| The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine. cve CVE-1999-1579 | |
| Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability. cve CVE-2000-0817 | |
| IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. cve CVE-2000-0884 | |
| Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates. cve CVE-2000-0885 | |
| IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability. cve CVE-2000-0886 | |
| Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability. cve CVE-2000-0929 | |
| The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability. cve CVE-2000-0933 | |
| The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability. cve CVE-2000-0942 | |
| A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search. cve CVE-2000-0951 | |
| IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability. cve CVE-2000-0970 | |
| File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability. cve CVE-2000-0979 | |
| NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network. cve CVE-2000-0980 | |
| Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability. cve CVE-2000-0982 | |
| Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability. cve CVE-2000-0983 | |
| Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability. cve CVE-2000-1034 | |
| Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back. cve CVE-2000-1227 | |
| Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed. cve CVE-2006-0033 | |
| Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389. cve CVE-2006-1316 | |
| Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316. cve CVE-2006-2389 | |
| Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet. cve CVE-2006-3014 | |
| Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability cve CVE-2015-2291 | |
| Adobe Flash Player Arbitrary Code Execution Vulnerability cve CVE-2016-1019 | |
| Microsoft Win32k Privilege Escalation Vulnerability cve CVE-2016-7255 | |
| Adobe Flash Player Use-After-Free Vulnerability cve CVE-2018-15982 | |
| Microsoft SMBv3 Remote Code Execution Vulnerability cve CVE-2020-0796 | |
| Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. cve CVE-2020-9695 | |
| Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. cve CVE-2020-9711 | |
| Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. cve CVE-2020-9713 | |
| SonicWall Email Security Unrestricted Upload of File Vulnerability cve CVE-2021-20022 | |
| SonicWall Email Security Path Traversal Vulnerability cve CVE-2021-20023 | |
| Microsoft Internet Explorer Memory Corruption Vulnerability cve CVE-2021-26411 | |
| Microsoft Exchange Server Remote Code Execution Vulnerability cve CVE-2021-26858 | |
| Microsoft Exchange Server Remote Code Execution Vulnerability cve CVE-2021-27065 | |
| Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability cve CVE-2022-37969 | |
| chromium-browser: Inappropriate implementation in Fullscreen cve CVE-2024-13178 | cvss |
| Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability cve CVE-2024-21400 | |
| Azure Identity Library for .NET Information Disclosure Vulnerability cve CVE-2024-29992 | |
| chromium-browser: Inappropriate implementation in DevTools cve CVE-2024-7017 | cvss |
| Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2024-7021 | |
| Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) cve CVE-2025-10200 | |
| Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords. cve CVE-2025-10221 | |
| Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption at rest. cve CVE-2025-10227 | |
| Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-10500 | |
| chromium-browser: Use after free in WebRTC cve CVE-2025-10501 | |
| Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-10890 | |
| Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-10891 | |
| chromium-browser: Out of bounds read in Media cve CVE-2025-11211 | cvss |
| Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-11212 | |
| chromium-browser: Off by one error in V8 cve CVE-2025-11215 | cvss |
| chromium-browser: Use after free in V8 cve CVE-2025-11219 | cvss |
| chromium-browser: Heap buffer overflow in Sync cve CVE-2025-11458 | cvss |
| chromium-browser: Use after free in Storage cve CVE-2025-11460 | |
| chromium-browser: Use after free in Safe Browsing cve CVE-2025-11756 | |
| chromium-browser: Out of bounds memory access in V8 cve CVE-2025-12036 | |
| Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data. cve CVE-2025-1241 | |
| chromium-browser: Type Confusion in V8 cve CVE-2025-12428 | |
| chromium-browser: Inappropriate implementation in V8 cve CVE-2025-12429 | |
| chromium-browser: Object lifecycle issue in Media cve CVE-2025-12430 | cvss |
| chromium-browser: Inappropriate implementation in Extensions cve CVE-2025-12431 | cvss |
| chromium-browser: Race in V8 cve CVE-2025-12432 | |
| chromium-browser: Inappropriate implementation in V8 cve CVE-2025-12433 | cvss |
| Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-12434 | |
| chromium-browser: Policy bypass in Extensions cve CVE-2025-12436 | cvss |
| chromium-browser: Use after free in PageInfo cve CVE-2025-12437 | cvss |
| chromium-browser: Inappropriate implementation in App-Bound Encryption cve CVE-2025-12439 | cvss |
| chromium-browser: Inappropriate implementation in Autofill cve CVE-2025-12440 | cvss |
| chromium-browser: Out of bounds read in V8 cve CVE-2025-12441 | cvss |
| chromium-browser: Out of bounds read in WebXR cve CVE-2025-12443 | cvss |
| chromium-browser: Incorrect security UI in Fullscreen UI cve CVE-2025-12444 | cvss |
| chromium-browser: Policy bypass in Extensions cve CVE-2025-12445 | cvss |
| chromium-browser: Incorrect security UI in SplitView cve CVE-2025-12446 | cvss |
| Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-12725 | |
| Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) cve CVE-2025-12726 | |
| chromium-browser: Inappropriate implementation in V8 cve CVE-2025-12727 | |
| Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-12728 | |
| Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low) cve CVE-2025-12905 | |
| chromium-browser: Inappropriate implementation in V8 cve CVE-2025-13042 | |
| chromium-browser: Inappropriate implementation in DevTools cve CVE-2025-13097 | cvss |
| chromium-browser: Inappropriate implementation in Compositing cve CVE-2025-13107 | |
| Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High) cve CVE-2025-13631 | |
| chromium-browser: Use after free in Digital Credentials cve CVE-2025-13633 | |
| chromium-browser: Inappropriate implementation in Downloads cve CVE-2025-13635 | cvss |
| chromium-browser: Inappropriate implementation in Split View cve CVE-2025-13636 | |
| chromium-browser: Inappropriate implementation in Downloads cve CVE-2025-13637 | |
| chromium-browser: Use after free in Media Stream cve CVE-2025-13638 | cvss |
| chromium-browser: Inappropriate implementation in WebRTC cve CVE-2025-13639 | cvss |
| chromium-browser: Bad cast in Loader cve CVE-2025-13720 | cvss |
| chromium-browser: Race in v8 cve CVE-2025-13721 | cvss |
| IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information cve CVE-2025-13916 | |
| chromium-browser: Side-channel information leakage in Navigation and Loading cve CVE-2025-13992 | cvss |
| Google Chromium Out of Bounds Memory Access Vulnerability cve CVE-2025-14174 | |
| Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-14372 | |
| Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) cve CVE-2025-14373 | |
| chromium-browser: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruption cve CVE-2025-14765 | |
| chromium-browser: Google Chrome V8: Out-of-bounds read and write leads to heap corruption cve CVE-2025-14766 | |
| Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability cve CVE-2025-21335 | |
| Microsoft Windows Storage Link Following Vulnerability cve CVE-2025-21391 | |
| NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running
cuobjdump. cve CVE-2025-23339 | |
| Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability cve CVE-2025-24993 | |
| Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability cve CVE-2025-26633 | |
| IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack. cve CVE-2025-33131 | |
| IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due an out of bounds write. cve CVE-2025-33133 | |
| Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. cve CVE-2025-3500 | |
| IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. cve CVE-2025-36298 | |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables. cve CVE-2025-36372 | |
| IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. cve CVE-2025-36431 | |
| Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. cve CVE-2025-49692 | |
| Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally. cve CVE-2025-54100 | |
| Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link. cve CVE-2025-54196 | |
| Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. cve CVE-2025-55233 | |
| Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network. cve CVE-2025-55242 | |
| A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase. cve CVE-2025-57870 | |
| Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally. cve CVE-2025-59497 | |
| Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. cve CVE-2025-59516 | |
| Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. cve CVE-2025-59517 | |
| Microsoft Windows Use After Free Vulnerability cve CVE-2025-62221 | |
| User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. cve CVE-2025-62223 | |
| User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. cve CVE-2025-62224 | |
| Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. cve CVE-2025-62455 | |
| Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. cve CVE-2025-62456 | |
| Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. cve CVE-2025-62457 | |
| Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. cve CVE-2025-62458 | |
| Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. cve CVE-2025-62461 | |
| Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. cve CVE-2025-62462 | |
| Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. cve CVE-2025-62463 | |
| Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. cve CVE-2025-62464 | |
| Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. cve CVE-2025-62466 | |
| Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. cve CVE-2025-62467 | |
| Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. cve CVE-2025-62468 | |
| Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. cve CVE-2025-62470 | |
| Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. cve CVE-2025-62472 | |
| Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. cve CVE-2025-62473 | |
| Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. cve CVE-2025-62474 | |
| Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. cve CVE-2025-62549 | |
| Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally. cve CVE-2025-62552 | |
| Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. cve CVE-2025-62554 | |
| Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. cve CVE-2025-62555 | |
| NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data. cve CVE-2025-64298 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. cve CVE-2025-64658 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. cve CVE-2025-64661 | |
| Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. cve CVE-2025-64677 | |
| Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue requires user interaction in that the user needs to open a malicious file. cve CVE-2025-64785 | |
| Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited unauthorized write access. Exploitation of this issue requires user interaction with a cryptographic signature. cve CVE-2025-64786 | |
| Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass cryptographic protections and gain limited unauthorized write access. Exploitation of this issue requires user interaction with a cryptographic signature. cve CVE-2025-64787 | |
| Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. cve CVE-2025-64899 | |
| Microsoft Edge (Chromium-based) Spoofing Vulnerability cve CVE-2025-65046 | |
| There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser. cve CVE-2025-67703 | |
| There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser. cve CVE-2025-67704 | |
| There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser. cve CVE-2025-67705 | |
| ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories.
However, the server’s architecture enforces controls that restrict uploaded files to non‑executable storage locations and prevent modification or replacement of existing application components or system configurations. Uploaded files cannot be executed, leveraged to escalate privileges, or used to access sensitive data.
Because the issue does not enable execution, service disruption, unauthorized access, or integrity compromise, its impact on confidentiality, integrity, and availability is low. Note that race conditions, secret values, or man‑in‑the‑middle conditions are required for exploitation. cve CVE-2025-67706 | |
| ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories.
However, the server’s architecture enforces controls that restrict uploaded files to non‑executable storage locations and prevent modification or replacement of existing application components or system configurations. Uploaded files cannot be executed, leveraged to escalate privileges, or used to access sensitive data.
Because the issue does not enable execution, service disruption, unauthorized access, or integrity compromise, its impact on confidentiality, integrity, and availability is low. Note that race conditions, secret values, or man‑in‑the‑middle conditions are required for exploitation. cve CVE-2025-67707 | |
| There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser. cve CVE-2025-67708 | |
| There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser. cve CVE-2025-67709 | |
| There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser. cve CVE-2025-67710 | |
| There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser. cve CVE-2025-67711 | |
| systeminformation: systeminformation: OS Command Injection in `fsSize()` allows arbitrary command execution on Windows. cve CVE-2025-68154 | |
| A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations. cve CVE-2025-69258 | |
| A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations.
Please note: authentication is not required in order to exploit this vulnerability.. cve CVE-2025-69259 | |
| A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations.
Please note: authentication is not required in order to exploit this vulnerability. cve CVE-2025-69260 | |
| chromium-browser: Out of bounds read in V8 cve CVE-2025-9479 | cvss |
| Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102313 | |
| Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) cve CVE-2026-102315 | |
| Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) cve CVE-2026-102317 | |
| In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions. cve CVE-2026-12878 | |
| Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for ArcGIS 12.1 and earlier. Other unsupported versions may also be affected. Esri recommends that users apply the Portal for ArcGIS Security 2026 Update 2 Patch to remediate this vulnerability. cve CVE-2026-13019 | |
| IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. cve CVE-2026-14470 | |
| IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. cve CVE-2026-17621 | |
| Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures. cve CVE-2026-18622 | |
| IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process. cve CVE-2026-19298 | |
| IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory. cve CVE-2026-19303 | |
| IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy. cve CVE-2026-19304 | |
| Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. cve CVE-2026-24301 | |
| Privilege escalation due to weak configuration during package extraction process. cve CVE-2026-25264 | |
| Privilege escalation due to weak configuration while temporary file handling. cve CVE-2026-25265 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-26174 | |
| InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. cve CVE-2026-27238 | |
| Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. cve CVE-2026-32157 | |
| Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability cve CVE-2026-33824 | |
| Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed. cve CVE-2026-34689 | |
| Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. cve CVE-2026-40400 | |
| Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. cve CVE-2026-47285 | |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. cve CVE-2026-47297 | |
| Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. cve CVE-2026-48361 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. cve CVE-2026-50349 | |
| Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. cve CVE-2026-50696 | |
| Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. cve CVE-2026-55946 | |
| Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-56172 | |
| Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. cve CVE-2026-56176 | |
| Use after free in Windows Server allows an authorized attacker to elevate privileges locally. cve CVE-2026-56177 | |
| Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally. cve CVE-2026-56198 | |
| Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. cve CVE-2026-57098 | |
| Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. cve CVE-2026-58599 | |
| Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally. cve CVE-2026-58600 | |
| Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally. cve CVE-2026-58611 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. cve CVE-2026-58616 | |
| Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. cve CVE-2026-58650 | |
| chromium-browser: Use after free in Media cve CVE-2026-5883 | cvss |
| Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. cve CVE-2026-59113 | |
| Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. cve CVE-2026-62694 | |
| Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. cve CVE-2026-62697 | |
| Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. cve CVE-2026-62699 | |
| Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. cve CVE-2026-62706 | |
| Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally. cve CVE-2026-62721 | |
| Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. cve CVE-2026-62744 | |
| Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network. cve CVE-2026-62759 | |
| Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. cve CVE-2026-62762 | |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network. cve CVE-2026-62801 | |
| Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally. cve CVE-2026-62810 | |
| Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. cve CVE-2026-62813 | |
| Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. cve CVE-2026-62904 | |
| Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. cve CVE-2026-63523 | |
| Microsoft SharePoint Code Injection Vulnerability cve CVE-2026-65660 | |
| No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. cve CVE-2026-65675 | |
| Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. cve CVE-2026-65812 | |
| External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. cve CVE-2026-66302 | |
| Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. cve CVE-2026-66303 | |
| Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. cve CVE-2026-66304 | |
| Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. cve CVE-2026-66305 | |
| Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. cve CVE-2026-66306 | |
| Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. cve CVE-2026-66307 | |
| Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. cve CVE-2026-66308 | |
| External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. cve CVE-2026-66310 | |
| Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. cve CVE-2026-66323 | |
| External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. cve CVE-2026-66324 | |
| cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods cve CVE-2026-66798 | cvss |
| Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-66814 | |
| Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network. cve CVE-2026-66816 | |
| Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-66818 | |
| Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-66819 | |
| Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-66820 | |
| Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-67368 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67369 | |
| Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-67370 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67373 | |
| Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network. cve CVE-2026-67376 | |
| Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network. cve CVE-2026-67378 | |
| Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67379 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67380 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-67381 | |
| Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67383 | |
| Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67384 | |
| Use after free in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67385 | |
| Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67386 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67388 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67389 | |
| Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67390 | |
| Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67393 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67624 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67629 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67630 | |
| Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. cve CVE-2026-67631 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. cve CVE-2026-67633 | |
| Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network. cve CVE-2026-67636 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67638 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67639 | |
| Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network. cve CVE-2026-67641 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-67642 | |
| Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. cve CVE-2026-67643 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67645 | |
| Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-67648 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-68775 | |
| Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-68776 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-68777 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-68778 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-68779 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-68780 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-68781 | |
| Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. cve CVE-2026-68784 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-68785 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. cve CVE-2026-68786 | |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally. cve CVE-2026-68787 | |
| Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. cve CVE-2026-68791 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. cve CVE-2026-68824 | |
| Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-68825 | |
| Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68827 | |
| Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. cve CVE-2026-68828 | |
| Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. cve CVE-2026-68830 | |
| Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. cve CVE-2026-68831 | |
| Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. cve CVE-2026-68832 | |
| Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. cve CVE-2026-68833 | |
| Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68834 | |
| Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68835 | |
| Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-68837 | |
| Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68838 | |
| Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. cve CVE-2026-68839 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-68840 | |
| Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. cve CVE-2026-68841 | |
| Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. cve CVE-2026-68842 | |
| Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. cve CVE-2026-68843 | |
| Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally. cve CVE-2026-68844 | |
| Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-68845 | |
| Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68846 | |
| Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. cve CVE-2026-68847 | |
| Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. cve CVE-2026-68848 | |
| Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally. cve CVE-2026-68849 | |
| Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally. cve CVE-2026-68850 | |
| Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. cve CVE-2026-68851 | |
| Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. cve CVE-2026-68852 | |
| Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally. cve CVE-2026-68873 | |
| Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. cve CVE-2026-68874 | |
| Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally. cve CVE-2026-68875 | |
| Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68876 | |
| Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally. cve CVE-2026-68877 | |
| Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68878 | |
| Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68880 | |
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. cve CVE-2026-68881 | |
| Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. cve CVE-2026-68884 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. cve CVE-2026-68885 | |
| Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. cve CVE-2026-68886 | |
| Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network. cve CVE-2026-68887 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. cve CVE-2026-68888 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68889 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. cve CVE-2026-68890 | |
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. cve CVE-2026-68891 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. cve CVE-2026-68892 | |
| Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68893 | |
| Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network. cve CVE-2026-68894 | |
| Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally. cve CVE-2026-68895 | |
| Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. cve CVE-2026-68896 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. cve CVE-2026-68897 | |
| Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. cve CVE-2026-68898 | |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. cve CVE-2026-69265 | |
| Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network. cve CVE-2026-69266 | |
| Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. cve CVE-2026-69267 | |
| Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. cve CVE-2026-69269 | |
| Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. cve CVE-2026-69270 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69271 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69272 | |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69274 | |
| Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69275 | |
| Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. cve CVE-2026-69276 | |
| Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. cve CVE-2026-69277 | |
| Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. cve CVE-2026-69278 | |
| Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69279 | |
| Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. cve CVE-2026-69280 | |
| Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally. cve CVE-2026-69281 | |
| Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69283 | |
| Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally. cve CVE-2026-69284 | |
| Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally. cve CVE-2026-69286 | |
| Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. cve CVE-2026-69287 | |
| Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. cve CVE-2026-69288 | |
| Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally. cve CVE-2026-69289 | |
| Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. cve CVE-2026-69290 | |
| Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network. cve CVE-2026-69291 | |
| Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69292 | |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69293 | |
| Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally. cve CVE-2026-69294 | |
| Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69295 | |
| Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69296 | |
| Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. cve CVE-2026-69297 | |
| Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69298 | |
| Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally. cve CVE-2026-69299 | |
| Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. cve CVE-2026-69300 | |
| Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69301 | |
| Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. cve CVE-2026-69303 | |
| Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. cve CVE-2026-69304 | |
| Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69305 | |
| Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. cve CVE-2026-69306 | |
| Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. cve CVE-2026-69307 | |
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. cve CVE-2026-69308 | |
| Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. cve CVE-2026-69309 | |
| Use after free in Windows DNS allows an authorized attacker to elevate privileges locally. cve CVE-2026-69310 | |
| Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69311 | |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. cve CVE-2026-69312 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69313 | |
| Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69314 | |
| Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally. cve CVE-2026-69315 | |
| Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. cve CVE-2026-69316 | |
| Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. cve CVE-2026-69317 | |
| Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. cve CVE-2026-69318 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69319 | |
| Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. cve CVE-2026-69320 | |
| Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally. cve CVE-2026-69321 | |
| Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69322 | |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69323 | |
| Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally. cve CVE-2026-69324 | |
| Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. cve CVE-2026-69325 | |
| Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. cve CVE-2026-69328 | |
| Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network. cve CVE-2026-69329 | |
| Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. cve CVE-2026-69331 | |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69332 | |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. cve CVE-2026-69333 | |
| Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network. cve CVE-2026-69334 | |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. cve CVE-2026-69335 | |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69336 | |
| Double free in Windows Registry allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69337 | |
| Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69338 | |
| Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. cve CVE-2026-69339 | |
| Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69340 | |
| Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. cve CVE-2026-69341 | |
| Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. cve CVE-2026-69342 | |
| Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. cve CVE-2026-69343 | |
| Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. cve CVE-2026-69344 | |
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. cve CVE-2026-69345 | |
| Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69346 | |
| Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. cve CVE-2026-69347 | |
| Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. cve CVE-2026-69348 | |
| Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. cve CVE-2026-69349 | |
| Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. cve CVE-2026-69350 | |
| Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. cve CVE-2026-69351 | |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69352 | |
| Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. cve CVE-2026-69353 | |
| External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. cve CVE-2026-69355 | |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. cve CVE-2026-69356 | |
| Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69357 | |
| Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network. cve CVE-2026-69358 | |
| Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. cve CVE-2026-69359 | |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. cve CVE-2026-69360 | |
| Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. cve CVE-2026-69361 | |
| Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally. cve CVE-2026-69362 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69364 | |
| Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69365 | |
| Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69366 | |
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. cve CVE-2026-69367 | |
| Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. cve CVE-2026-69368 | |
| Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. cve CVE-2026-69369 | |
| Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69371 | |
| Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network. cve CVE-2026-69372 | |
| Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. cve CVE-2026-69373 | |
| Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network. cve CVE-2026-69374 | |
| Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. cve CVE-2026-69375 | |
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. cve CVE-2026-69376 | |
| Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. cve CVE-2026-69377 | |
| Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. cve CVE-2026-69378 | |
| Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally. cve CVE-2026-69379 | |
| Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69380 | |
| Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack. cve CVE-2026-69381 | |
| Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. cve CVE-2026-69382 | |
| External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally. cve CVE-2026-69383 | |
| Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally. cve CVE-2026-69384 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. cve CVE-2026-69385 | |
| Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. cve CVE-2026-69386 | |
| Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69388 | |
| Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally. cve CVE-2026-69389 | |
| Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. cve CVE-2026-69390 | |
| Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69391 | |
| Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. cve CVE-2026-69392 | |
| Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. cve CVE-2026-69393 | |
| Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69394 | |
| Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network. cve CVE-2026-69395 | |
| Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69396 | |
| Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network. cve CVE-2026-69397 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69398 | |
| Azure Arc Elevation of Privilege Vulnerability cve CVE-2026-69399 | |
| Use after free in Audio Video Control Transport Protocol allows an authorized attacker to elevate privileges locally. cve CVE-2026-69401 | |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. cve CVE-2026-69402 | |
| Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. cve CVE-2026-69403 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. cve CVE-2026-69404 | |
| Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. cve CVE-2026-69405 | |
| Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. cve CVE-2026-69406 | |
| Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69407 | |
| Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. cve CVE-2026-69408 | |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. cve CVE-2026-69410 | |
| Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. cve CVE-2026-69412 | |
| Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. cve CVE-2026-69413 | |
| Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69415 | |
| Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. cve CVE-2026-69416 | |
| Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69418 | |
| Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally. cve CVE-2026-69420 | |
| Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69421 | |
| Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69422 | |
| Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69423 | |
| Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally. cve CVE-2026-69424 | |
| Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally. cve CVE-2026-69425 | |
| Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally. cve CVE-2026-69426 | |
| Out-of-bounds read in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69427 | |
| Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. cve CVE-2026-69428 | |
| Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network. cve CVE-2026-69429 | |
| Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69430 | |
| Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. cve CVE-2026-69431 | |
| Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69432 | |
| Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally. cve CVE-2026-69433 | |
| Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network. cve CVE-2026-69434 | |
| Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally. cve CVE-2026-69436 | |
| Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network. cve CVE-2026-69438 | |
| Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. cve CVE-2026-69439 | |
| Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. cve CVE-2026-69440 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. cve CVE-2026-69441 | |
| Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to disclose information over a network. cve CVE-2026-69443 | |
| Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. cve CVE-2026-69444 | |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally. cve CVE-2026-69445 | |
| Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69447 | |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. cve CVE-2026-69448 | |
| Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally. cve CVE-2026-69449 | |
| Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally. cve CVE-2026-69450 | |
| Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69451 | |
| Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. cve CVE-2026-69453 | |
| Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. cve CVE-2026-69455 | |
| Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. cve CVE-2026-69456 | |
| Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. cve CVE-2026-69457 | |
| Out-of-bounds read in Windows BitLocker allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69458 | |
| Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally. cve CVE-2026-69459 | |
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69460 | |
| Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. cve CVE-2026-69461 | |
| Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network. cve CVE-2026-69462 | |
| Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. cve CVE-2026-69463 | |
| Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally. cve CVE-2026-69466 | |
| Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. cve CVE-2026-69467 | |
| Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. cve CVE-2026-69468 | |
| Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack. cve CVE-2026-69469 | |