 2026-07-21 01:02:31
Link: View Details
Information published.
CVE-2026-64117 wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
Published on: 2026-07-21 01:02:37
Link: View Details
Information published.
CVE-2026-63954 hpfs: fix a crash if hpfs_map_dnode_bitmap fails
Published on: 2026-07-21 01:02:44
Link: View Details
Information published.
CVE-2026-64078 netfilter: x_tables: add and use xtables_unregister_table_exit
Published on: 2026-07-21 01:02:56
Link: View Details
Information published.
CVE-2026-63983 net/sched: fix packet loop on netem when duplicate is on
Published on: 2026-07-21 01:03:15
Link: View Details
Information published.
CVE-2026-63964 usb: typec: ucsi: ccg: reject firmware images without a ':' record header
Published on: 2026-07-21 01:03:23
Link: View Details
Information published.
CVE-2026-63960 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
Published on: 2026-07-21 01:03:29
Link: View Details
Information published.
CVE-2026-63881 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
Published on: 2026-07-21 01:03:35
Link: View Details
Information published.
CVE-2026-63961 usb: typec: altmodes/displayport: validate count before reading Status Update VDO
Published on: 2026-07-21 01:03:41
Link: View Details
Information published.
CVE-2026-63963 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers
Published on: 2026-07-21 01:03:48
Link: View Details
Information published.
CVE-2026-64111 lsm: hold cred_guard_mutex for lsm_set_self_attr()
Published on: 2026-07-21 01:04:00
Link: View Details
Information published.
CVE-2026-64154 drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()
Published on: 2026-07-21 01:04:06
Link: View Details
Information published.
CVE-2026-64112 rbd: eliminate a race in lock_dwork draining on unmap
Published on: 2026-07-21 01:04:19
Link: View Details
Information published.
CVE-2026-64076 netfilter: bridge: eb_tables: close module init race
Published on: 2026-07-21 01:04:27
Link: View Details
Information published.
CVE-2026-64060 netfs: Fix leak of request in netfs_write_begin() error handling
Published on: 2026-07-21 01:04:33
Link: View Details
Information published.
CVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doit
Published on: 2026-07-21 01:04:40
Link: View Details
Information published.
CVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
Published on: 2026-07-21 01:04:52
Link: View Details
Information published.
CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit
Published on: 2026-07-21 01:04:58
Link: View Details
Information published.
CVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
Published on: 2026-07-21 01:05:04
Link: View Details
Information published.
CVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on error
Published on: 2026-07-21 01:05:16
Link: View Details
Information published.
CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Published on: 2026-07-21 01:05:23
Link: View Details
Information published.
CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Published on: 2026-07-21 01:05:29
Link: View Details
Information published.
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function
Published on: 2026-07-21 01:05:35
Link: View Details
Information published.
CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q
Published on: 2026-07-21 01:05:50
Link: View Details
Information published.
CVE-2026-42769 Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
Published on: 2026-07-21 01:05:42
Link: View Details
Information published.
CVE-2026-47302 .NET Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-47304 .NET Security Feature Bypass Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50525 .NET Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50527 .NET Framework Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50646 .NET Framework Remote Code Execution Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50648 .NET Framework Denial of Service Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50649 .NET Remote Code Execution Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50650 .NET Framework Elevation of Privilege Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50659 .NET Spoofing Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Published on: 2026-07-20 07:00:00
Link: View Details
Updated the build numbers. This is an informational update only.
CVE-2026-63815 f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
Published on: 2026-07-20 01:01:23
Link: View Details
Information published.
CVE-2026-53386 iio: adc: ti-ads1298: add bounds check to pga_settings index
Published on: 2026-07-20 01:01:49
Link: View Details
Information published.
CVE-2026-63810 block: Avoid mounting the bdev pseudo-filesystem in userspace
Published on: 2026-07-20 01:02:14
Link: View Details
Information published.
CVE-2026-53392 NFSv4/flexfiles: reject zero filehandle version count
Published on: 2026-07-20 01:02:33
Link: View Details
Information published.
CVE-2026-53374 drm/amdgpu: zero-initialize GART table on allocation
Published on: 2026-07-20 01:02:39
Link: View Details
Information published.
CVE-2026-53376 drm/amdkfd: Add upper bound check for num_of_nodes
Published on: 2026-07-20 01:02:57
Link: View Details
Information published.
CVE-2026-63806 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
Published on: 2026-07-20 01:03:04
Link: View Details
Information published.
CVE-2026-63833 ntfs3: reject direct userspace writes to reserved $LX* xattrs
Published on: 2026-07-20 01:03:29
Link: View Details
Information published.
CVE-2026-63826 fbdev: fix use-after-free in store_modes()
Published on: 2026-07-20 01:03:53
Link: View Details
Information published.
CVE-2026-63829 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
Published on: 2026-07-20 01:04:12
Link: View Details
Information published.
CVE-2026-53375 drm/amdgpu/vce: Prevent partial address patches
Published on: 2026-07-20 01:04:18
Link: View Details
Information published.
CVE-2026-53393 nfsd: reset write verifier on deferred writeback errors
Published on: 2026-07-20 01:04:37
Link: View Details
Information published.
CVE-2026-63809 bpf: use kvfree() for replaced sysctl write buffer
Published on: 2026-07-20 01:04:44
Link: View Details
Information published.
CVE-2026-63803 hdlc_ppp: sync per-proto timers before freeing hdlc state
Published on: 2026-07-20 01:05:02
Link: View Details
Information published.
CVE-2026-63834 batman-adv: tp_meter: restrict number of unacked list entries
Published on: 2026-07-20 01:05:09
Link: View Details
Information published.
CVE-2026-53391 NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
Published on: 2026-07-20 01:05:28
Link: View Details
Information published.
CVE-2026-63822 wifi: ath11k: fix warning when unbinding
Published on: 2026-07-20 01:05:34
Link: View Details
Information published.
CVE-2026-53397 nfsd: fix posix_acl leak on SETACL decode failure
Published on: 2026-07-20 01:05:52
Link: View Details
Information published.
CVE-2026-63836 batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
Published on: 2026-07-20 01:05:58
Link: View Details
Information published.
CVE-2026-63796 ocfs2: reject oversized group bitmap descriptors
Published on: 2026-07-20 01:06:42
Link: View Details
Information published.
CVE-2026-63812 f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
Published on: 2026-07-20 01:07:14
Link: View Details
Information published.
CVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
Published on: 2026-07-20 01:07:32
Link: View Details
Information published.
CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsg
Published on: 2026-07-20 01:07:39
Link: View Details
Information published.
CVE-2026-53382 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
Published on: 2026-07-20 01:07:57
Link: View Details
Information published.
CVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error path
Published on: 2026-07-20 01:08:03
Link: View Details
Information published.
CVE-2026-53381 virtiofs: fix UAF on submount umount
Published on: 2026-07-20 01:08:22
Link: View Details
Information published.
CVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry()
Published on: 2026-07-20 01:08:28
Link: View Details
Information published.
CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Published on: 2026-07-20 01:40:39
Link: View Details
Information published.
CVE-2026-62389 ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS
Published on: 2026-07-20 01:40:45
Link: View Details
Information published.
CVE-2026-63805 crypto: nx - fix nx_crypto_ctx_exit argument
Published on: 2026-07-20 01:01:30
Link: View Details
Information published.
CVE-2026-63816 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
Published on: 2026-07-20 01:01:36
Link: View Details
Information published.
CVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashes
Published on: 2026-07-20 01:01:43
Link: View Details
Information published.
CVE-2026-63853 drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring
Published on: 2026-07-20 01:01:55
Link: View Details
Information published.
CVE-2026-53402 fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
Published on: 2026-07-20 01:02:01
Link: View Details
Information published.
CVE-2026-63819 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
Published on: 2026-07-20 01:02:08
Link: View Details
Information published.
CVE-2026-53401 fbdev: omap2: fix use-after-free in omapfb_mmap
Published on: 2026-07-20 01:02:20
Link: View Details
Information published.
CVE-2026-63811 f2fs: read COW data with the original inode during atomic write
Published on: 2026-07-20 01:02:26
Link: View Details
Information published.
CVE-2026-63793 ntfs: serialize volume label accesses
Published on: 2026-07-20 01:02:45
Link: View Details
Information published.
CVE-2026-53403 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
Published on: 2026-07-20 01:02:51
Link: View Details
Information published.
CVE-2026-53377 drm/msm: always recover the gpu
Published on: 2026-07-20 01:03:10
Link: View Details
Information published.
CVE-2026-53368 f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage
Published on: 2026-07-20 01:03:16
Link: View Details
Information published.
CVE-2026-53400 i2c: core: fix adapter registration race
Published on: 2026-07-20 01:03:23
Link: View Details
Information published.
CVE-2026-63871 Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
Published on: 2026-07-20 01:03:35
Link: View Details
Information published.
CVE-2026-63872 esp: fix page frag reference leak on skb_to_sgvec failure
Published on: 2026-07-20 01:03:41
Link: View Details
Information published.
CVE-2026-53399 nfsd: release layout stid on setlease failure
Published on: 2026-07-20 01:03:47
Link: View Details
Information published.
CVE-2026-63858 netfilter: nf_tables: add hook transactions for device deletions
Published on: 2026-07-20 01:04:00
Link: View Details
Information published.
CVE-2026-63818 f2fs: validate orphan inode entry count
Published on: 2026-07-20 01:04:06
Link: View Details
Information published.
CVE-2026-63832 wifi: mt76: add wcid publish check in mt76_sta_add
Published on: 2026-07-20 01:04:24
Link: View Details
Information published.
CVE-2026-53387 iio: light: veml6075: add bounds check to veml6075_it_ms index
Published on: 2026-07-20 01:04:31
Link: View Details
Information published.
CVE-2026-63835 batman-adv: v: prevent OGM aggregation on disabled hardif
Published on: 2026-07-20 01:04:50
Link: View Details
Information published.
CVE-2026-63807 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
Published on: 2026-07-20 01:04:56
Link: View Details
Information published.
CVE-2026-53384 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
Published on: 2026-07-20 01:05:15
Link: View Details
Information published.
CVE-2026-63830 net: skmsg: preserve sg.copy across SG transforms
Published on: 2026-07-20 01:05:21
Link: View Details
Information published.
CVE-2026-53388 fuse: re-lock request before replacing page cache folio
Published on: 2026-07-20 01:05:40
Link: View Details
Information published.
CVE-2026-63794 KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
Published on: 2026-07-20 01:05:46
Link: View Details
Information published.
CVE-2026-63821 wifi: rtw88: usb: fix memory leaks on USB write failures
Published on: 2026-07-20 01:06:05
Link: View Details
Information published.
CVE-2026-63824 KEYS: fix overflow in keyctl_pkey_params_get_2()
Published on: 2026-07-20 01:06:11
Link: View Details
Information published.
CVE-2026-63798 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
Published on: 2026-07-20 01:06:17
Link: View Details
Information published.
CVE-2026-63823 keys: Pin request_key_auth payload in instantiate paths
Published on: 2026-07-20 01:06:24
Link: View Details
Information published.
CVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout()
Published on: 2026-07-20 01:06:30
Link: View Details
Information published.
CVE-2026-63797 rpmsg: char: Fix use-after-free on probe error path
Published on: 2026-07-20 01:06:36
Link: View Details
Information published.
CVE-2026-63817 f2fs: validate compress cache inode only when enabled
Published on: 2026-07-20 01:06:49
Link: View Details
Information published.
CVE-2026-63804 gfs2: fix use-after-free in gfs2_qd_dealloc
Published on: 2026-07-20 01:06:55
Link: View Details
Information published.
CVE-2026-63831 mac802154: llsec: add skb_cow_data() before in-place crypto
Published on: 2026-07-20 01:07:01
Link: View Details
Information published.
CVE-2026-63802 blk-cgroup: fix UAF in __blkcg_rstat_flush()
Published on: 2026-07-20 01:07:07
Link: View Details
Information published.
CVE-2026-53385 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
Published on: 2026-07-20 01:07:20
Link: View Details
Information published.
CVE-2026-53390 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
Published on: 2026-07-20 01:07:26
Link: View Details
Information published.
CVE-2026-63814 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
Published on: 2026-07-20 01:07:45
Link: View Details
Information published.
CVE-2026-53383 ksmbd: reject non-VALID session in compound request branch
Published on: 2026-07-20 01:07:51
Link: View Details
Information published.
CVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanup
Published on: 2026-07-20 01:08:10
Link: View Details
Information published.
CVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loop
Published on: 2026-07-20 01:08:16
Link: View Details
Information published.
CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS
Published on: 2026-07-18 01:01:20
Link: View Details
Information published.
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record
Published on: 2026-07-18 01:01:26
Link: View Details
Information published.
CVE-2026-47729 Squid: Memory disclosure in FTP gateway
Published on: 2026-07-18 01:01:34
Link: View Details
Information published.
CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling
Published on: 2026-07-18 01:01:40
Link: View Details
Information published.
Chromium: CVE-2026-15904 Use after free in Ozone
Published on: 2026-07-17 17:42:43
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-15903 Out of bounds read and write in V8
Published on: 2026-07-17 17:42:41
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-15899 Use after free in CameraCapture
Published on: 2026-07-17 17:42:35
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-15900 Use after free in GPU
Published on: 2026-07-17 17:42:38
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-15901 Use after free in Network
Published on: 2026-07-17 17:42:39
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-15902 Use after free in Cast
Published on: 2026-07-17 17:42:40
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-15905 Use after free in Aura
Published on: 2026-07-17 17:42:44
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability
Published on: 2026-07-17 07:00:00
Link: View Details
Added acknowledgements. This is an informational change only.
CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
Published on: 2026-07-17 01:01:19
Link: View Details
Information published.
CVE-2026-53366 ipv4: account for fraggap on the paged allocation path
Published on: 2026-07-17 01:01:26
Link: View Details
Information published.
CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak
Published on: 2026-07-17 01:01:38
Link: View Details
Information published.
CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string
Published on: 2026-07-17 01:01:45
Link: View Details
Information published.
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption
Published on: 2026-07-17 01:01:51
Link: View Details
Information published.
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Published on: 2026-07-17 01:02:16
Link: View Details
Information published.
CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index
Published on: 2026-07-17 01:02:29
Link: View Details
Information published.
CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
Published on: 2026-07-17 01:02:41
Link: View Details
Information published.
CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values
Published on: 2026-07-17 01:02:48
Link: View Details
Information published.
CVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation
Published on: 2026-07-17 01:01:32
Link: View Details
Information published.
CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service
Published on: 2026-07-17 01:01:57
Link: View Details
Information published.
CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
Published on: 2026-07-17 01:02:03
Link: View Details
Information published.
CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
Published on: 2026-07-17 01:02:10
Link: View Details
Information published.
CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
Published on: 2026-07-17 01:02:22
Link: View Details
Information published.
CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
Published on: 2026-07-17 01:02:35
Link: View Details
Information published.
CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-58643 Windows Admin Center Spoofing Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58598 Windows Backup Service Elevation of Privilege Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Updated product information in the Software Update table. This is an informational change only.
CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published on: 2026-07-16 07:00:00
Link: View Details
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace
Published on: 2026-07-16 01:39:07
Link: View Details
Information published.
CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability
Published on: 2026-07-15 07:00:00
Link: View Details
Corrected the Exploitability Index, Exploited flag and CVSS vector which was incorrect at the time of publication on 7/14/2026. This is an informational change only.
CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability
Published on: 2026-07-15 07:00:00
Link: View Details
Updated acknowledgment. This is an informational change only.
CVE-2026-50375 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-15 07:00:00
Link: View Details
Updated acknowledgment. This is an informational change only.
CVE-2026-56182 Windows NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-15 07:00:00
Link: View Details
Updated acknowledgment. This is an informational change only.
CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability
Published on: 2026-07-15 07:00:00
Link: View Details
Updated acknowledgment. This is an informational change only.
CVE-2026-56288 NULL Pointer Dereference in GNU patch
Published on: 2026-07-15 01:40:21
Link: View Details
Information published.
CVE-2026-58207 NATS Server: Remote crash via integer overflow in Connz pagination
Published on: 2026-07-15 01:40:45
Link: View Details
Information published.
CVE-2026-58251 NATS Server: Queue Subscribe Authz Bypass
Published on: 2026-07-15 01:40:53
Link: View Details
Information published.
CVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
Published on: 2026-07-15 01:41:00
Link: View Details
Information published.
CVE-2026-58252 NATS Server: Subscribe Authz Bypass via Wildcard-Overlap
Published on: 2026-07-15 01:41:15
Link: View Details
Information published.
CVE-2026-58209 NATS Server: MQTT retained and QoS replay bypass subscribe deny filters
Published on: 2026-07-15 01:41:23
Link: View Details
Information published.
CVE-2026-58253 NATS Server: Route API Auth Bypass
Published on: 2026-07-15 01:41:30
Link: View Details
Information published.
CVE-2026-57432 Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack
Published on: 2026-07-15 01:01:20
Link: View Details
Information published.
CVE-2026-39822 Root escape via symlink plus trailing slash in os
Published on: 2026-07-15 01:01:36
Link: View Details
Information published.
CVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tls
Published on: 2026-07-15 01:01:45
Link: View Details
Information published.
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header
Published on: 2026-07-15 01:02:01
Link: View Details
Information published.
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
Published on: 2026-07-15 01:02:14
Link: View Details
Information published.
CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch
Published on: 2026-07-15 01:40:12
Link: View Details
Information published.
CVE-2026-58250 NATS Server: Pre-auth server crash via double INFO in leafnode handshake
Published on: 2026-07-15 01:41:08
Link: View Details
Information published.
CVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Published on: 2026-07-15 01:03:21
Link: View Details
Information published.
CVE-2026-13221 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
Published on: 2026-07-15 01:01:27
Link: View Details
Information published.
CVE-2026-59875 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
Published on: 2026-07-15 01:01:52
Link: View Details
Information published.
CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace
Published on: 2026-07-15 01:02:07
Link: View Details
Information published.
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Published on: 2026-07-15 01:02:20
Link: View Details
Information published.
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
Published on: 2026-07-15 01:02:26
Link: View Details
Information published.
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
Published on: 2026-07-15 01:02:32
Link: View Details
Information published.
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
Published on: 2026-07-15 01:02:45
Link: View Details
Information published.
CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows
Published on: 2026-07-15 01:03:10
Link: View Details
Information published.
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
Published on: 2026-07-15 01:03:16
Link: View Details
Information published.
CVE-2025-44904 hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
Published on: 2026-07-15 01:39:09
Link: View Details
Information published.
CVE-2026-44839 RabbitMQ: Unsanitized vhost names allow for XSS in management UI
Published on: 2026-07-15 01:39:24
Link: View Details
Information published.
CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
Published on: 2026-07-15 01:39:37
Link: View Details
Information published.
CVE-2026-48561 Microsoft Copilot Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
CVE-2026-42982 Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-47296 Microsoft SQL Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
CVE-2026-34349 Windows Media Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
CVE-2026-34346 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
CVE-2026-42900 Microsoft Windows App Store Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42975 Windows Bluetooth Port Driver Remote Code Execution
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-47300 ASP.NET Core Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302 .NET Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303 ASP.NET Core Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-42990 SQL Server ODBC driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
CVE-2026-48572 Windows App Package Installer Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-48571 Windows App Package Installer Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-49164 Windows Active Directory Domain Services Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
CVE-2026-49165 Microsoft Windows App Store Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
CVE-2026-49166 Windows Print Configuration Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-49169 Windows DNS Server Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in DNS Server allows an authorized attacker to execute code over a network.
CVE-2026-49170 Windows StateRepository API Server file Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
CVE-2026-49171 Windows Speech Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
CVE-2026-49176 Windows WalletService Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
CVE-2026-49175 Windows DNS Client Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-49172 Windows FTP Service Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
CVE-2026-49173 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49174 DNS Client Tampering Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
CVE-2026-49784 Microsoft Windows App Store Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
CVE-2026-50506 OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-47282 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-45496 Visual Studio Code Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-50663 Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
CVE-2026-54983 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-50695 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-54129 Windows Hyper-V Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2026-54989 Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
CVE-2026-54987 Windows Overlay Filter Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
CVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
CVE-2026-54990 Remote Desktop Client Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-55000 Windows USB Print Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-54111 Universal Print Management Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-54991 Windows USB Print Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-54132 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-54107 Windows Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-54986 Windows Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-54993 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
CVE-2026-55001 Active Directory Domain Services Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
CVE-2026-54112 Windows Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-55004 Windows Print Configuration Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-54992 Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
CVE-2026-54109 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-54982 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-54114 Windows Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-54996 Windows USB Print Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-54119 Windows Active Directory Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-54997 Windows SMB Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-54999 Windows TCP/IP Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-55003 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-54995 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-54122 Windows GDI+ Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
CVE-2026-55005 Microsoft Exchange Server Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-55006 Microsoft Exchange Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55009 Microsoft Exchange Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
CVE-2026-50338 Azure Spring Apps Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-55011 Microsoft Defender Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
CVE-2026-55012 Microsoft Defender Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
CVE-2026-50524 .NET Framework Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-55002 Microsoft SQL Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
CVE-2026-55144 Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
CVE-2026-50520 Visual Studio Code Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
CVE-2026-54108 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-50675 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-50678 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-54988 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55899 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55948 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-56155 Active Directory Federation Services Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
CVE-2026-56164 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56169 Windows Admin Center Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-56170 ASP.NET Core Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-50694 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
CVE-2026-54127 Windows Hyper-V Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
CVE-2026-56193 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56185 Windows Admin Center Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
CVE-2026-57097 Microsoft XML Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-57107 Windows Admin Center Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
CVE-2026-57969 Azure CycleCloud Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-57976 Windows Active Directory Domain Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Information published.
CVE-2026-57979 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-55014 Windows Remote Help Defense Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
CVE-2026-58279 Azure CycleCloud Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-58526 Windows Storage Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-58595 Microsoft Bing App for IOS Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-58601 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58602 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58608 Windows Print Spooler Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
CVE-2026-58609 Windows Graphics Component Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
CVE-2026-58610 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
CVE-2026-58614 Windows Kernel Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-58618 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-58631 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
CVE-2026-58635 Windows Narrator Braille Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-58636 Microsoft PC Manager Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58640 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
The Patch for this issue was released but the CVE was inadvertently left out of the Patch Tuesday June 2026 release
CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-33842 Windows File Explorer Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-34328 Windows Audio Service Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
CVE-2026-40422 Windows File Explorer Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-41087 Windows File Explorer Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
CVE-2026-34348 Windows Event Logging Service Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
CVE-2026-44806 Windows Secure Channel Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
CVE-2026-40378 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
CVE-2026-47304 .NET Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-44800 Windows Push Notifications Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-47632 Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
CVE-2026-48564 DHCP Server Service Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-48581 Surface Broker SDMA Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
CVE-2026-45646 OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-49178 Windows Active Directory Domain Services Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
CVE-2026-49180 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-49181 Windows DHCP Client Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-49184 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
CVE-2026-49783 Secure Boot Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-49787 HTTP.sys Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
CVE-2026-49788 HTTP/2 Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVE-2026-49789 Windows NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-49790 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Information published.
CVE-2026-49791 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-49792 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-49793 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-49794 Windows USB Audio Class Driver Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-49796 Windows GDI+ Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
CVE-2026-49795 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49797 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50299 Windows Storage Spaces Direct Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-49800 Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
CVE-2026-49799 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
CVE-2026-50308 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50311 Windows Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
CVE-2026-49804 Windows USB Video Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-50294 Windows Kernel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-49801 Windows SMB Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-49802 Windows USB Print Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-49806 Windows USB Print Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-49805 Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-49803 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50323 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50318 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
CVE-2026-49807 Windows DirectX Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.
CVE-2026-50342 Windows MIDI Service Module Elevation of Privileges Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-49808 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50293 Windows Internal Task Bar Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
CVE-2026-50316 Windows Kernel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50354 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50296 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50297 Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50325 Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50356 Microsoft Windows App Store Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
CVE-2026-50384 Windows Clip Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50295 Windows Zero Trust DNS Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
CVE-2026-50350 Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
CVE-2026-50381 Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.
CVE-2026-50300 Windows DWM Core Library Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50303 Windows Key Guard Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
CVE-2026-50364 Windows Backup Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.
CVE-2026-50302 Windows Cryptographic Services Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50332 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50372 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
CVE-2026-50305 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50329 Microsoft DWM Core Library Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50363 Windows Push Notifications Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-50392 Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50328 Windows Server Update Service (WSUS) Tampering Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
CVE-2026-50306 Windows TCP/IP Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-50360 Windows SMB Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-50393 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-50412 Windows NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50337 Windows Notification Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.
CVE-2026-50386 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50400 Windows App Package Installer Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50419 Windows Kernel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50307 Windows TCP/IP Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-50326 Windows Unified Consent System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50440 Windows Audio Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50380 Windows GDI+ Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2026-50327 Windows Media Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-50407 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-50331 Windows Application Model Core API Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.
CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50396 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-50370 DHCP Server Service Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-50347 Windows Data.dll Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
CVE-2026-50321 Windows USB Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50425 Windows Internal System User Profile Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
CVE-2026-50315 Windows Image Acquisition Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Information published.
CVE-2026-50434 Windows Push Notification Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50339 Windows Push Notification Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50430 Windows Push Notification Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50310 Windows Human Interface Device Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-50312 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-50330 Windows Remote Desktop Client Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50357 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-50377 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50390 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50452 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50348 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50345 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50322 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50335 Windows Operating Systems Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
CVE-2026-50375 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-50361 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50317 Windows Operating Systems Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
CVE-2026-50340 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.
CVE-2026-50404 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50366 Windows Active Directory Domain Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Information published.
CVE-2026-50416 Win32k Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-50358 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50428 Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
CVE-2026-50373 Windows Search Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-50353 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-50388 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50410 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50449 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50371 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CVE-2026-50336 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50398 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
CVE-2026-50414 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
CVE-2026-50379 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
CVE-2026-50463 Windows Kernel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
CVE-2026-50460 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50403 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50433 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50391 Windows Group Policy Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
CVE-2026-50418 Windows System Secure Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-50423 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50378 Windows Key Guard Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.
CVE-2026-50401 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
CVE-2026-50346 Netlogon RPC Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50376 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50397 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50405 Windows Filtering Platform Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
CVE-2026-50448 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50387 Windows GDI Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-50334 Windows Push Notification Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.
CVE-2026-50445 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50344 Windows OLE Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
CVE-2026-50352 Windows Cryptographic Services Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
CVE-2026-50382 DirectX Graphics Kernel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
CVE-2026-50436 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50437 Windows DWM Core Library Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-50471 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50369 Windows Remote Desktop Services Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
CVE-2026-50469 Windows Projected File System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50454 Windows User Interface Core Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
CVE-2026-50365 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
CVE-2026-50426 Windows DNS Server Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
CVE-2026-50385 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50413 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50427 Content Delivery Manager Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50421 Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CVE-2026-50374 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.
CVE-2026-50367 Windows Sensor Data Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-50451 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-50455 Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-50466 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50402 NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50435 Windows Overlay Filter Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
CVE-2026-50409 Windows Overlay Filter Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.
CVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-50465 Windows DNS Client Tampering Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
CVE-2026-50439 Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
CVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-50457 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50473 Windows File Explorer Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50442 Windows File Explorer Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50389 Windows File Explorer Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50456 Windows File Explorer Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50432 Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
CVE-2026-50399 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50461 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50431 Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Information published.
CVE-2026-50453 Windows USB Audio Class Driver Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-50417 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50447 Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-50438 Microsoft PC Manager Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-50420 HTTP.sys Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.
CVE-2026-50362 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-50474 Remote Desktop Client Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-50444 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-50394 Windows Media Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
CVE-2026-50415 Windows Media Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.
CVE-2026-50458 Microsoft Brokering File System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50475 Windows Kernel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50476 Windows Network Connections Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
CVE-2026-50429 Windows Kernel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
CVE-2026-50450 Windows Network Connections Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50424 Windows Domain Controller Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
CVE-2026-50406 Windows Backup Engine Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
CVE-2026-50470 Windows Network Policy Server SNMP Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50459 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50477 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50478 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50479 Windows USB Hub Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50480 Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
CVE-2026-50482 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50495 DNS Client Tampering Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
CVE-2026-50483 Windows Graphics Component Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.
CVE-2026-50484 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50493 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50502 Windows Event Logging Service Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
CVE-2026-50485 Windows Hyper-V Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2026-50486 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50487 Windows DNS Client Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50488 Clipboard User Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50500 Windows Netlogon Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.
CVE-2026-50499 Windows Print Spooler Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CVE-2026-50489 Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50494 Windows NTFS Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50490 Windows Installer Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-50498 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Information published.
CVE-2026-50505 Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
CVE-2026-50491 Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-50492 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-50501 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-50503 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50497 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
CVE-2026-50496 Windows Network Policy Server SNMP Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50504 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-47295 Microsoft SQL Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-50509 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50510 GitHub Copilot Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
CVE-2026-50518 Windows DHCP Server Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50525 .NET Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526 .NET Tampering Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527 .NET Framework Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528 .NET Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646 .NET Framework Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-50648 .NET Framework Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649 .NET Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650 .NET Framework Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651 .NET Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-50657 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
CVE-2026-50658 Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2026-50659 .NET Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-50666 Windows Remote Access Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-50667 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50668 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-50669 Windows Telephony Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50670 Windows Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50672 Windows NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50673 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Information published.
CVE-2026-50674 Windows USB Print Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50676 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50677 Windows Media Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-54115 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
CVE-2026-50684 Active Directory Federation Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
CVE-2026-50679 Windows Search Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-50688 Windows Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50680 Windows Hyper-V Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2026-50681 Windows Secure Channel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVE-2026-50682 Active Directory Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
CVE-2026-50685 Windows DHCP Server Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-50683 Windows DHCP Client Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2026-50687 Windows Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50686 Windows OLE Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
CVE-2026-50689 Windows Clipboard Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
CVE-2026-54125 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50690 Windows SMB Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-50692 Desktop Window Manager Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
CVE-2026-54126 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-55010 Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
CVE-2026-47290 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-47642 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-48580 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-50301 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-50314 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-50467 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55017 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55016 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55024 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-50408 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55019 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55018 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55046 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55020 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55021 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55022 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55023 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55025 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55030 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55125 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55031 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55026 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55048 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55034 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55027 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55029 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55028 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55047 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55039 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55045 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-55049 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55032 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55033 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55041 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55138 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55124 Microsoft Word Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-55127 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55136 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55141 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55035 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55036 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55044 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55055 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55054 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-55037 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55058 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55038 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55132 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55137 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55053 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55122 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55057 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55131 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55126 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55051 Microsoft SharePoint Server Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55056 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-55142 Microsoft Word Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-55140 Microsoft Office Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55128 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55130 Microsoft Word Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55042 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55139 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55043 Microsoft PowerPoint Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55133 Microsoft OneNote Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
CVE-2026-55123 Microsoft PowerPoint Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55120 Microsoft PowerPoint Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55052 Microsoft SharePoint Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-55135 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-50468 Microsoft SQL Server Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-54116 Microsoft SQL Server Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-55145 Outlook Copilot Tampering Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.
CVE-2026-54131 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55898 Microsoft Excel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55944 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
CVE-2026-55947 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55949 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-56156 Microsoft Excel Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-56157 Microsoft SharePoint Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50359 Microsoft XML Core Services Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
CVE-2026-56168 Windows SMB Server Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Information published.
CVE-2026-56173 Windows WebView Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
CVE-2026-56176 Windows Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2026-56175 Windows NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-56182 Windows NTFS Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-56183 Windows MIDI Service Module Elevation of Privileges Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56190 Remote Desktop Protocol Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
CVE-2026-56184 Win32k Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-56187 Windows MIDI Service Module Elevation of Privileges Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56186 Windows Secure Channel Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
CVE-2026-56189 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
CVE-2026-50665 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56192 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56195 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56196 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-56178 Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
CVE-2026-56643 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56644 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-54124 Windows Terminal Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
CVE-2026-56194 Windows NFS Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
CVE-2026-56647 Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
CVE-2026-56648 Windows NFS Server Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.
CVE-2026-56649 Windows Network File System Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.
CVE-2026-57083 Windows Media Photo Codec Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
CVE-2026-57084 Windows File Explorer Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
CVE-2026-56650 Windows Network File System Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
CVE-2026-57095 Win32k Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
CVE-2026-57090 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-57094 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-57091 Windows File History Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVE-2026-57089 Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
CVE-2026-57085 Windows Print Spooler Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-57092 Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
CVE-2026-57087 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-57088 Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
CVE-2026-57093 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-57096 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVE-2026-57101 Visual Studio Code Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-57102 Visual Studio Code Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-57108 .NET Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57968 Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CVE-2026-57973 Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.
CVE-2026-57982 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
CVE-2026-58277 Microsoft SharePoint Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-58527 Windows Runtime Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-58528 Windows USB Audio Class Driver Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-58530 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-58538 Windows Bluetooth Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58533 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58535 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58546 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58539 Windows Remote Desktop Client Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58540 Windows Installer Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-58531 Windows SMB Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2026-58532 Windows Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-58537 Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-58534 Windows Input Method Editor (IME) Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2026-58536 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-58545 Windows Kernel Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
CVE-2026-58544 Windows Management Services Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
CVE-2026-58542 Windows Media Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-58543 Universal Print Management Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.
CVE-2026-58541 Microsoft DWM Core Library Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2026-58594 Remote Desktop Client Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
CVE-2026-47305 Visual Studio Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2026-58613 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58617 M365 Copilot for iOS Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58619 Windows Sensor Data Service Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58626 Windows Remote Desktop Services Remote Code Execution Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
CVE-2026-58627 Windows DHCP Server Denial of Service Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-58628 Windows Wireless Network Manager Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
CVE-2026-58629 DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-58632 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-58633 Desktop Window Manager Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58634 Desktop Window Manager Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58637 Windows Client-Side Caching Elevation of Privilege Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
CVE-2026-58638 Windows Boot Loader Security Feature Bypass Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
CVE-2026-56181 Windows Network Address Translation (NAT) Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-55121 Microsoft Office Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-58529 Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
CVE-2026-55008 Microsoft Exchange Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
ADV990001 Latest Servicing Stack Updates
Published on: 2026-07-14 07:00:00
Link: View Details
Advisory updated to announce new versions of Servicing Stack Updates are available. Please see the FAQ for details.
CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability
Published on: 2026-07-14 07:00:00
Link: View Details
Updated FAQ information. This is an informational change only.
CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras
Published on: 2026-07-14 01:38:59
Link: View Details
Information published.
CVE-2026-40468 Heap buffer overflow in gawk
Published on: 2026-07-14 01:01:35
Link: View Details
Information published.
CVE-2026-14461 Out-of-bound read in mtr
Published on: 2026-07-14 01:39:17
Link: View Details
Information published.
CVE-2026-40553 Stack-based buffer overflow in gawk
Published on: 2026-07-14 01:01:22
Link: View Details
Information published.
CVE-2026-40469 Heap buffer overflow in gawk
Published on: 2026-07-14 01:01:29
Link: View Details
Information published.
CVE-2026-40467 Use after free in gawk
Published on: 2026-07-14 01:01:41
Link: View Details
Information published.
CVE-2025-71072 shmem: fix recovery on rename failures
Published on: 2026-07-13 01:44:37
Link: View Details
Information published.
CVE-2022-4543 A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.
Published on: 2026-07-13 01:38:47
Link: View Details
Information published.
CVE-2025-38096 wifi: iwlwifi: don't warn when if there is a FW error
Published on: 2026-07-13 01:46:49
Link: View Details
Information published.
CVE-2026-45489 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published on: 2026-07-12 07:00:00
Link: View Details
CWE added. Informational change only.
CVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Published on: 2026-07-12 01:01:27
Link: View Details
Information published.
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion
Published on: 2026-07-12 01:01:34
Link: View Details
Information published.
CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input
Published on: 2026-07-12 01:01:40
Link: View Details
Information published.
CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace
Published on: 2026-07-12 01:01:47
Link: View Details
Information published.
Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn
Published on: 2026-07-11 15:41:38
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWeb
Published on: 2026-07-11 15:39:58
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13778 Use after free in WebUSB
Published on: 2026-07-11 15:39:26
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14394 Use after free in V8
Published on: 2026-07-11 15:37:39
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14396 Out of bounds read in ANGLE
Published on: 2026-07-11 15:39:53
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14395 Out of bounds write in V8
Published on: 2026-07-11 15:37:40
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14397 Out of bounds write in ANGLE
Published on: 2026-07-11 15:39:54
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14398 Use after free in ANGLE
Published on: 2026-07-11 15:37:41
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14399 Uninitialized Use in Dawn
Published on: 2026-07-11 15:37:43
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14400 Out of bounds write in ANGLE
Published on: 2026-07-11 15:37:44
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLE
Published on: 2026-07-11 15:39:23
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14402 Uninitialized Use in ANGLE
Published on: 2026-07-11 15:37:45
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14403 Use after free in V8
Published on: 2026-07-11 15:37:47
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14405 Uninitialized Use in V8
Published on: 2026-07-11 15:37:50
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14404 Inappropriate implementation in PDFium
Published on: 2026-07-11 15:37:48
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14406 Out of bounds read in V8
Published on: 2026-07-11 15:37:51
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14410 Inappropriate implementation in Skia
Published on: 2026-07-11 15:37:56
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14407 Inappropriate implementation in V8
Published on: 2026-07-11 15:37:53
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14409 Inappropriate implementation in V8
Published on: 2026-07-11 15:37:55
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLE
Published on: 2026-07-11 15:37:59
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14408 Uninitialized Use in Dawn
Published on: 2026-07-11 15:37:54
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLE
Published on: 2026-07-11 15:37:57
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14413 Uninitialized Use in ANGLE
Published on: 2026-07-11 15:38:00
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14415 Inappropriate implementation in V8
Published on: 2026-07-11 15:38:03
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14418 Uninitialized Use in ANGLE
Published on: 2026-07-11 15:38:07
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14417 Use after free in Dawn
Published on: 2026-07-11 15:38:05
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14416 Out of bounds read in Dawn
Published on: 2026-07-11 15:38:04
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14419 Use after free in Skia
Published on: 2026-07-11 15:38:08
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14420 Out of bounds read and write in Dawn
Published on: 2026-07-11 15:38:09
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14421 Uninitialized Use in Dawn
Published on: 2026-07-11 15:39:25
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14422 Out of bounds read and write in Tint
Published on: 2026-07-11 15:39:55
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14423 Type Confusion in Tint
Published on: 2026-07-11 15:38:10
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14425 Use after free in ANGLE
Published on: 2026-07-11 15:38:12
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14426 Use after free in V8
Published on: 2026-07-11 15:38:13
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14427 Heap buffer overflow in Skia
Published on: 2026-07-11 15:38:14
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14424 Use after free in Dawn
Published on: 2026-07-11 15:39:57
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14429 Insufficient validation of untrusted input in Skia
Published on: 2026-07-11 15:38:16
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14430 Integer overflow in V8
Published on: 2026-07-11 15:38:17
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14432 Use after free in V8
Published on: 2026-07-11 15:38:19
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14431 Type Confusion in V8
Published on: 2026-07-11 15:38:18
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14414 Insufficient validation of untrusted input in Skia
Published on: 2026-07-11 15:38:02
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13785 Use after free in Bluetooth
Published on: 2026-07-11 15:39:28
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13788 Use after free in Fullscreen
Published on: 2026-07-11 15:40:49
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13791 Insufficient validation of untrusted input in Downloads
Published on: 2026-07-11 15:39:29
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13807 Use after free in Import
Published on: 2026-07-11 15:40:01
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOS
Published on: 2026-07-11 15:39:59
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13792 Use after free in Touchbar
Published on: 2026-07-11 15:39:30
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13805 Use after free in GFX
Published on: 2026-07-11 15:39:31
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13808 Insufficient data validation in Chrome for iOS
Published on: 2026-07-11 15:40:02
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13812 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:05
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13809 Side-channel information leakage in Safe Browsing
Published on: 2026-07-11 15:40:03
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13813 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:06
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13816 Insufficient validation of untrusted input in File Input
Published on: 2026-07-11 15:40:50
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13822 Inappropriate implementation in Extensions
Published on: 2026-07-11 15:40:52
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13819 Out of bounds read in ANGLE
Published on: 2026-07-11 15:39:33
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13825 Uninitialized Use in Dawn
Published on: 2026-07-11 15:40:53
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13826 Inappropriate implementation in Autofill
Published on: 2026-07-11 15:40:54
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13827 Use after free in Updater
Published on: 2026-07-11 15:39:34
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13842 Incorrect security UI in Chrome for iOS
Published on: 2026-07-11 15:40:07
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13843 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:09
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13833 Uninitialized Use in ANGLE
Published on: 2026-07-11 15:39:35
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13846 Use after free in USB
Published on: 2026-07-11 15:39:37
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13847 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:10
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13850 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:11
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstalls
Published on: 2026-07-11 15:40:56
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13856 Insufficient validation of untrusted input in Speech
Published on: 2026-07-11 15:40:58
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstalls
Published on: 2026-07-11 15:40:57
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
CVE-2026-13862
Published on: 2026-07-11 15:40:13
Link: View Details
CVE-2026-13862
Chromium: CVE-2026-13863 Insufficient validation of untrusted input in CustomTabs
Published on: 2026-07-11 15:41:00
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13866 Insufficient validation of untrusted input in Input
Published on: 2026-07-11 15:41:01
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstalls
Published on: 2026-07-11 15:41:05
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13868 Inappropriate implementation in Network
Published on: 2026-07-11 15:41:02
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13870 Use after free in WebView
Published on: 2026-07-11 15:41:04
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13878 Use after free in Bluetooth
Published on: 2026-07-11 15:39:38
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13885 Use after free in Skia
Published on: 2026-07-11 15:41:06
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13880 Use after free in USB
Published on: 2026-07-11 15:39:39
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthentication
Published on: 2026-07-11 15:40:14
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOS
Published on: 2026-07-11 15:40:15
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13887 Insufficient policy enforcement in NFC
Published on: 2026-07-11 15:41:08
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13902 Inappropriate implementation in Chrome for iOS
Published on: 2026-07-11 15:40:16
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13904 Incorrect security UI in Safe Browsing
Published on: 2026-07-11 15:40:18
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13905 Incorrect security UI in Chrome for iOS
Published on: 2026-07-11 15:40:19
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13907 Inappropriate implementation in iOSWeb
Published on: 2026-07-11 15:40:20
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13908 Insufficient validation of untrusted input in Omnibox
Published on: 2026-07-11 15:40:22
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13910 Insufficient policy enforcement in WebXR
Published on: 2026-07-11 15:41:09
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13912 Incorrect security UI in Safe Browsing
Published on: 2026-07-11 15:40:23
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13914 Inappropriate implementation in Passwords
Published on: 2026-07-11 15:39:40
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13913 Insufficient policy enforcement in Autofill
Published on: 2026-07-11 15:40:24
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13915 Use after free in Chrome for iOS
Published on: 2026-07-11 15:40:26
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOS
Published on: 2026-07-11 15:40:27
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:28
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13918 Use after free in Chrome for iOS
Published on: 2026-07-11 15:40:29
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13924 Insufficient validation of untrusted input in WebView
Published on: 2026-07-11 15:41:12
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13923 Uninitialized Use in GPU
Published on: 2026-07-11 15:41:10
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13926 Insufficient validation of untrusted input in Network
Published on: 2026-07-11 15:41:13
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13927 Insufficient validation of untrusted input in UI
Published on: 2026-07-11 15:41:14
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13932 Inappropriate implementation in Sharing
Published on: 2026-07-11 15:41:17
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13929 Insufficient validation of untrusted input in DevTools
Published on: 2026-07-11 15:41:15
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13936 Inappropriate implementation in Passwords
Published on: 2026-07-11 15:41:18
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShare
Published on: 2026-07-11 15:41:19
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13944 Inappropriate implementation in DataTransfer
Published on: 2026-07-11 15:39:42
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13943 Uninitialized Use in CSS
Published on: 2026-07-11 15:41:21
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13949 Insufficient policy enforcement in Payments
Published on: 2026-07-11 15:41:22
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13946 Inappropriate implementation in ScriptInjections
Published on: 2026-07-11 15:40:31
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabs
Published on: 2026-07-11 15:41:23
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13964 Insufficient policy enforcement in WebView
Published on: 2026-07-11 15:41:24
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13969 Uninitialized Use in UI
Published on: 2026-07-11 15:41:26
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13974 Integer overflow in Safe Browsing
Published on: 2026-07-11 15:39:43
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13975 Out of bounds read in ANGLE
Published on: 2026-07-11 15:39:44
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13980 Incorrect security UI in Chrome for iOS
Published on: 2026-07-11 15:40:32
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13994 Inappropriate implementation in Credential Management
Published on: 2026-07-11 15:41:28
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13983 Incorrect security UI in Chrome for iOS
Published on: 2026-07-11 15:40:34
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13981 Inappropriate implementation in Chrome for iOS
Published on: 2026-07-11 15:40:33
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13991 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:36
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13992 Inappropriate implementation in UI
Published on: 2026-07-11 15:39:46
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13987 Incorrect security UI in Mobile
Published on: 2026-07-11 15:41:27
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13997 Incorrect security UI in Extensions
Published on: 2026-07-11 15:41:31
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13998 Incorrect security UI in File Input
Published on: 2026-07-11 15:39:47
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14028 Incorrect security UI in Chrome for iOS
Published on: 2026-07-11 15:40:37
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-13995 Insufficient validation of untrusted input in Autofill
Published on: 2026-07-11 15:41:29
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14005 Use after free in Omnibox
Published on: 2026-07-11 15:41:32
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14066 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:38
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14067 Use after free in Chrome for iOS
Published on: 2026-07-11 15:40:40
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14075 Policy bypass in Chrome for iOS
Published on: 2026-07-11 15:40:41
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14099 Use after free in Chrome for iOS
Published on: 2026-07-11 15:40:43
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14096 Object lifecycle issue in Input
Published on: 2026-07-11 15:41:33
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14101 Insufficient policy enforcement in Sandbox
Published on: 2026-07-11 15:39:49
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls
Published on: 2026-07-11 15:41:35
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14126 Incorrect security UI in UI
Published on: 2026-07-11 15:41:36
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14123 Incorrect security UI in Chrome for iOS
Published on: 2026-07-11 15:40:44
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14128 Insufficient data validation in Chrome for iOS
Published on: 2026-07-11 15:40:45
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE
Published on: 2026-07-11 15:41:37
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14136 Incorrect security UI in Chrome for iOS
Published on: 2026-07-11 15:40:46
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14137 Insufficient validation of untrusted input in Chrome for iOS
Published on: 2026-07-11 15:40:48
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14386 Out of bounds read in ANGLE
Published on: 2026-07-11 15:39:52
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14385 Heap buffer overflow in ANGLE
Published on: 2026-07-11 15:39:50
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14388 Out of bounds read in ANGLE
Published on: 2026-07-11 15:39:22
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14390 Use after free in ANGLE
Published on: 2026-07-11 15:37:31
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14393 Use after free in V8
Published on: 2026-07-11 15:37:37
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14391 Integer overflow in ANGLE
Published on: 2026-07-11 15:37:35
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Chromium: CVE-2026-14392 Out of bounds write in Tint
Published on: 2026-07-11 15:37:36
Link: View Details
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
CVE-2026-58281 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published on: 2026-07-11 07:00:00
Link: View Details
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2024-7598 Network restriction bypass via race condition during namespace termination
Published on: 2026-07-11 01:38:52
Link: View Details
Information published.
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop
Published on: 2026-07-11 01:40:30
Link: View Details
Information published.
CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
Published on: 2026-07-11 01:08:33
Link: View Details
Information published.
CVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Published on: 2026-07-11 01:41:05
Link: View Details
Information published.
CVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-Completion
Published on: 2026-07-11 01:01:16
Link: View Details
Information published.
CVE-2026-20214 ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Published on: 2026-07-11 01:01:29
Link: View Details
Information published.
CVE-2026-20215 ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Published on: 2026-07-11 01:01:35
Link: View Details
Information published.
CVE-2026-20216 ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
Published on: 2026-07-11 01:01:41
Link: View Details
Information published.
CVE-2026-20217 ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Published on: 2026-07-11 01:01:47
Link: View Details
Information published.
CVE-2026-20244 ClamAV DMG File Processing Denial of Service Vulnerability
Published on: 2026-07-11 01:02:00
Link: View Details
Information published.
CVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
Published on: 2026-07-11 01:02:59
Link: View Details
Information published.
CVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Published on: 2026-07-11 01:06:39
Link: View Details
Information published.
CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment
Published on: 2026-07-11 01:06:45
Link: View Details
Information published.
CVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directive
Published on: 2026-07-11 01:06:59
Link: View Details
Information published.
CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
Published on: 2026-07-11 01:07:05
Link: View Details
Information published.
CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Published on: 2026-07-11 01:07:18
Link: View Details
Information published.
CVE-2026-59890 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Published on: 2026-07-11 01:07:37
Link: View Details
Information published.
CVE-2026-58207 NATS Server: Remote crash via integer overflow in Connz pagination
Published on: 2026-07-11 01:07:49
Link: View Details
Information published.
CVE-2026-58251 NATS Server: Queue Subscribe Authz Bypass
Published on: 2026-07-11 01:07:55
Link: View Details
Information published.
CVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
Published on: 2026-07-11 01:08:02
Link: View Details
Information published.
CVE-2026-58252 NATS Server: Subscribe Authz Bypass via Wildcard-Overlap
Published on: 2026-07-11 01:08:14
Link: View Details
Information published.
CVE-2026-58209 NATS Server: MQTT retained and QoS replay bypass subscribe deny filters
Published on: 2026-07-11 01:08:20
Link: View Details
Information published.
CVE-2026-58253 NATS Server: Route API Auth Bypass
Published on: 2026-07-11 01:08:26
Link: View Details
Information published.
CVE-2026-20213 ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability
Published on: 2026-07-11 01:01:22
Link: View Details
Information published.
CVE-2026-20243 ClamAV ALZ Archive Processing Denial of Service Vulnerability
Published on: 2026-07-11 01:01:53
Link: View Details
Information published.
CVE-2026-14461 Out-of-bound read in mtr
Published on: 2026-07-11 01:04:28
Link: View Details
Information published.
CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
Published on: 2026-07-11 01:06:33
Link: View Details
Information published.
CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
Published on: 2026-07-11 01:06:53
Link: View Details
Information published.
CVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
Published on: 2026-07-11 01:07:11
Link: View Details
Information published.
CVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumption
Published on: 2026-07-11 01:07:43
Link: View Details
Information published.
CVE-2026-58250 NATS Server: Pre-auth server crash via double INFO in leafnode handshake
Published on: 2026-07-11 01:08:08
Link: View Details
Information published.
CVE-2026-45571 go-git: Crafted repositories may modify main and submodule .git directories
Published on: 2026-07-11 01:39:50
Link: View Details
Information published.
CVE-2026-45570 go-git: Improper single-quote escaping in go-git SSH transport
Published on: 2026-07-11 01:39:57
Link: View Details
Information published.
CVE-2026-56288 NULL Pointer Dereference in GNU patch
Published on: 2026-07-10 01:01:37
Link: View Details
Information published.
CVE-2026-59818 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation
Published on: 2026-07-10 01:01:17
Link: View Details
Information published.
CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch
Published on: 2026-07-10 01:01:27
Link: View Details
Information published.
CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
Published on: 2026-07-09 01:42:39
Link: View Details
Information published.
CVE-2025-58188 Panic when validating certificates with DSA public keys in crypto/x509
Published on: 2026-07-09 01:41:05
Link: View Details
Information published.
CVE-2025-61724 Excessive CPU consumption in Reader.ReadResponse in net/textproto
Published on: 2026-07-09 01:40:56
Link: View Details
Information published.
CVE-2025-23131 dlm: prevent NPD when writing a positive value to event_done
Published on: 2026-07-09 01:40:16
Link: View Details
Information published.
CVE-2026-9545 exposing HTTP/3 early data
Published on: 2026-07-09 01:46:22
Link: View Details
Information published.
CVE-2026-8932 incomplete mTLS config matching in conn reuse
Published on: 2026-07-09 01:46:48
Link: View Details
Information published.
CVE-2026-9547 SSH improper host validation
Published on: 2026-07-09 01:47:17
Link: View Details
Information published.
CVE-2026-8458 wrong reuse for different services
Published on: 2026-07-09 01:48:27
Link: View Details
Information published.
CVE-2026-8924 trailing dot domain super cookie
Published on: 2026-07-09 01:48:07
Link: View Details
Information published.
CVE-2026-10536 HTTP/2 stream-dependency tree UAF
Published on: 2026-07-09 01:48:59
Link: View Details
Information published.
CVE-2026-11856 cross-origin Digest auth state leak
Published on: 2026-07-09 01:47:43
Link: View Details
Information published.
CVE-2026-8286 wrong STARTTLS connection reuse
Published on: 2026-07-09 01:50:03
Link: View Details
Information published.
CVE-2026-8926 password leak with netrc and user in URL
Published on: 2026-07-09 01:49:37
Link: View Details
Information published.
CVE-2026-9080 UAF after pause in socket callback
Published on: 2026-07-09 01:49:11
Link: View Details
Information published.
CVE-2026-8925 SASL double-free
Published on: 2026-07-09 01:49:49
Link: View Details
Information published.
CVE-2026-53359 KVM: x86: Fix shadow paging use-after-free due to unexpected role
Published on: 2026-07-09 01:50:15
Link: View Details
Information published.
CVE-2026-14355 ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
Published on: 2026-07-09 01:50:09
Link: View Details
Information published.
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
Published on: 2026-07-09 01:50:21
Link: View Details
Information published.
CVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
Published on: 2026-07-09 01:01:15
Link: View Details
Information published.
CVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Published on: 2026-07-09 01:01:22
Link: View Details
Information published.
CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
Published on: 2026-07-09 01:01:28
Link: View Details
Information published.
CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
Published on: 2026-07-09 01:01:35
Link: View Details
Information published.
CVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
Published on: 2026-07-09 01:01:41
Link: View Details
Information published.
CVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
Published on: 2026-07-09 01:01:47
Link: View Details
Information published.
CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Published on: 2026-07-09 01:01:53
Link: View Details
Information published.
CVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer Overflow
Published on: 2026-07-09 01:02:13
Link: View Details
Information published.
CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
Published on: 2026-07-09 01:02:26
Link: View Details
Information published.
CVE-2026-38968 ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Published on: 2026-07-09 01:02:45
Link: View Details
Information published.
CVE-2026-38969 ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.
Published on: 2026-07-09 01:02:55
Link: View Details
Information published.
CVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Published on: 2026-07-09 01:03:02
Link: View Details
Information published.
CVE-2026-53354 arm64: errata: Mitigate TLBI errata on various Arm CPUs
Published on: 2026-07-09 01:44:00
Link: View Details
Information published.
CVE-2026-53345 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
Published on: 2026-07-09 01:44:09
Link: View Details
Information published.
CVE-2026-53332 slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
Published on: 2026-07-09 01:44:16
Link: View Details
Information published.
CVE-2026-53336 nvmem: layouts: onie-tlv: fix hang on unknown types
Published on: 2026-07-09 01:44:34
Link: View Details
Information published.
CVE-2026-53327 debugobjects: Do not fill_pool() if pi_blocked_on
Published on: 2026-07-09 01:44:25
Link: View Details
Information published.
CVE-2026-53339 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
Published on: 2026-07-09 01:45:03
Link: View Details
Information published.
CVE-2026-9079 stale proxy password leak
Published on: 2026-07-09 01:46:04
Link: View Details
Information published.
CVE-2026-8927 env-set cross-proxy Digest auth state leak
Published on: 2026-07-09 01:49:26
Link: View Details
Information published.
CVE-2026-12064 proto-default skips SSH verification
Published on: 2026-07-09 01:48:39
Link: View Details
Information published.
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
Published on: 2026-07-09 01:50:30
Link: View Details
Information published.
CVE-2026-56001 libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
Published on: 2026-07-09 01:02:00
Link: View Details
Information published.
CVE-2026-56003 libXfont2 computeProps Property Buffer Heap Buffer Overflow
Published on: 2026-07-09 01:02:07
Link: View Details
Information published.
CVE-2026-55999 xorg-server / xwayland glamor font atlas Heap Buffer Overflow
Published on: 2026-07-09 01:02:20
Link: View Details
Information published.
CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
Published on: 2026-07-09 01:02:39
Link: View Details
Information published.
CVE-2026-23278 netfilter: nf_tables: always walk all pending catchall elements
Published on: 2026-07-09 01:43:38
Link: View Details
Information published.
CVE-2026-43010 bpf: Reject sleepable kprobe_multi programs at attach time
Published on: 2026-07-09 01:44:14
Link: View Details
Information published.
CVE-2026-46054 selinux: fix overlayfs mmap() and mprotect() access checks
Published on: 2026-07-09 01:47:35
Link: View Details
Information published.
CVE-2026-46135 nvmet-tcp: fix race between ICReq handling and queue teardown
Published on: 2026-07-09 01:47:55
Link: View Details
Information published.
CVE-2026-46242 eventpoll: fix ep_remove struct eventpoll / struct file UAF
Published on: 2026-07-09 01:48:05
Link: View Details
Information published.
CVE-2026-46140 Bluetooth: btmtk: validate WMT event SKB length before struct access
Published on: 2026-07-09 01:40:47
Link: View Details
Information published.
CVE-2026-46252 regulator: core: fix locking in regulator_resolve_supply() error path
Published on: 2026-07-09 01:48:25
Link: View Details
Information published.
CVE-2026-53269 netfilter: synproxy: add mutex to guard hook reference counting
Published on: 2026-07-09 01:02:32
Link: View Details
Information published.
CVE-2026-46331 net/sched: fix pedit partial COW leading to page cache corruption
Published on: 2026-07-09 01:40:26
Link: View Details
Information published.
CVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validation
Published on: 2026-07-09 01:42:15
Link: View Details
Information published.
CVE-2026-53167 fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
Published on: 2026-07-09 01:46:14
Link: View Details
Information published.
CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
Published on: 2026-07-09 01:43:14
Link: View Details
Information published.
CVE-2026-4360 Tarfile.extract() doesn't fully respect filter parameter
Published on: 2026-07-09 01:45:43
Link: View Details
Information published.
CVE-2026-42980 NT OS Kernel Elevation of Privilege Vulnerability
Published on: 2026-07-08 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability
Published on: 2026-07-08 07:00:00
Link: View Details
Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656. Please see the FAQ for more information on how to check if the new version has been installed.
CVE-2026-58525 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published on: 2026-07-08 07:00:00
Link: View Details
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published on: 2026-07-07 07:00:00
Link: View Details
Updated an acknowledgement. This is an informational change only.
CVE-2026-9545 exposing HTTP/3 early data
Published on: 2026-07-07 01:41:09
Link: View Details
Information published.
CVE-2026-8932 incomplete mTLS config matching in conn reuse
Published on: 2026-07-07 01:41:30
Link: View Details
Information published.
CVE-2026-8458 wrong reuse for different services
Published on: 2026-07-07 01:42:14
Link: View Details
Information published.
CVE-2026-8924 trailing dot domain super cookie
Published on: 2026-07-07 01:41:55
Link: View Details
Information published.
CVE-2026-10536 HTTP/2 stream-dependency tree UAF
Published on: 2026-07-07 01:42:55
Link: View Details
Information published.
CVE-2026-8286 wrong STARTTLS connection reuse
Published on: 2026-07-07 01:42:34
Link: View Details
Information published.
CVE-2026-8926 password leak with netrc and user in URL
Published on: 2026-07-07 01:43:09
Link: View Details
Information published.
CVE-2026-9080 UAF after pause in socket callback
Published on: 2026-07-07 01:43:20
Link: View Details
Information published.
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
Published on: 2026-07-07 01:01:15
Link: View Details
Information published.
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop
Published on: 2026-07-07 01:01:22
Link: View Details
Information published.
CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras
Published on: 2026-07-07 01:01:38
Link: View Details
Information published.
CVE-2026-14647 onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
Published on: 2026-07-07 01:01:44
Link: View Details
Information published.
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
Published on: 2026-07-07 01:01:28
Link: View Details
Information published.
CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Published on: 2026-07-07 01:40:29
Link: View Details
Information published.
CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
Published on: 2026-07-07 01:40:36
Link: View Details
Information published.
