9288 entries matching microsoft — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-69843 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwo | CRITICAL | 10.0 | 48%ile | NVD | 2026-09-18 |
| USN-8729-2 | USN-8729-2: Linux kernel (Raspberry Pi Real-time) vulnerabilities | HIGH | 7.1 | — | Ubuntu | 2026-09-18 |
| CVE-2026-69865 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev | CRITICAL | 10.0 | 39%ile | NVD | 2026-09-17 |
| CVE-2026-77903 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a ne | CRITICAL | 9.0 | 32%ile | NVD | 2026-09-17 |
| CVE-2026-78501 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business | HIGH | 7.4 | 41%ile | NVD | 2026-09-17 |
| CVE-2026-55946 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut | MEDIUM | 6.1 | 34%ile | NVD | 2026-09-17 |
| CVE-2024-58385 | Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpo | CRITICAL | 9.3 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-40058 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability on | HIGH | 8.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-69486 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net | HIGH | 8.8 | 50%ile | NVD | 2026-09-15 |
| CVE-2026-85893 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | HIGH | 8.8 | 51%ile | NVD | 2026-09-15 |
| CVE-2026-58201 | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2 | HIGH | 8.7 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-91734 | Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execut | HIGH | 7.4 | 1%ile | NVD | 2026-09-15 |
| CVE-2026-92237 | Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2 | MEDIUM | 6.5 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-85892 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium- | HIGH | 7.8 | 9%ile | NVD | 2026-09-14 |
| CVE-2026-10556 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entr | MEDIUM | 5.3 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-77490 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) | MEDIUM | 6.1 | 23%ile | NVD | 2026-09-11 |
| CVE-2026-70352 | Azure AI Language Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-83711 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-83941 | Entra ID Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-66302 | Skype for Business Remote Code Execution Vulnerability | CRITICAL | 9.8 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-67631 | Microsoft SQL Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-67643 | Microsoft SQL Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-68839 | Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability | CRITICAL | 9.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69276 | Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69408 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | CRITICAL | 9.8 | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-69431 | Telnet Client Remote Code Execution Vulnerability | CRITICAL | 9.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69463 | Windows NTFS Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69491 | Microsoft DirectMusic Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69493 | Windows Event Logging Service Remote Code Execution Vulnerability | CRITICAL | 9.8 | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-69496 | Windows Compressed Folder Remote Code Execution Vulnerability | CRITICAL | 9.8 | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-69525 | Remote Desktop Services Remote Code Execution Vulnerability | CRITICAL | 9.8 | 62%ile | Microsoft | 2026-09-08 |
| CVE-2026-69579 | Windows Message Queuing Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-69586 | Microsoft Windows PDF Remote Code Execution Vulnerability | CRITICAL | 9.8 | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-69590 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-69595 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | CRITICAL | 9.8 | 63%ile | Microsoft | 2026-09-08 |
| CVE-2026-69715 | Windows Direct Show Remote Code Execution Vulnerability | CRITICAL | 9.8 | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-69730 | Windows DNS Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 63%ile | Microsoft | 2026-09-08 |
| CVE-2026-69768 | Windows RNDIS Remote Code Execution Vulnerability | CRITICAL | 9.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69769 | Windows HTTP Print Provider Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69819 | RPC Runtime Library Remote Code Execution Vulnerability | CRITICAL | 9.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69824 | Microsoft Standard XPS Remote Code Execution Vulnerability | CRITICAL | 9.8 | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-69829 | Windows Shell Remote Code Execution Vulnerability | CRITICAL | 9.8 | 62%ile | Microsoft | 2026-09-08 |
| CVE-2026-69845 | Windows DHCP Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69910 | Windows Hyper-V Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-70296 | Windows Imaging Component Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-72979 | Windows DHCP Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-72982 | Windows Netlogon Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-72983 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-73009 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-73010 | Microsoft Failover Cluster Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-73025 | Windows iSCSI Security Feature Bypass Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-77493 | Windows Graphics Component Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-78445 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | CRITICAL | 9.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-78509 | Microsoft Office Outlook Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-78510 | Microsoft Word Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-85504 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-85506 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipm | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-85507 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ip | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-85508 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-o | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-85509 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC retu | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-65669 | Microsoft SQL Server Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-81376 | Visual Studio Code Security Feature Bypass Vulnerability | CRITICAL | 9.6 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69356 | Microsoft Exchange Server Spoofing Vulnerability | CRITICAL | 9.3 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-80098 | Copilot Studio Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-62916 | Microsoft Entra ID Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-69641 | Microsoft Exchange Server Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-67378 | Microsoft SQL Server Remote Code Execution Vulnerability | CRITICAL | 9.0 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-67636 | Microsoft SQL Server Remote Code Execution Vulnerability | CRITICAL | 9.0 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-69854 | Spring Cloud Azure Elevation of Privilege Vulnerability | CRITICAL | 9.0 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-44950 | fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 | CRITICAL | 9.0 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-59679 | fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 | CRITICAL | 9.0 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-62706 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-62744 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-62895 | Azure Arc SQL Server Extension Elevation of Privilege Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-65772 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-66814 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-66818 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-66819 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-66820 | SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-67368 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-67370 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-67373 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-67380 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-67381 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-67384 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-67385 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-67388 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-67638 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-67639 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-67642 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-68775 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-68786 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-68828 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-69266 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 8.8 | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-69268 | Microsoft Office SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-69273 | Microsoft Office SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-69282 | Microsoft Office SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-69285 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-69291 | Windows Volume Manager Extension Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-69334 | Windows Volume Manager Extension Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69355 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69360 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69386 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69434 | Windows URL Moniker Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69439 | .NET and Visual Studio Elevation of Privilege Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-69442 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69461 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-69464 | Microsoft Office SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69465 | Microsoft Office SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69485 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69494 | Windows Event Logging Service Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69495 | Windows Event Logging Service Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69499 | Windows Imaging Component Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69511 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69518 | Windows Remote Desktop Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69522 | .NET and Visual Studio Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69529 | Microsoft Office Access Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-69547 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69551 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69556 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69598 | Windows iSCSI Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69601 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69603 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69614 | Microsoft Office Access Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69628 | Windows iSCSI Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69629 | Microsoft Office Outlook Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69632 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69649 | Raw Image Extension Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69669 | Windows Kernel Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69671 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69676 | Windows Kerberos Remote Code Execution Vulnerability | HIGH | 8.8 | 66%ile | Microsoft | 2026-09-08 |
| CVE-2026-69678 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69686 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69712 | Windows Key Distribution Center Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69716 | Microsoft Office SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69722 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69724 | Microsoft Office SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69729 | Windows Credential Providers Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69740 | Windows Hello Elevation of Privilege Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69742 | Microsoft Office Publisher Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69759 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69764 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69767 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69772 | Windows Network File System Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69778 | Microsoft Office Access Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69784 | Windows Hello Elevation of Privilege Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69797 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69860 | Windows Imaging Component Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-70203 | Windows Media Player Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-70351 | Microsoft WebP Image Extension Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-70586 | Windows Paint Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-71328 | .NET and Visual Studio Remote Code Execution Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-71336 | Windows Work Folder Service Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-71352 | Windows Remote Access Connection Manager Remote Code Execution Vulnerability | HIGH | 8.8 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-72933 | Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-72940 | Windows Schannel Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-72950 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-72959 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-72960 | Windows Media Player Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-72972 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-72973 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-72986 | Graphic Fonts Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-73006 | DirectWrite Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-73012 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-73013 | Windows Imaging Component Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-73016 | DirectWrite Remote Code Execution Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-73018 | Graphic Fonts Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-73023 | Windows Imaging Component Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-73028 | SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-77480 | SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-77481 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-77482 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-77483 | SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-77484 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-77486 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-77487 | SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-77495 | Windows Imaging Component Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-77504 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-77901 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-77906 | Visual Studio Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-77907 | Visual Studio Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-77908 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-78439 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-78442 | Windows OLE DB Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-78456 | SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-78462 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.8 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-78463 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-78504 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-78505 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-78507 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-78511 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-78512 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-78514 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-78517 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-78518 | Microsoft Office Excel Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-78519 | Microsoft Office Outlook Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-78521 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-78524 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-78525 | Microsoft Office Outlook Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-78526 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-80074 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-80077 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-80080 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-80081 | Microsoft Office PowerPoint Remote Code Execution Vulnerability | HIGH | 8.8 | 40%ile | Microsoft | 2026-09-08 |
| CVE-2026-80083 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.8 | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-80085 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 8.8 | 40%ile | Microsoft | 2026-09-08 |
| CVE-2026-80096 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-81352 | Web Media Extensions Remote Code Execution Vulnerability | HIGH | 8.8 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-81385 | Microsoft Office Publisher Remote Code Execution Vulnerability | HIGH | 8.8 | 62%ile | Microsoft | 2026-09-08 |
| CVE-2026-81952 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-81955 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-83992 | Windows Imaging Component Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-83996 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 8.8 | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-83998 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-85877 | Windows Print Spooler Remote Code Execution Vulnerability | HIGH | 8.8 | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-87766 | Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup | HIGH | 8.8 | 4%ile | Microsoft | 2026-09-08 |
| CVE-2026-72649 | Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution | HIGH | 8.8 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-0799 | OOBR and OOBW in libpcap before 1.10.7 | HIGH | 8.7 | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-80097 | Microsoft Authenticator Elevation of Privilege Vulnerability | HIGH | 8.6 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-65818 | Power Automate Elevation of Privilege Vulnerability | HIGH | 8.5 | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-67379 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-69857 | Azure Cosmos DB Spoofing Vulnerability | HIGH | 8.5 | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-70178 | Microsoft Fabric Elevation of Privilege Vulnerability | HIGH | 8.5 | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-89638 | smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions | HIGH | 8.4 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-69479 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 8.4 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69638 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 8.4 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-77503 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 8.4 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69646 | Skype for Business Spoofing Vulnerability | HIGH | 8.3 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69820 | Windows Hello Elevation of Privilege Vulnerability | HIGH | 8.2 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69846 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | HIGH | 8.2 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69874 | Windows ALPC Elevation of Privilege Vulnerability | HIGH | 8.2 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-69906 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | HIGH | 8.2 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-72958 | Windows Credential Guard Elevation of Privilege Vulnerability | HIGH | 8.2 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-72961 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 8.2 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-72962 | Windows USB Video Driver Elevation of Privilege Vulnerability | HIGH | 8.2 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-81354 | Windows Hello Elevation of Privilege Vulnerability | HIGH | 8.2 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-81356 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.2 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-81357 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.2 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-81378 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.2 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-81379 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.2 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-83939 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | HIGH | 8.2 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-18329 | NGINX ngx_http_js_module vulnerability | HIGH | 8.2 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-86145 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursiv | HIGH | 8.2 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-6485 | UEFI BIOS embedded Shell can be used to bypass Secure Boot | HIGH | 8.2 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-82209 | domain-scoped PSL domain cookie | HIGH | 8.2 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-89952 | mtd: rawnand: validate ONFI extended parameter page sections | HIGH | 8.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-47297 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.1 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-55007 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH | 8.1 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-69325 | Microsoft JScript Remote Code Execution Vulnerability | HIGH | 8.1 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69380 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69438 | Microsoft JScript Remote Code Execution Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69510 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 8.1 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-69524 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69530 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | HIGH | 8.1 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-69546 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69620 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69680 | Windows DNS Spoofing Vulnerability | HIGH | 8.1 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69732 | Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69782 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.1 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-69786 | Windows Text Shaping Remote Code Execution Vulnerability | HIGH | 8.1 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-69813 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.1 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69827 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.1 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-69858 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.1 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-69989 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-70342 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 8.1 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-70563 | Windows Shell Spoofing Vulnerability | HIGH | 8.1 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-72936 | Windows SMB Client Remote Code Execution Vulnerability | HIGH | 8.1 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-72981 | IP Helper Remote Code Execution Vulnerability | HIGH | 8.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-72987 | Windows DNS Remote Code Execution Vulnerability | HIGH | 8.1 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-77505 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-78444 | Microsoft Failover Cluster Remote Code Execution Vulnerability | HIGH | 8.1 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-78449 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | HIGH | 8.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-78450 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | HIGH | 8.1 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-83997 | Windows Message Queuing Remote Code Execution Vulnerability | HIGH | 8.1 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-78689 | NGINX ngx_http_js_module vulnerablility | HIGH | 8.1 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-80792 | ipv6: fix use-after-free in ip6_finish_output2() | HIGH | 8.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80798 | nfc: llcp: reject PDUs shorter than the LLCP header | HIGH | 8.1 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-80799 | nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers | HIGH | 8.1 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-80800 | nfc: llcp: bound the connect_sn TLV walk to the skb | HIGH | 8.1 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-80803 | nfc: digital: clamp SENSF_RES length to the destination buffer | HIGH | 8.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80823 | nfc: st21nfca: validate ATR_REQ length against the received frame | HIGH | 8.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-68827 | Windows GDI+ Elevation of Privilege Vulnerability | HIGH | 8.0 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-68834 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 8.0 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-68838 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 8.0 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-68876 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | HIGH | 8.0 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-68878 | Windows Fast FAT Driver Elevation of Privilege Vulnerability | HIGH | 8.0 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-68880 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.0 | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-68894 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 8.0 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-69271 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69301 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.0 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69322 | Microsoft Windows Search Component Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69332 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69346 | Windows Print Spooler Components Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69365 | Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability | HIGH | 8.0 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-69371 | Windows Overlay Filter Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69412 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 8.0 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-69418 | Volume Manager Driver Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69423 | Windows USB Video Driver Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69427 | Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69458 | Windows BitLocker Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69462 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69481 | Windows Enterprise App Management Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69503 | Windows USB Driver Elevation of Privilege Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69505 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69512 | Windows Spaceport.sys Elevation of Privilege Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69619 | Windows exFAT File System Elevation of Privilege Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69623 | Windows HTTP Print Provider Remote Code Execution Vulnerability | HIGH | 8.0 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69625 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | HIGH | 8.0 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-69643 | Windows Spaceport.sys Elevation of Privilege Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69681 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | HIGH | 8.0 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69689 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69714 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 8.0 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69717 | Windows Group Policy Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69727 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69762 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69773 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69777 | Windows DHCP Client Elevation of Privilege Vulnerability | HIGH | 8.0 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-69807 | PowerShell Elevation of Privilege Vulnerability | HIGH | 8.0 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69826 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 8.0 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69847 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 8.0 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-69875 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69876 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 8.0 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-83948 | Microsoft Azure CLI Remote Code Execution Vulnerability | HIGH | 8.0 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-86140 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. | HIGH | 8.0 | 4%ile | Microsoft | 2026-09-08 |
| CVE-2026-78408 | Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority | HIGH | 7.9 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-89853 | scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump | HIGH | 7.8 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89864 | scsi: qla2xxx: Bound i2c->length in I2C bsg handlers | HIGH | 7.8 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89956 | s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects | HIGH | 7.8 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-56172 | Windows VHD miniport driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-56177 | Windows Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-56198 | Microsoft Trace Data Helper Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-58599 | HEVC Video Extensions Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-58600 | HEVC Video Extensions Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-58611 | Xbox Gaming Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-62697 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-62804 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-62810 | Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-68787 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-68832 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-68841 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-68844 | Windows Storage Spaces Controller Remote Code Execution Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-68845 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-68848 | Windows Print Spooler Components Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-68850 | Microsoft Account Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-68875 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-68877 | Windows Storage Spaces Controller Remote Code Execution Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-68885 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-68888 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-68890 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-68892 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-68896 | Microsoft Windows Search Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-69265 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-69269 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69270 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-69277 | Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-69283 | Windows CD-ROM Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69284 | Windows DCOM Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69289 | Windows Setup Files Cleanup Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-69290 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69293 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-69295 | Windows USB Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69298 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69307 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69312 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69323 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69324 | Windows Performance Monitor Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69328 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69348 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69352 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69359 | Active Directory Domain Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69368 | Windows Overlay Filter Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69377 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-69389 | Windows Storage Management Provider Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69391 | Windows Broker Infrastructure Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-69392 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69407 | Volume Manager Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69420 | Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69421 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69424 | Windows Distributed File System (DFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69426 | Windows VOLSNAP.SYS Remote Code Execution Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69432 | Volume Manager Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69433 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69436 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69444 | Microsoft Windows Speech Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69445 | Windows Compressed Folder Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-69447 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69450 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69455 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69456 | Microsoft Windows Speech Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69459 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69467 | Microsoft Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-69475 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69476 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-69478 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69480 | Windows Partition Management Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69489 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69508 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69509 | Role: Windows Fax Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69513 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69528 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-69532 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69534 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-69535 | Windows Spaceport.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69538 | Windows Spaceport.sys Remote Code Execution Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69541 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69542 | Windows Camera Frame Server Monitor Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69544 | Windows SMB Client Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69561 | Windows CD-ROM Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69571 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69576 | Graphic Fonts Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69580 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69582 | Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69583 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69584 | Windows USB Video Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69585 | Microsoft Windows Search Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-69589 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69592 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69593 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69594 | Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-69604 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69608 | Microsoft Windows Search Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69612 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-69685 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69687 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69691 | Windows Spaceport.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69707 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69709 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69720 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69725 | Windows Hello Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69731 | HID Class Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69738 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69758 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69785 | Windows Smart Card Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69787 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69790 | Windows Credential Providers Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69799 | Windows Hello Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-69801 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69821 | Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69822 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69841 | Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69844 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69864 | Windows Hello Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-69900 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-69907 | Windows Enterprise App Management Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-69921 | Windows Print Spooler Components Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-70289 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-70334 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-70564 | Windows Print Spooler Components Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-70569 | Windows Spaceport.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-70572 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-70574 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-70581 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-70583 | Windows Core Messaging Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-70584 | Windows Core Messaging Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-71334 | Windows NFS Portmapper Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-71337 | Windows Storage Management Provider Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-71343 | Windows Remote Access Connection Manager Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-71345 | Windows Spaceport.sys Remote Code Execution Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-72929 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-72941 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-72944 | Role: Windows Fax Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-72946 | Microsoft Storage Port Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-72953 | Windows USB Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-72957 | Windows Deployment Services Remote Code Execution Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-72965 | Windows WebClient Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-72967 | Windows Network Connection Broker Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-72988 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-72990 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-72991 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-72992 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-72993 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-72994 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-72995 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-72996 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-72997 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-73000 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-73001 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-73002 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-73007 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-73011 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-73014 | Data Sharing Service Client Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-73015 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-73020 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-73021 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-73024 | Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-73026 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-77489 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-77500 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-77904 | Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-78447 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-78448 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-80075 | Windows Work Folders Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-81353 | HEIF Image Extensions Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-81386 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-81388 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-81396 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81397 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81398 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-81947 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-81948 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81949 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81950 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81951 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81953 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81954 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-81956 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81957 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81959 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81960 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-81963 | Windows Update Stack Elevation of Privilege Vulnerability | HIGH | 7.8 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-83498 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-83942 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-83952 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-83954 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83955 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-83967 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83968 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83969 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-83970 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83971 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83972 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83973 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83974 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-83975 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83976 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-83977 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83978 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83979 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83980 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83981 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83982 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83983 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83985 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83986 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83987 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83988 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-83990 | Microsoft Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-83995 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-84000 | Microsoft Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-76642 | util-linux libmount Privilege Escalation via Failed Mount Helper | HIGH | 7.8 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-78410 | Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection | HIGH | 7.8 | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-80909 | drm/amdgpu: Reject UVD message with invalid number of h265 refs | HIGH | 7.8 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-84838 | Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() | HIGH | 7.8 | 62%ile | Microsoft | 2026-09-08 |
| CVE-2026-77909 | Azure CycleCloud Information Disclosure Vulnerability | HIGH | 7.7 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-85197 | Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload | HIGH | 7.6 | 13%ile | Microsoft | 2026-09-08 |
| CVE-2025-70873 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier al | HIGH | 7.5 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-57098 | Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-57099 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-62759 | Windows Netlogon Spoofing Vulnerability | HIGH | 7.5 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-62813 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-66304 | Skype for Business Information Disclosure Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-66307 | Skype for Business and Lync Denial of Service Vulnerability | HIGH | 7.5 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-67376 | Microsoft SQL Server Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-68887 | Windows Message Queuing Queue Manager Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69329 | BranchCache Denial of Service Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-09-08 |
| CVE-2026-69342 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-69378 | Microsoft Exchange Server Denial of Service Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-09-08 |
| CVE-2026-69397 | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-69428 | Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-69429 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-69443 | Windows Device Health Attestation (DHA) Information Disclosure Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-09-08 |
| CVE-2026-69514 | Remote Desktop Services Remote Code Execution Vulnerability | HIGH | 7.5 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69539 | Remote Desktop Services Remote Code Execution Vulnerability | HIGH | 7.5 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69587 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | HIGH | 7.5 | 67%ile | Microsoft | 2026-09-08 |
| CVE-2026-69588 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.5 | 67%ile | Microsoft | 2026-09-08 |
| CVE-2026-69599 | Remote Desktop Services Remote Code Execution Vulnerability | HIGH | 7.5 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69607 | Windows Deployment Services Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-69631 | Windows DNS Denial of Service Vulnerability | HIGH | 7.5 | 67%ile | Microsoft | 2026-09-08 |
| CVE-2026-69710 | Windows Hello Elevation of Privilege Vulnerability | HIGH | 7.5 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69744 | Windows Kerberos Denial of Service Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-69760 | Windows Kerberos Denial of Service Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-69793 | Windows TCP/IP Security Feature Bypass Vulnerability | HIGH | 7.5 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69804 | Microsoft Office SharePoint Remote Code Execution Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-69805 | .NET Elevation of Privilege Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-69809 | Windows Active Directory Domain Services Denial of Service Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-09-08 |
| CVE-2026-69852 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.5 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-69881 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-09-08 |
| CVE-2026-69890 | Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability | HIGH | 7.5 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-70065 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-09-08 |
| CVE-2026-70570 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.5 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-70579 | Windows Mobile Broadband Information Disclosure Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-09-08 |
| CVE-2026-70587 | Windows Remote Desktop Protocol Information Disclosure Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-71330 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-72928 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-72932 | Windows Message Queuing Queue Manager Information Disclosure Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-09-08 |
| CVE-2026-72943 | Windows Deployment Services Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-72949 | Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-72954 | Windows Deployment Services Remote Code Execution Vulnerability | HIGH | 7.5 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-72989 | Windows Failover Cluster Information Disclosure Vulnerability | HIGH | 7.5 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-73017 | Graphics Kernel Remote Code Execution Vulnerability | HIGH | 7.5 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-77494 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-09-08 |
| CVE-2026-77498 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-77499 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-77501 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-77502 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-77886 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-77888 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-77889 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-77890 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-77893 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-77895 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-77898 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-09-08 |
| CVE-2026-81355 | Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability | HIGH | 7.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-83989 | Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-84001 | Windows Key Distribution Center Denial of Service Vulnerability | HIGH | 7.5 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-14957 | FIPS mode assertion failure via malicious CERT payload | HIGH | 7.5 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-33630 | c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() o | HIGH | 7.5 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-56855 | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | HIGH | 7.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-78130 | strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser. | HIGH | 7.5 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-78132 | strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax | HIGH | 7.5 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-78133 | libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling. | HIGH | 7.5 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-78222 | NGINX ngx_http_js_module vulnerability | HIGH | 7.5 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-78662 | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh | HIGH | 7.5 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-80229 | OpenSSL provider use-after-free | HIGH | 7.5 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-80788 | nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations | HIGH | 7.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80789 | nvmet-tcp: bound SGL data length before allocating command buffers | HIGH | 7.5 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-84304 | gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | HIGH | 7.5 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-85505 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipm | HIGH | 7.5 | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-87776 | compression vulnerable to Denial of Service via memory leak on premature response close | HIGH | 7.5 | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-80791 | nvmet-auth: zero the AUTH_RECEIVE response buffer | HIGH | 7.5 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-85393 | node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Padding | HIGH | 7.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-85396 | rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix | HIGH | 7.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-62906 | Microsoft Discovery Studio Information Disclosure Vulnerability | HIGH | 7.4 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69347 | Windows Fast FAT Driver Remote Code Execution Vulnerability | HIGH | 7.4 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-78461 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.4 | 62%ile | Microsoft | 2026-09-08 |
| CVE-2026-81383 | Visual Studio Code Information Disclosure Vulnerability | HIGH | 7.4 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-84003 | Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability | HIGH | 7.4 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-78254 | Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write | HIGH | 7.4 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-80837 | netfilter: nf_tables: don't queue packet path object notifications | HIGH | 7.4 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80840 | ipv6: seg6: clear IPv4 control block on IPIP decapsulation | HIGH | 7.4 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-85091 | zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate | HIGH | 7.4 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-86098 | ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape | HIGH | 7.4 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-89161 | In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect | HIGH | 7.4 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | HIGH | 7.4 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-69402 | Microsoft Office SharePoint Spoofing Vulnerability | HIGH | 7.3 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-69417 | Microsoft Office SharePoint Spoofing Vulnerability | HIGH | 7.3 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-69477 | Microsoft Office Access Remote Code Execution Vulnerability | HIGH | 7.3 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-81349 | Azure HDInsight Ambari Elevation of Privilege Vulnerability | HIGH | 7.2 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-89694 | nfsd: check client ownership when cancelling a copy-notify stateid | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89785 | fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init | HIGH | 7.1 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89787 | ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() | HIGH | 7.1 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89797 | power: supply: ab8500_fg: fix use-after-free on remove | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89817 | drm/gud: NUL-terminate TV mode names read from the device | HIGH | 7.1 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89837 | f2fs: fix dentry folio leak in find_in_level | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89839 | f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89842 | scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89843 | scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89845 | scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89852 | scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89858 | scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89859 | scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak | HIGH | 7.1 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-89862 | scsi: qla2xxx: Fix BSG job leak on validate flash image error path | HIGH | 7.1 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-89874 | media: v4l2-async: avoid deleting unlinked ASC entry on link error | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89878 | media: s2255: check firmware size before reading trailing marker | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89884 | media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89891 | media: em28xx: fix use-after-free of dev_next->devlist on disconnect | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89892 | media: em28xx: defer audio-only extension registration | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89923 | KVM: s390: Free guest debug data on vcpu destroy | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89934 | iio: light: ltrf216a: fix runtime PM reference leak in error path | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89939 | iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable | HIGH | 7.1 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89948 | batman-adv: bla: fix freeing of claims on meshif deletion | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89962 | powerpc/kexec_file: Prevent kexec range truncation | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89984 | perf/x86/intel: Fix kernel address leakages in LBR stack | HIGH | 7.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-90031 | usb-storage: ene_ub6250: fix race between scan work and probe | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-90033 | ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() | HIGH | 7.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-66305 | Skype for Business Spoofing Vulnerability | HIGH | 7.1 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-68835 | Windows Print Spooler Components Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-68846 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.1 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-68889 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.1 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-68893 | Remote Desktop Licensing Service Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69272 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.1 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69274 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.1 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-69296 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69305 | Microsoft Windows Search Component Elevation of Privilege Vulnerability | HIGH | 7.1 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-69313 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69314 | Windows Device Association Broker Service Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69336 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69337 | Windows Registry Elevation of Privilege Vulnerability | HIGH | 7.1 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69338 | Remote Desktop Gateway Service Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69340 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69357 | Windows NDIS Elevation of Privilege Vulnerability | HIGH | 7.1 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69358 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69364 | Windows Print Spooler Components Elevation of Privilege Vulnerability | HIGH | 7.1 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-69366 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.1 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-69384 | Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability | HIGH | 7.1 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-69396 | Windows NDIS Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69451 | Windows Management Instrumentation Elevation of Privilege Vulnerability | HIGH | 7.1 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69460 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69482 | Windows Error Reporting Tampering Vulnerability | HIGH | 7.1 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69536 | Remote Desktop Services Remote Code Execution Vulnerability | HIGH | 7.1 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-69553 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.1 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-69597 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.1 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-69602 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | HIGH | 7.1 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-69688 | Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability | HIGH | 7.1 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-69706 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.1 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-69757 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.1 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69761 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-69775 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.1 | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-78134 | strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a | HIGH | 7.1 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-80732 | ata: pata_sl82c105: fix bridge revision use-after-free | HIGH | 7.1 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80737 | serial: amba-pl011: synchronize DMA teardown | HIGH | 7.1 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-86090 | ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers | HIGH | 7.1 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-86091 | ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler | HIGH | 7.1 | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-50349 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-62694 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-68824 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-68825 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-68837 | Windows File History Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-68840 | Windows USB Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-68847 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-68884 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-68897 | Microsoft Standard XPS Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69275 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-69279 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69280 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69281 | Windows License Manager Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69287 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69292 | Remote Desktop Gateway Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69299 | Microsoft COM for Windows Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-69300 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69309 | Windows Print Spooler Components Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69310 | Windows DNS Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-69311 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69319 | Windows USB Video Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69331 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69333 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69335 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69341 | Windows Image Acquisition Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69362 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69379 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-69383 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69385 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69388 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69394 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69398 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69401 | Audio Video Control Transport Protocol Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69404 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69410 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69413 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69422 | Windows USB Video Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69430 | Windows Embedded Mode Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69440 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69441 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69448 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69466 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-69468 | Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-69470 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-69472 | Windows Devices Human Interface Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-69473 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-69488 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69492 | Windows Partition Management Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69498 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-69500 | Windows Image Acquisition Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69501 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-69516 | Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69517 | Windows Wireless Networking Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69540 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69549 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | HIGH | 7.0 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-69560 | Windows Work Folder Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69563 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69564 | Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69567 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69573 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69574 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69575 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69578 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-69581 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69600 | Microsoft Windows Search Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-69605 | Microsoft Install Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-69606 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69610 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69611 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69613 | Windows Image Acquisition Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69617 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69621 | Role: Windows Fax Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69630 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69645 | Windows Message Queuing Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69648 | Windows Notification Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69652 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69654 | Windows Accounts Control Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69682 | Windows Host Guardian Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-69692 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69693 | Windows Device Association Broker Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69694 | Windows IP Address Management (IPAM) Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 76%ile | Microsoft | 2026-09-08 |
| CVE-2026-69708 | Windows Web Platform Storage Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69711 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69735 | Windows Broadcast DVR User Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69779 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69791 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-69806 | .NET Elevation of Privilege Vulnerability | HIGH | 7.0 | 78%ile | Microsoft | 2026-09-08 |
| CVE-2026-69814 | Windows Credential Providers Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69816 | Windows Accounts Control Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69817 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69818 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69834 | Windows ALPC Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69838 | Windows Print Spooler Components Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69859 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-69866 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69889 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69891 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69896 | Windows Error Reporting Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69911 | Microsoft Windows Search Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-70283 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-70562 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-70565 | Windows AF_UNIX Socket Provider Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-70567 | Windows Display Enhancement Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-70568 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-70573 | Windows Biometric Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-70577 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-70578 | Windows Credential Guard Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-70585 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-71332 | Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-71333 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-71340 | Windows File History Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-71342 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-71351 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-71353 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-72926 | Windows Internet Connection Sharing (ICS) Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-72930 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-72952 | Windows Spaceport.sys Remote Code Execution Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-72963 | Windows Modern Execution Server Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-73003 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-73005 | Windows Authentication Methods Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-73022 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-77485 | SQL Server Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-77894 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-77897 | Microsoft Power Automate Desktop Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-77899 | Windows Security Center Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-77905 | Windows Management Instrumentation Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-78457 | Windows Security Health Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-78464 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-80093 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-81389 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.0 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-83940 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-83999 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-85360 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-71220 | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit | HIGH | 7.0 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-71221 | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta | HIGH | 7.0 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-84233 | Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames | HIGH | 7.0 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-86138 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | MEDIUM | 6.9 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-86142 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer l | MEDIUM | 6.9 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-86143 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to r | MEDIUM | 6.9 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-86139 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | MEDIUM | 6.9 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-65812 | Microsoft Teams for Android Information Disclosure Vulnerability | MEDIUM | 6.8 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-68833 | Windows NTFS Remote Code Execution Vulnerability | MEDIUM | 6.8 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-69415 | Windows DHCP Server Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69490 | Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-69566 | Windows NTFS Remote Code Execution Vulnerability | MEDIUM | 6.8 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-71329 | Windows NTFS Remote Code Execution Vulnerability | MEDIUM | 6.8 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-71348 | Windows Spaceport.sys Remote Code Execution Vulnerability | MEDIUM | 6.8 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-71349 | Windows Spaceport.sys Remote Code Execution Vulnerability | MEDIUM | 6.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-71350 | Windows Spaceport.sys Remote Code Execution Vulnerability | MEDIUM | 6.8 | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-72985 | Volume Shadow Copy Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-72999 | Windows USB Hub Driver Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-77892 | Windows Boot Manager Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-78451 | Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-69350 | Windows Overlay Filter Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-69373 | Windows Overlay Filter Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-69449 | Windows BitLocker Remote Code Execution Vulnerability | MEDIUM | 6.7 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-71339 | Windows Installer Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-72927 | Winsock Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-72935 | Windows NTFS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-72948 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-69469 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability | MEDIUM | 6.6 | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-90015 | xhci: fix lost bounce buffers on TDs spanning several ring segments | MEDIUM | 6.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-58649 | .NET Information Disclosure Vulnerability | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-62762 | Windows Active Directory Domain Services Denial of Service Vulnerability | MEDIUM | 6.5 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-62801 | Microsoft PowerShell Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-63523 | Skype for Business Spoofing Vulnerability | MEDIUM | 6.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-64918 | Microsoft Office Spoofing Vulnerability | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-09-08 |
| CVE-2026-66303 | Skype for Business and Lync Denial of Service Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-66306 | Skype for Business Information Disclosure Vulnerability | MEDIUM | 6.5 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-66308 | Skype for Business and Lync Denial of Service Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-66816 | Microsoft SQL Server Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-67369 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-67383 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-67386 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-67389 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-67390 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-67393 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-67624 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-67629 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-67630 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-67633 | Microsoft SQL Server Denial of Service Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-67641 | Microsoft SQL Server Denial of Service Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-67645 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-67648 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-68776 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-68777 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-68778 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-68779 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-09-08 |
| CVE-2026-68780 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-68781 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-68784 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-68898 | Windows iSCSI Denial of Service Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-69267 | Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability | MEDIUM | 6.5 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-69297 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-69361 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69374 | Windows SMB Server Denial of Service Vulnerability | MEDIUM | 6.5 | 64%ile | Microsoft | 2026-09-08 |
| CVE-2026-69375 | Microsoft Exchange Server Tampering Vulnerability | MEDIUM | 6.5 | 47%ile | Microsoft | 2026-09-08 |
| CVE-2026-69395 | Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69409 | Microsoft Office SharePoint Information Disclosure Vulnerability | MEDIUM | 6.5 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-69497 | Windows DHCP Server Denial of Service Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-69562 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-69624 | Active Directory Certificate Services (AD CS) Tampering Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-69626 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69636 | Microsoft Office SharePoint Information Disclosure Vulnerability | MEDIUM | 6.5 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-69642 | Skype for Business Spoofing Vulnerability | MEDIUM | 6.5 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-69683 | Microsoft Office SharePoint Information Disclosure Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69719 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69734 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69739 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69781 | Windows DHCP Client Denial of Service Vulnerability | MEDIUM | 6.5 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-69839 | Windows iSCSI Target Service Denial of Service Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-70019 | Windows Compressed Folder Information Disclosure Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2026-09-08 |
| CVE-2026-72938 | Microsoft Office PowerPoint Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-72939 | Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-09-08 |
| CVE-2026-72942 | Windows Spaceport.sys Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-72956 | Microsoft Office PowerPoint Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-72974 | Microsoft Office Excel Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-72975 | Microsoft Office PowerPoint Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-72977 | Microsoft Office PowerPoint Information Disclosure Vulnerability | MEDIUM | 6.5 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-73029 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-77896 | Windows Remote Desktop Client Denial of Service Vulnerability | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-77911 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-78441 | Windows OLE DB Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-78453 | Microsoft Windows SCSI Class System File Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-78502 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-78503 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-78515 | Microsoft Office Excel Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-78520 | Microsoft Office Outlook Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-09-08 |
| CVE-2026-78522 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-80073 | Microsoft Office Outlook Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-80076 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-80078 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-80079 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-80082 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-80084 | Microsoft Office Outlook Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-80086 | Microsoft Office PowerPoint Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-80087 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-80088 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-80089 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-80090 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-80091 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-81377 | Visual Studio Code Tampering Vulnerability | MEDIUM | 6.5 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-81381 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-19931 | Negotiate ambient user conn reuse | MEDIUM | 6.5 | 66%ile | Microsoft | 2026-09-08 |
| CVE-2026-80819 | Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept | MEDIUM | 6.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-85769 | Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-89158 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. | MEDIUM | 6.5 | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-89625 | HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind | MEDIUM | 6.4 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-69878 | Windows DHCP Server Remote Code Execution Vulnerability | MEDIUM | 6.4 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-70582 | Windows Management Instrumentation Elevation of Privilege Vulnerability | MEDIUM | 6.4 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-71338 | Windows Failover Cluster Elevation of Privilege Vulnerability | MEDIUM | 6.4 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-72947 | Windows File History Service Elevation of Privilege Vulnerability | MEDIUM | 6.4 | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-77887 | Windows DHCP Server Remote Code Execution Vulnerability | MEDIUM | 6.4 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-77891 | Windows DHCP Server Remote Code Execution Vulnerability | MEDIUM | 6.4 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-80757 | selinux: reject a class permission count below its inherited common | MEDIUM | 6.4 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80785 | fbdev: serialize mode sysfs access with lock_fb_info() | MEDIUM | 6.3 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-80831 | crypto: mxs-dcp - fix source scatterlist length access | MEDIUM | 6.3 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-18090 | Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block | MEDIUM | 6.1 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80755 | selinux: reject a permission value exceeding the class permission count | MEDIUM | 6.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80844 | xfrm: ah6: validate routing header segments_left | MEDIUM | 6.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80852 | tls: device: fix out-of-bounds write in tls_append_frag() | MEDIUM | 6.0 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80807 | nilfs2: reject invalid block index in GC ioctl | MEDIUM | 6.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89531 | svcrdma: Reject connection when transport allocation fails | MEDIUM | 5.9 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-69304 | ASP.NET Core Denial of Service Vulnerability | MEDIUM | 5.9 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-69382 | Microsoft Exchange Server Information Disclosure Vulnerability | MEDIUM | 5.9 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-69803 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 5.9 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69929 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 5.9 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69930 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 5.9 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-70091 | Windows DNS Denial of Service Vulnerability | MEDIUM | 5.9 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-70124 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 5.9 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-72978 | Active Directory Federation Services (AD FS) Denial of Service Vulnerability | MEDIUM | 5.9 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-78523 | Windows DNS Server Denial of Service Vulnerability | MEDIUM | 5.9 | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-18149 | undici vulnerable to Denial of Service via orphaned RetryHandler response body | MEDIUM | 5.9 | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-18924 | HTTP/2 server push UAF | MEDIUM | 5.9 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-78129 | strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption. | MEDIUM | 5.9 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-80783 | HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() | MEDIUM | 5.9 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80829 | ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() | MEDIUM | 5.9 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80904 | net/tls: Fail tls_sw_splice_read() after a failed async decrypt | MEDIUM | 5.9 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-85534 | Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during d | MEDIUM | 5.9 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-80780 | HID: pidff: fix OOB write when hid->inputs is empty | MEDIUM | 5.9 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80802 | nfc: fdp: bound the device-reported read length and fix an skb leak | MEDIUM | 5.9 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80846 | xfrm: drop ESP-in-TCP packets with no ingress device | MEDIUM | 5.9 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80848 | xfrm: espintcp: fix UAF during close | MEDIUM | 5.9 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80891 | KVM: s390: pci: Validate AIBV and AISB before pinning guest pages | MEDIUM | 5.9 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-69559 | Microsoft Teams for Android Information Disclosure Vulnerability | MEDIUM | 5.8 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-89740 | serial: imx: serialize imx_uart_ports[] lifetime | MEDIUM | 5.7 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-68874 | Windows Program Compatibility Assistant Service Information Disclosure Vulnerability | MEDIUM | 5.7 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69317 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 5.7 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69349 | Windows Management Instrumentation Information Disclosure Vulnerability | MEDIUM | 5.7 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69372 | Windows Network File System Denial of Service Vulnerability | MEDIUM | 5.7 | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-69393 | Windows Spaceport.sys Information Disclosure Vulnerability | MEDIUM | 5.7 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69405 | Windows DHCP Server Denial of Service Vulnerability | MEDIUM | 5.7 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-69416 | Windows DHCP Server Denial of Service Vulnerability | MEDIUM | 5.7 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-69507 | Microsoft Windows Search Component Information Disclosure Vulnerability | MEDIUM | 5.7 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-69552 | Windows Print Spooler Components Information Disclosure Vulnerability | MEDIUM | 5.7 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69569 | Windows Print Spooler Components Denial of Service Vulnerability | MEDIUM | 5.7 | 57%ile | Microsoft | 2026-09-08 |
| CVE-2026-69572 | Windows SMB Client Information Disclosure Vulnerability | MEDIUM | 5.7 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69591 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.7 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-69637 | Windows DHCP Server Denial of Service Vulnerability | MEDIUM | 5.7 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69679 | Windows DHCP Server Denial of Service Vulnerability | MEDIUM | 5.7 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-69723 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.7 | 60%ile | Microsoft | 2026-09-08 |
| CVE-2026-80731 | net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header | MEDIUM | 5.7 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80841 | net/packet: defer vmalloc TX_RING free until skbs finish | MEDIUM | 5.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80842 | net: bridge: mcast: fix use-after-free of a master VLAN's multicast context | MEDIUM | 5.7 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-89157 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a | MEDIUM | 5.7 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80790 | nvmet-fc: fix invalid free in LS IOD error path | MEDIUM | 5.7 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80851 | gtp: serialize PDP context updates | MEDIUM | 5.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80854 | usb: gadget: f_tcm: keep port count until LUN teardown completes | MEDIUM | 5.7 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-69832 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.6 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-78135 | libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CH | MEDIUM | 5.6 | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-86144 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This ha | MEDIUM | 5.6 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80768 | HID: ft260: fix stack-use-after-return write in I2C read race | MEDIUM | 5.6 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-89604 | efivarfs: Rate limit statfs() handler | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89784 | SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89796 | mm/damon/core: avoid infinite kdamond_merge_regions() internal loop | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89800 | drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89802 | drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89809 | drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-89812 | drm/amdgpu: force complete the MES ring fences on reset | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-89813 | drm/amdgpu: force complete the KIQ ring fences on reset | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-89816 | drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89821 | drm/amd/display: avoid divide-by-zero in __is_lut_linear() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89822 | drm/i915: Guard against NULL driver_data in i915_pci_probe() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89833 | f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89850 | scsi: qla2xxx: Don't query firmware state while chip is down | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89865 | scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89871 | media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89872 | media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89879 | media: s2255: bound JPEG frame size before copying into the buffer | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89881 | media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89896 | media: cedrus: fix memory leak in cedrus_init_ctrls() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89900 | media: cec: core: Fix kmemleak due to missed rc_free_device() call | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89901 | media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89924 | KVM: s390: Fix old_data leak in guest debug error path | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89933 | iio: pressure: dps310: fix NULL pointer dereference on ACPI probe | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89937 | iio: chemical: sgp30: Handle IAQ thread creation failure | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89945 | ASoC: cs35l34: drain threaded IRQ before runtime suspend | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89946 | ASoC: cs35l33: drain threaded IRQ before runtime suspend | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89953 | mtd: mtdoops: free page bitmap when the backing MTD is removed | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89955 | s390/vfio-ap: Fix NULL deref in status_show() during queue probe | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89975 | nvme-fabrics: fix DHCHAP secret leak on parse failure | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89982 | i2c: mux: Fix channel node leak on adapter add failure | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89987 | mm/huge_memory: transfer the pmd dirty bit to the folio on zap | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89989 | ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-89993 | dmaengine: dw-edma: Initialize IRQ data before requesting IRQs | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-90019 | usb: gadget: fix null pointer dereference in usb_put_function_instance() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-90020 | USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-90023 | usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-90035 | drm/amd/display: fix division by zero in get_estimated_bw() | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-68830 | Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-68831 | Windows Defender Firewall Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-68842 | Windows MIDI Service Module Information Disclosure Vulnerability | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-68843 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-68851 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-68852 | Microsoft Account Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-68873 | Windows Program Compatibility Assistant Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-68881 | Microsoft Standard XPS Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-68886 | Windows Network Connection Broker Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-68895 | Internet Storage Name Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-69286 | Windows USB Audio Class Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69288 | Windows GDI+ Information Disclosure Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-69294 | Microsoft COM for Windows Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69303 | Push Message Routing Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69308 | Microsoft Standard XPS Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69315 | Windows License Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-69318 | Windows Imaging Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69321 | Windows Power Dependency Coordinator Tampering Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-69339 | Windows MIDI Service Module Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-69343 | Windows Overlay Filter Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69344 | Windows Print Spooler Components Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69345 | Microsoft Standard XPS Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69351 | Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-69353 | Windows Text Shaping Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69367 | Microsoft Standard XPS Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69369 | Windows DNS Information Disclosure Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-69376 | Microsoft Standard XPS Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69390 | Windows Spaceport.sys Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69403 | Windows SMB Server Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-69406 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-69453 | Microsoft Windows Search Component Tampering Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69457 | Windows USB Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69504 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69527 | Windows USB Mass Storage Class Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69531 | Microsoft Windows Speech Tampering Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69554 | Microsoft Windows Search Component Tampering Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69568 | Storage Spaces Controller Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69609 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69616 | Windows Remote Desktop Services Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69618 | Windows SMB Client Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69627 | Windows Remote Desktop Licensing Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69672 | Windows DNS Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69674 | Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-69684 | Windows Error Reporting Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-09-08 |
| CVE-2026-69741 | Windows Spaceport.sys Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69770 | Windows Spaceport.sys Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69794 | Windows Encrypting File System (EFS) Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69808 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-69862 | Windows Wireless Wide Area Network Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-70145 | Microsoft Windows Search Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-70290 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-71341 | Windows Partition Management Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-72937 | Windows Storage Port Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-72945 | Windows Task Scheduler Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-72964 | Windows Internet Connection Sharing (ICS) Tampering Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-72966 | Windows Remote Access Connection Manager Tampering Vulnerability | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-73004 | Windows Autopilot Tampering Vulnerability | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-73008 | Windows Biometric Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-77488 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-77491 | Windows GDI Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-77492 | Windows Storage Port Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-78454 | Windows CD-ROM Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-78506 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-78513 | Microsoft Office PowerPoint Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-81387 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-81390 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-81391 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-81392 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-81393 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-81394 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-81395 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-81399 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-81400 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-81401 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-81958 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-83501 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-83949 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-83951 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-83991 | Windows Cloud Files Mini Filter Driver Tampering Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-85875 | Microsoft Office Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-31911 | abort() in libpcap before 1.10.7 on an invalid BPF opcode | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-31912 | OOBR in libpcap before 1.10.7 | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-6244 | division by zero in libpcap before 1.10.7 | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-6554 | infinte loop in libpcap before 1.10.7 | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-77159 | Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80728 | Revert "drm/amdgpu: fix aperture mapping leak" | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80730 | ring-buffer: Fix crash passing ERR_PTR to kthread_stop() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-80733 | net: remove WARN_ON_ONCE() from sk_mc_loop() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80738 | bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-80742 | af_packet: Don't send zero-byte data in tpacket_snd(). | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80743 | ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80747 | drm/amdkfd: Add bounds check for CRAT subtype length | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80752 | Input: psxpad-spi - set driver data before use | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80888 | drm/vmwgfx: drop dma_buf reference on foreign-fd prime import | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80905 | net: tap: fix wrong transport_header when sending VLAN-tagged frame | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-80832 | crypto: qce - fix CCM AAD buffer underallocation | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-78607 | Missing Authorization in Elasticsearch Leading to Information Disclosure | MEDIUM | 5.4 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-70575 | Windows Schannel Denial of Service Vulnerability | MEDIUM | 5.3 | 56%ile | Microsoft | 2026-09-08 |
| CVE-2026-78446 | Windows Distributed File System (DFS) Denial of Service Vulnerability | MEDIUM | 5.3 | 48%ile | Microsoft | 2026-09-08 |
| CVE-2026-81380 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 5.3 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-71222 | Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing | MEDIUM | 5.3 | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-72976 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.0 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-18238 | OOBR in rpcap client in libpcap before 1.10.7 | MEDIUM | 5.0 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-68785 | Microsoft SQL Server Remote Code Execution Vulnerability | MEDIUM | 4.9 | 54%ile | Microsoft | 2026-09-08 |
| CVE-2026-56143 | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service | MEDIUM | 4.9 | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-69474 | Windows Overlay Filter Information Disclosure Vulnerability | MEDIUM | 4.8 | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-80890 | sctp: reject stale cookies with mismatched verification tags | MEDIUM | 4.8 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-89567 | jbd2: bound shrinker scans by examined checkpoint buffers | MEDIUM | 4.7 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89598 | fbdev: ssd1307fb: defer I2C transfers from damage callbacks | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-89642 | cifs: call pagecache_isize_extended() in cifs_setsize() when extending | MEDIUM | 4.7 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-89753 | mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() | MEDIUM | 4.7 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-89756 | mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() | MEDIUM | 4.7 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-68849 | Windows Bluetooth Port Driver Information Disclosure Vulnerability | MEDIUM | 4.7 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-68891 | Microsoft Standard XPS Information Disclosure Vulnerability | MEDIUM | 4.7 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-69316 | Windows Overlay Filter Information Disclosure Vulnerability | MEDIUM | 4.7 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-69425 | Windows NTFS Tampering Vulnerability | MEDIUM | 4.7 | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-69483 | Windows Image Acquisition Information Disclosure Vulnerability | MEDIUM | 4.7 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-69771 | Windows Container Manager Service Security Feature Bypass Vulnerability | MEDIUM | 4.7 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-69792 | Windows Win32K Security Feature Bypass Vulnerability | MEDIUM | 4.7 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-69853 | Win32k Information Disclosure Vulnerability | MEDIUM | 4.7 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-69895 | Windows Spaceport.sys Information Disclosure Vulnerability | MEDIUM | 4.7 | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-72931 | Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | MEDIUM | 4.7 | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-71219 | Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-71224 | Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-80726 | KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page | MEDIUM | 4.7 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80767 | HID: sensor: custom: Fix use-after-free in enable_sensor | MEDIUM | 4.7 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80855 | fuse: fix invalidate lock leak on open O_TRUNC DAX failure | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80856 | fuse: fix invalidate lock leak on setattr writeback failure | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80864 | RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp | MEDIUM | 4.7 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-80923 | xhci: dbgtty: Fix unregister on tty_register_driver() failure | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80771 | HID: nintendo: register input device after capabilities are set | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80809 | ocfs2: fix missing metadata reservation for large xattrs | MEDIUM | 4.7 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80833 | crypto: sun8i-ss - Remove crypto_rng interface | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80834 | crypto: sun8i-ce - Remove crypto_rng interface | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-69381 | Windows Storage Port Driver Information Disclosure Vulnerability | MEDIUM | 4.6 | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-69548 | Windows RNDIS Information Disclosure Vulnerability | MEDIUM | 4.6 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-69690 | Microsoft Office SharePoint Spoofing Vulnerability | MEDIUM | 4.6 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-78452 | Microsoft Windows SCSI Class System File Information Disclosure Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-09-08 |
| CVE-2026-78508 | Windows CD-ROM Driver Information Disclosure Vulnerability | MEDIUM | 4.6 | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-80765 | HID: hyperv: validate initial device info bounds | MEDIUM | 4.5 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80999 | net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO | MEDIUM | 4.4 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89539 | SUNRPC: reject duplicate CREDS_VALUE options | MEDIUM | 4.4 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-89726 | lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-69713 | Windows Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 4.4 | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-72980 | Windows Hello Security Feature Bypass Vulnerability | MEDIUM | 4.4 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-80756 | selinux: do not cancel a policy conversion that never started | MEDIUM | 4.4 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80793 | ipv4: reject undersized MTUs in ip_do_fragment() | MEDIUM | 4.4 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80805 | xfs: validate attr entry pointer before field access | MEDIUM | 4.4 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80847 | tcp: clamp route advmss to TCP_MIN_MSS | MEDIUM | 4.4 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80863 | RDMA/rxe: Fix OOB in free_rd_atomic_resources() | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80902 | dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA | MEDIUM | 4.4 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80912 | selinux: reject an unclaimed class value in security_get_classes() | MEDIUM | 4.4 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80913 | selinux: require every boolean value to be defined | MEDIUM | 4.4 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-90024 | usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-73019 | Windows URL Moniker Security Feature Bypass Vulnerability | MEDIUM | 4.3 | 53%ile | Microsoft | 2026-09-08 |
| CVE-2026-78455 | Xbox Information Disclosure Vulnerability | MEDIUM | 4.3 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-78516 | Windows Storage Information Disclosure Vulnerability | MEDIUM | 4.3 | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-18313 | rpcapd memory leak in libpcap before 1.10.7 | MEDIUM | 4.3 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80763 | Bluetooth: hci_event: validate LE Set CIG Parameters response | MEDIUM | 4.3 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-80828 | ALSA: usb-audio: Complete cleanup after system-resume errors | MEDIUM | 4.3 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-87875 | Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound | MEDIUM | 4.3 | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-80772 | HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() | MEDIUM | 4.3 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-80794 | nfc: nci: fix uninit-value in the RF discover/activated NTF handlers | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80796 | nfc: nci: add data_len bound checks to activation parameter extractors | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80801 | nfc: microread: validate target discovery payload lengths | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-81005 | ipmi: si: Fix NULL pointer dereference after failed registration | MEDIUM | 4.2 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80861 | usb: xhci: bail out of setup if the controller is inaccessible | MEDIUM | 4.2 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-80914 | Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready | MEDIUM | 4.2 | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-89092 | Stack overflow in nscd due to unbounded alloca use | MEDIUM | 4.2 | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-80921 | KVM: s390: vsie: zero stale crypto bits | MEDIUM | 4.2 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-80762 | Bluetooth: hci_sync: Fix accept list UAF during suspend | MEDIUM | 4.1 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-80764 | Bluetooth: hci_event: fix LE list UAF on reset | MEDIUM | 4.1 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-80806 | ext4: don't enable DAX on new encrypted files | MEDIUM | 4.1 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-80808 | ext4: stop retrying saturated xattr cache entries | MEDIUM | 4.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80824 | usb: usbfs: fix use-after-free of usb_device in usbdev_release() | MEDIUM | 4.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80826 | USB: c67x00: fix use-after-free in c67x00_add_iso_urb() | MEDIUM | 4.1 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80836 | crypto: virtio - bound the akcipher result length | MEDIUM | 4.1 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80866 | tipc: avoid busy looping in tipc_exit_net() | MEDIUM | 4.1 | 4%ile | Microsoft | 2026-09-08 |
| CVE-2026-80917 | PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems | MEDIUM | 4.1 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80925 | vlan: fix skb_under_panic and races when toggling HW VLAN offload | MEDIUM | 4.1 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-80820 | xfs: don't livelock in scrub on a circular unlinked list | MEDIUM | 4.1 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80872 | ALSA: hda/tas2781: Cancel async firmware request at unbind | MEDIUM | 4.1 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-80766 | HID: uclogic: fix use-after-free of inrange_timer on remove | MEDIUM | 4.0 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80782 | HID: magicmouse: do not keep a stale msc->input if no input is claimed | MEDIUM | 4.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80830 | usb: core: Add lock to usb_wakeup_notification() | MEDIUM | 4.0 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80770 | HID: nintendo: stop device IO before hid_hw_stop on probe failure | MEDIUM | 4.0 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-89628 | HID: picolcd: clamp eeprom debugfs read to bytes actually received | LOW | 3.9 | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-89582 | bnx2x: fix double free in bnx2x_init_firmware() error path | LOW | 3.8 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-89565 | ipip: fix skb leak in collect_md mode when metadata_dst allocation fails | LOW | 3.7 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass | LOW | 3.7 | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-18540 | undici vulnerable to downstream response splitting via retry interceptor | LOW | 3.7 | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-78124 | strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of relea | LOW | 3.7 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-78127 | libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE mess | LOW | 3.7 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-78131 | strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribu | LOW | 3.7 | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-80230 | OpenSSL pinning bypass | LOW | 3.7 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-80255 | secure cookie attribute bypass with tab | LOW | 3.7 | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-89156 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF da | LOW | 3.7 | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-89160 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF su | LOW | 3.7 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80231 | native CA store conn reuse | LOW | 3.7 | 59%ile | Microsoft | 2026-09-08 |
| CVE-2026-89461 | power: supply: max17040: synchronize work cancellation on suspend | LOW | 3.6 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-89757 | mm/mglru: fix and remove redundant unevictable folio handling | LOW | 3.6 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-69615 | Microsoft Office SharePoint Spoofing Vulnerability | LOW | 3.5 | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-69904 | Microsoft Office SharePoint Information Disclosure Vulnerability | LOW | 3.5 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-80744 | netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path | LOW | 3.3 | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-80761 | Bluetooth: ISO: zero the sockaddr before returning it in getname | LOW | 3.3 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80920 | io_uring: defer eventfd signaling when queued from a wakeup handler | LOW | 3.3 | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-80892 | erofs: cap LZMA stream pool size | LOW | 3.3 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-80910 | ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses | LOW | 3.3 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-89768 | fs: fix user path of nested backing files | LOW | 3.0 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87876 | Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) | LOW | 3.0 | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-89462 | power: supply: max17040: propagate register read errors | LOW | 2.9 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-86137 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro i | LOW | 2.9 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-86141 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., i | LOW | 2.9 | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-80983 | net/smc: fix socket refcount leak in smc_switch_conns() | LOW | 2.5 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-18743 | Popt-devel: popt-static: short realloc in poptconfigfiletostring | LOW | 2.5 | 4%ile | Microsoft | 2026-09-08 |
| CVE-2026-80784 | mptcp: pm: fix memory leak from alloc-during-teardown race | LOW | 2.5 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-80893 | mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() | LOW | 2.5 | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-80889 | can: isotp: fix timer drain order, wakeup handling and tx_gen ordering | LOW | 2.5 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80918 | HID: core: fix number/pointer type confusion on long items | LOW | 2.4 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80843 | xfrm: fix xfrm_state_construct() auth-trunc leak | LOW | 2.3 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89627 | HID: roccat: free buffered reports when destroying device | LOW | 2.1 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-80949 | wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() | LOW | 1.9 | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-80996 | net: l2tp: do not propagate multicast notification errors | LOW | 1.9 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-89473 | power: supply: bq25890: Fix power_supply reference leak | LOW | 1.9 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-89645 | btrfs: drop recovered reloc root refs on recovery failure | LOW | 1.9 | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-80797 | nfc: pn533: purge fragmented skbs during cleanup | LOW | 1.9 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80827 | USB: serial: option: fix slab OOB read in interrupt URB callback | LOW | 1.8 | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-80948 | wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() | LOW | 1.6 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-76017 | Chromium CVE-2026-76017: Use after free in Chromoting | UNKNOWN | — | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-76018 | Chromium CVE-2026-76018: Privilege elevation in Import | UNKNOWN | — | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-76019 | Chromium CVE-2026-76019: Incorrect authorization in Workers | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-76021 | Chromium CVE-2026-76021: Use after free in DOM | UNKNOWN | — | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-76022 | Chromium CVE-2026-76022: Buffer overflow in Network | UNKNOWN | — | 40%ile | Microsoft | 2026-09-08 |
| CVE-2026-76023 | Chromium CVE-2026-76023: Improper resource control in Linux Toolkit Theming | UNKNOWN | — | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-76036 | Chromium CVE-2026-76036: Buffer overflow in Dawn | UNKNOWN | — | 55%ile | Microsoft | 2026-09-08 |
| CVE-2026-76039 | Chromium CVE-2026-76039: Incorrect reference resolution in Core | UNKNOWN | — | 42%ile | Microsoft | 2026-09-08 |
| CVE-2026-84323 | Chromium: CVE-2026-84323 Missing authorization in FileSystem | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-84324 | Chromium: CVE-2026-84324 Use after free in Proxy | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-84325 | Chromium: CVE-2026-84325 Improper input validation in DataTransfer | UNKNOWN | — | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-84326 | Chromium: CVE-2026-84326 Uninitialized resource in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-84327 | Chromium: CVE-2026-84327 Incorrect authorization in Autofill | UNKNOWN | — | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-84328 | Chromium: CVE-2026-84328 Missing authorization in FileSystem | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-84329 | Chromium: CVE-2026-84329 Confused deputy in CredentialProvider | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-84330 | Chromium: CVE-2026-84330 UI misrepresentation in FullScreen | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-84331 | Chromium: CVE-2026-84331 Incorrect authorization in Actor | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-84332 | Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-84333 | Chromium: CVE-2026-84333 Use after free in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-84334 | Chromium: CVE-2026-84334 Incorrect authorization in Chromoting | UNKNOWN | — | 0%ile | Microsoft | 2026-09-08 |
| CVE-2026-84335 | Chromium: CVE-2026-84335 Incorrect authorization in TabStrip | UNKNOWN | — | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-84347 | Chromium: CVE-2026-84347 Use after free in WebRTC | UNKNOWN | — | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-84348 | Chromium: CVE-2026-84348 Information leak in MediaCapture | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-84349 | Chromium: CVE-2026-84349 Use after free in Browser | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-84350 | Chromium: CVE-2026-84350 Use after free in TabStrip | UNKNOWN | — | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-84351 | Chromium: CVE-2026-84351 Buffer overflow in GPU | UNKNOWN | — | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-84352 | Chromium: CVE-2026-84352 Use after free in WebGL | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-84353 | Chromium: CVE-2026-84353 Use after free in Shared Tab Groups | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-84354 | Chromium: CVE-2026-84354 Incorrect authorization in FileSystem | UNKNOWN | — | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-84355 | Chromium: CVE-2026-84355 Incorrect authorization in Navigation | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-84356 | Chromium: CVE-2026-84356 UI misrepresentation in FullScreen | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-84357 | Chromium: CVE-2026-84357 Improper input validation in Omnibox | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-84358 | Chromium: CVE-2026-84358 Improper privilege management in Downloads | UNKNOWN | — | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-84359 | Chromium: CVE-2026-84359 Information leak in Skia | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-85042 | Chromium CVE-2026-85042: Use after free in DevTools | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-85043 | Chromium CVE-2026-85043: Incomplete cleanup in Network | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-85045 | Chromium CVE-2026-85045: Race condition in V8 | UNKNOWN | — | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-85046 | Chromium: CVE-2026-85046 Type confusion in V8 | UNKNOWN | — | 72%ile | Microsoft | 2026-09-08 |
| CVE-2026-85048 | Chromium CVE-2026-85048: Use after free in Compositing | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-85049 | Chromium CVE-2026-85049: Use after free in Skia | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-85051 | Chromium CVE-2026-85051: Type confusion in Compositing | UNKNOWN | — | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-85052 | Chromium CVE-2026-85052: Out of bounds read in CrashReporting | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-85053 | Chromium CVE-2026-85053: Improper resource exposure in CacheStorage | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-87429 | Chromium CVE-2026-87429: Missing authorization in ServiceWorker | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-87430 | Chromium CVE-2026-87430: Buffer overflow in WebRTC | UNKNOWN | — | 43%ile | Microsoft | 2026-09-08 |
| CVE-2026-87431 | Chromium CVE-2026-87431: Missing authorization in Extensions | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-87432 | Chromium CVE-2026-87432: Incorrect authorization in Navigation | UNKNOWN | — | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-87433 | Chromium CVE-2026-87433: Race condition in FileAPI | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87434 | Chromium CVE-2026-87434: Missing authorization in CORS | UNKNOWN | — | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-87435 | Chromium CVE-2026-87435: Information leak in ControlledFrame | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-87436 | Chromium CVE-2026-87436: Incomplete cleanup in Browser | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-87437 | Chromium CVE-2026-87437: Information leak in Frames | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-87439 | Chromium CVE-2026-87439: Information leak in ServiceWorker | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-87440 | Chromium CVE-2026-87440: Out of bounds read in Media | UNKNOWN | — | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-87441 | Chromium CVE-2026-87441: Missing authorization in Downloads | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87442 | Chromium CVE-2026-87442: Confused deputy in Prerender | UNKNOWN | — | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-87443 | Chromium CVE-2026-87443: Missing authorization in Actor | UNKNOWN | — | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-87444 | Chromium CVE-2026-87444: Memory corruption in Codecs | UNKNOWN | — | 38%ile | Microsoft | 2026-09-08 |
| CVE-2026-87445 | Chromium CVE-2026-87445: UI misrepresentation in Session | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87446 | Chromium CVE-2026-87446: Incomplete cleanup in Extensions | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-87447 | Chromium CVE-2026-87447: Incorrect authorization in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-87448 | Chromium CVE-2026-87448: Use after free in DevTools | UNKNOWN | — | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-87449 | Chromium CVE-2026-87449: Cross-site request forgery in DeviceBoundSessionCredentials | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87450 | Chromium CVE-2026-87450: Incorrect authorization in Permissions | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-87451 | Chromium CVE-2026-87451: Information leak in Downloads | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87452 | Chromium CVE-2026-87452: Incorrect authorization in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87453 | Chromium CVE-2026-87453: Confused deputy in BackgroundFetch | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87454 | Chromium CVE-2026-87454: Information leak in Enterprise | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87455 | Chromium CVE-2026-87455: Use after free in Aura | UNKNOWN | — | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-87456 | Chromium CVE-2026-87456: Uninitialized resource in Media | UNKNOWN | — | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-87457 | Chromium CVE-2026-87457: Race condition in Updater | UNKNOWN | — | 0%ile | Microsoft | 2026-09-08 |
| CVE-2026-87458 | Chromium CVE-2026-87458: UI misrepresentation in Geometry | UNKNOWN | — | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-87459 | Chromium CVE-2026-87459: Observable discrepancy in Select | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87460 | Chromium CVE-2026-87460: Use after free in Platform | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87461 | Chromium CVE-2026-87461: Information leak in Core | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-87462 | Chromium CVE-2026-87462: UI misrepresentation in FedCM | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87463 | Chromium CVE-2026-87463: Incorrect authorization in Certificate | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-87465 | Chromium CVE-2026-87465: Incorrect authorization in Downloads | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-87466 | Chromium CVE-2026-87466: Incorrect authorization in Workers | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87467 | Chromium CVE-2026-87467: Race condition in Updater | UNKNOWN | — | 0%ile | Microsoft | 2026-09-08 |
| CVE-2026-87468 | Chromium CVE-2026-87468: Incorrect authorization in Isolated | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87469 | Chromium CVE-2026-87469: Improper input validation in Extensions | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87470 | Chromium CVE-2026-87470: Improper quantity validation in Tint | UNKNOWN | — | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-87471 | Chromium CVE-2026-87471: Incorrect authorization in ServiceWorker | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-87472 | Chromium CVE-2026-87472: Improper input validation in FedCM | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87473 | Chromium CVE-2026-87473: Incorrect authorization in FileHandling | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87474 | Chromium CVE-2026-87474: Use after free in Payments | UNKNOWN | — | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-87475 | Chromium CVE-2026-87475: Missing authorization in Omnibox | UNKNOWN | — | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-87476 | Chromium CVE-2026-87476: Incorrect authorization in Loader | UNKNOWN | — | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-87477 | Chromium CVE-2026-87477: Information leak in Core | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-87478 | Chromium CVE-2026-87478: Observable discrepancy in Autofill | UNKNOWN | — | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-87479 | Chromium CVE-2026-87479: Insufficient policy enforcement in Extensions | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-87480 | Chromium CVE-2026-87480: Use after free in Printing | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-87484 | Chromium CVE-2026-87484: UI misrepresentation in Geometry | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87485 | Chromium CVE-2026-87485: Incorrect authorization in CORS | UNKNOWN | — | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-87487 | Chromium CVE-2026-87487: Missing authorization in FileSystem | UNKNOWN | — | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-87489 | Chromium CVE-2026-87489: Memory corruption in V8 | UNKNOWN | — | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-87490 | Chromium CVE-2026-87490: Information leak in Transactions Platform | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87491 | Chromium CVE-2026-87491: Out of bounds write in V8 | UNKNOWN | — | 61%ile | Microsoft | 2026-09-08 |
| CVE-2026-87492 | Chromium CVE-2026-87492: Incorrect authorization in DevTools | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-87493 | Chromium CVE-2026-87493: Missing authorization in FileSystem | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87494 | Chromium CVE-2026-87494: Use after free in Browser | UNKNOWN | — | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-87495 | Chromium CVE-2026-87495: Information leak in Scroll | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87496 | Chromium CVE-2026-87496: UI misrepresentation in Browser | UNKNOWN | — | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-87497 | Chromium CVE-2026-87497: Uninitialized resource in Codecs | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87498 | Chromium CVE-2026-87498: Missing authorization in WebUI | UNKNOWN | — | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-87499 | Chromium CVE-2026-87499: Incorrect authorization in Network | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87500 | Chromium CVE-2026-87500: Improper validation of array index in ANGLE | UNKNOWN | — | 27%ile | Microsoft | 2026-09-08 |
| CVE-2026-87501 | Chromium CVE-2026-87501: UI misrepresentation in Passwords | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87502 | Chromium CVE-2026-87502: Confused deputy in Fullscreen | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-87504 | Chromium CVE-2026-87504: Use after free in Core | UNKNOWN | — | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-87505 | Chromium CVE-2026-87505: Incorrect authorization in FileSystem | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87506 | Chromium CVE-2026-87506: Privilege elevation in WebUI | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-87507 | Chromium CVE-2026-87507: UI misrepresentation in Downloads | UNKNOWN | — | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-87508 | Chromium CVE-2026-87508: Incorrect authorization in Loader | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87509 | Chromium CVE-2026-87509: Incorrect authorization in Updater | UNKNOWN | — | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-87510 | Chromium CVE-2026-87510: Improper input validation in FileAPI | UNKNOWN | — | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-87511 | Chromium CVE-2026-87511: Missing authorization in DevTools | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87512 | Chromium CVE-2026-87512: Use after free in ANGLE | UNKNOWN | — | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-87513 | Chromium CVE-2026-87513: Missing authorization in ControlledFrame | UNKNOWN | — | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-87514 | Chromium CVE-2026-87514: Use after free in Views | UNKNOWN | — | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-87515 | Chromium CVE-2026-87515: Incorrect authorization in FileAPI | UNKNOWN | — | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-87516 | Chromium CVE-2026-87516: Observable discrepancy in Navigation | UNKNOWN | — | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-87519 | Chromium CVE-2026-87519: Incorrect authorization in Safebrowsing | UNKNOWN | — | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-87521 | Chromium CVE-2026-87521: Information leak in WebMCP | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87523 | Chromium CVE-2026-87523: Race condition in DataTransfer | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87524 | Chromium CVE-2026-87524: Use after free in Core | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-87525 | Chromium CVE-2026-87525: Out of bounds read in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-87526 | Chromium CVE-2026-87526: Use after free in Passwords | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-87527 | Chromium CVE-2026-87527: Buffer overflow in WebGL | UNKNOWN | — | 40%ile | Microsoft | 2026-09-08 |
| CVE-2026-87528 | Chromium CVE-2026-87528: Type confusion in Rust | UNKNOWN | — | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-87529 | Chromium CVE-2026-87529: Numeric truncation error in Media | UNKNOWN | — | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-87530 | Chromium CVE-2026-87530: Uncontrolled search path element in CredentialProvider | UNKNOWN | — | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-87531 | Chromium CVE-2026-87531: Information leak in CORS | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87532 | Chromium CVE-2026-87532: Improper state validation in Safebrowsing | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87533 | Chromium CVE-2026-87533: Use after free in DevTools | UNKNOWN | — | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-87535 | Chromium CVE-2026-87535: Information loss or omission in Safebrowsing | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87536 | Chromium CVE-2026-87536: Use after free in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87537 | Chromium CVE-2026-87537: Missing authorization in Extensions | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87538 | Chromium CVE-2026-87538: Clickjacking in Input | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87539 | Chromium CVE-2026-87539: Observable discrepancy in Network | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87540 | Chromium CVE-2026-87540: Incorrect authorization in Isolated | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87541 | Chromium CVE-2026-87541: Information leak in Navigation | UNKNOWN | — | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-87542 | Chromium CVE-2026-87542: Use after free in Input | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87543 | Chromium CVE-2026-87543: Missing authorization in Core | UNKNOWN | — | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-87544 | Chromium CVE-2026-87544: Incorrect authorization in Extensions | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87546 | Chromium CVE-2026-87546: Incorrect type conversion or cast in Safebrowsing | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87547 | Chromium CVE-2026-87547: Incorrect reference resolution in FileSystem | UNKNOWN | — | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-87548 | Chromium CVE-2026-87548: Improper state validation in Installer | UNKNOWN | — | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-87549 | Chromium CVE-2026-87549: Incomplete cleanup in Downloads | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-87550 | Chromium CVE-2026-87550: Improper encoding or escaping of output in CSS | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87551 | Chromium CVE-2026-87551: Improper certificate validation in CORS | UNKNOWN | — | 4%ile | Microsoft | 2026-09-08 |
| CVE-2026-87553 | Chromium CVE-2026-87553: Improper input validation in SiteIsolation | UNKNOWN | — | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-87554 | Chromium CVE-2026-87554: Race condition in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-09-08 |
| CVE-2026-87556 | Chromium CVE-2026-87556: Missing authorization in Browser | UNKNOWN | — | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-87557 | Chromium CVE-2026-87557: Missing authorization in LocalNetworkAccess | UNKNOWN | — | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-87558 | Chromium CVE-2026-87558: Use after free in Payments | UNKNOWN | — | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-87559 | Chromium CVE-2026-87559: UI misrepresentation in UI | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87560 | Chromium CVE-2026-87560: Missing authorization in Browser | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87561 | Chromium CVE-2026-87561: Incorrect authorization in Web Authentication | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87562 | Chromium CVE-2026-87562: Incorrect reference resolution in Accessibility | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87563 | Chromium CVE-2026-87563: Origin validation error in Paint | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-87564 | Chromium CVE-2026-87564: Type confusion in V8 | UNKNOWN | — | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-87565 | Chromium CVE-2026-87565: Information leak in Passwords | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87566 | Chromium CVE-2026-87566: Observable discrepancy in Layout | UNKNOWN | — | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-87567 | Chromium CVE-2026-87567: UI misrepresentation in UrlFormatting | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-87568 | Chromium CVE-2026-87568: Improper input validation in Chromium | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-87569 | Chromium CVE-2026-87569: Missing authorization in Views | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87570 | Chromium CVE-2026-87570: Incorrect authorization in SiteIsolation | UNKNOWN | — | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-87571 | Chromium CVE-2026-87571: Improper certificate validation in Loader | UNKNOWN | — | 2%ile | Microsoft | 2026-09-08 |
| CVE-2026-87572 | Chromium CVE-2026-87572: Injection in DevTools | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-87573 | Chromium CVE-2026-87573: Improper input validation in Network | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87574 | Chromium CVE-2026-87574: Information leak in ServiceWorker | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87575 | Chromium CVE-2026-87575: Incorrect authorization in Loader | UNKNOWN | — | 4%ile | Microsoft | 2026-09-08 |
| CVE-2026-87577 | Chromium CVE-2026-87577: Incorrect authorization in Isolated | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87578 | Chromium CVE-2026-87578: Use after free in Receiver | UNKNOWN | — | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-87579 | Chromium CVE-2026-87579: Buffer overflow in WebRTC | UNKNOWN | — | 37%ile | Microsoft | 2026-09-08 |
| CVE-2026-87580 | Chromium CVE-2026-87580: Incorrect authorization in WebAppInstalls | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87581 | Chromium CVE-2026-87581: Use after free in Payments | UNKNOWN | — | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-87582 | Chromium CVE-2026-87582: Confused deputy in DataTransfer | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-87583 | Chromium CVE-2026-87583: UI misrepresentation in Passwords | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-87584 | Chromium CVE-2026-87584: Incorrect authorization in WebUI | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87585 | Chromium CVE-2026-87585: Double free in PDFium | UNKNOWN | — | 21%ile | Microsoft | 2026-09-08 |
| CVE-2026-87586 | Chromium CVE-2026-87586: Out of bounds read in ANGLE | UNKNOWN | — | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-87587 | Chromium CVE-2026-87587: Use after free in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87588 | Chromium CVE-2026-87588: Use after free in Chromecast | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87589 | Chromium CVE-2026-87589: Incorrect authorization in SiteIsolation | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87590 | Chromium CVE-2026-87590: Improper input validation in Passwords | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87591 | Chromium CVE-2026-87591: Incorrect authorization in Extensions | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87592 | Chromium CVE-2026-87592: Out of bounds read in Tint | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87593 | Chromium CVE-2026-87593: Information leak in Editing | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87594 | Chromium CVE-2026-87594: Incorrect authorization in DataTransfer | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87596 | Chromium CVE-2026-87596: Out of bounds read in ANGLE | UNKNOWN | — | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-87598 | Chromium CVE-2026-87598: Incorrect authorization in ServiceWorker | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87599 | Chromium CVE-2026-87599: Improper input validation in Interstitials | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87600 | Chromium CVE-2026-87600: Improper input validation in Safebrowsing | UNKNOWN | — | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-87601 | Chromium CVE-2026-87601: Race condition in V8 | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87602 | Chromium CVE-2026-87602: Out of bounds read in ANGLE | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-87603 | Chromium CVE-2026-87603: Missing authorization in FileSystem | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87604 | Chromium CVE-2026-87604: Out of bounds read in ANGLE | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-87605 | Chromium CVE-2026-87605: Missing authorization in Contacts | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-87606 | Chromium CVE-2026-87606: Missing authorization in SiteIsolation | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87608 | Chromium CVE-2026-87608: Improper certificate validation in FedCM | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87609 | Chromium CVE-2026-87609: Use after free in Sharing | UNKNOWN | — | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-87610 | Chromium CVE-2026-87610: Incorrect authorization in Omnibox | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87611 | Chromium CVE-2026-87611: Missing authorization in FileSystem | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-87612 | Chromium CVE-2026-87612: Type confusion in V8 | UNKNOWN | — | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-87613 | Chromium CVE-2026-87613: Incorrect reference resolution in Extensions | UNKNOWN | — | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-87614 | Chromium CVE-2026-87614: Incorrect authorization in ServiceWorker | UNKNOWN | — | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-87615 | Chromium CVE-2026-87615: Race condition in Payments | UNKNOWN | — | 4%ile | Microsoft | 2026-09-08 |
| CVE-2026-87616 | Chromium CVE-2026-87616: Improper initialization in Views | UNKNOWN | — | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-87617 | Chromium CVE-2026-87617: Use after free in DevTools | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-87618 | Chromium CVE-2026-87618: Incorrect reference resolution in Storage | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-87619 | Chromium CVE-2026-87619: Observable discrepancy in Prefetch | UNKNOWN | — | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-87620 | Chromium CVE-2026-87620: Observable discrepancy in SVG | UNKNOWN | — | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-87621 | Chromium CVE-2026-87621: Out of bounds write in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-87622 | Chromium CVE-2026-87622: Missing authorization in FedCM | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87623 | Chromium CVE-2026-87623: Observable discrepancy in DOM | UNKNOWN | — | 15%ile | Microsoft | 2026-09-08 |
| CVE-2026-87624 | Chromium CVE-2026-87624: UI misrepresentation in Passwords | UNKNOWN | — | 4%ile | Microsoft | 2026-09-08 |
| CVE-2026-87625 | Chromium CVE-2026-87625: Use after free in V8 | UNKNOWN | — | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-87626 | Chromium CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentials | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87627 | Chromium CVE-2026-87627: Interpretation conflict in Safebrowsing | UNKNOWN | — | 10%ile | Microsoft | 2026-09-08 |
| CVE-2026-87628 | Chromium CVE-2026-87628: Use after free in Cast | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-87629 | Chromium CVE-2026-87629: Incorrect authorization in Sources | UNKNOWN | — | 16%ile | Microsoft | 2026-09-08 |
| CVE-2026-87630 | Chromium CVE-2026-87630: Integer overflow in WebRTC | UNKNOWN | — | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-87631 | Chromium CVE-2026-87631: Missing authorization in DOM | UNKNOWN | — | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-87632 | Chromium CVE-2026-87632: Cross-site scripting in SanitizerAPI | UNKNOWN | — | 14%ile | Microsoft | 2026-09-08 |
| CVE-2026-87633 | Chromium CVE-2026-87633: Use after free in Views | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-87634 | Chromium CVE-2026-87634: Use after free in WebPackaging | UNKNOWN | — | 34%ile | Microsoft | 2026-09-08 |
| CVE-2026-87635 | Chromium CVE-2026-87635: UI misrepresentation in Payments | UNKNOWN | — | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-87636 | Chromium CVE-2026-87636: Type confusion in XML | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-87637 | Chromium CVE-2026-87637: Use after free in Extensions | UNKNOWN | — | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-87638 | Chromium CVE-2026-87638: Out of bounds write in Media | UNKNOWN | — | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-87639 | Chromium CVE-2026-87639: Use after free in WebPackaging | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-87641 | Chromium CVE-2026-87641: Race condition in Browser | UNKNOWN | — | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-87642 | Chromium CVE-2026-87642: Uninitialized resource in WebGL | UNKNOWN | — | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-87644 | Chromium CVE-2026-87644: Incorrect authorization in Views | UNKNOWN | — | 19%ile | Microsoft | 2026-09-08 |
| CVE-2026-87645 | Chromium CVE-2026-87645: Improper state validation in Safebrowsing | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-87646 | Chromium CVE-2026-87646: Use after free in Web Authentication | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-87647 | Chromium CVE-2026-87647: Uninitialized resource in GPU | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87648 | Chromium CVE-2026-87648: Use after free in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-09-08 |
| CVE-2026-87649 | Chromium CVE-2026-87649: UI misrepresentation in Downloads | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-87650 | Chromium CVE-2026-87650: Out of bounds read in WebGL | UNKNOWN | — | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-87651 | Chromium CVE-2026-87651: Incorrect authorization in Paint | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87652 | Chromium CVE-2026-87652: Incorrect authorization in PushAPI | UNKNOWN | — | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-87653 | Chromium CVE-2026-87653: UI misrepresentation in FullScreen | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87654 | Chromium CVE-2026-87654: Buffer overflow in ANGLE | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-87655 | Chromium CVE-2026-87655: Clickjacking in Downloads | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87656 | Chromium CVE-2026-87656: Improper state validation in Safebrowsing | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-87657 | Chromium CVE-2026-87657: Use after free in V8 | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-87658 | Chromium CVE-2026-87658: Information leak in Extensions | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-11573 | Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml) | UNKNOWN | — | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-55951 | httpc memory exhaustion via unbounded response header accumulation | UNKNOWN | — | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-59696 | uri_string does not bound the port component of a URI before integer conversion | UNKNOWN | — | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-66357 | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-66835 | httpd mod_auth directory protection bypassed by a doubled slash in the request path | UNKNOWN | — | 49%ile | Microsoft | 2026-09-08 |
| CVE-2026-69664 | httpd parks a request worker indefinitely on a malformed chunk size sent after the headers | UNKNOWN | — | 51%ile | Microsoft | 2026-09-08 |
| CVE-2026-70409 | eldap does not bound the port component of a referral URL before integer conversion | UNKNOWN | — | 36%ile | Microsoft | 2026-09-08 |
| CVE-2026-71380 | httpd applies no timeout while receiving a request body, parking a worker on a stalled client | UNKNOWN | — | 33%ile | Microsoft | 2026-09-08 |
| CVE-2026-71562 | httpc does not bound server-supplied numeric header values before integer conversion | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-73270 | httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems | UNKNOWN | — | 50%ile | Microsoft | 2026-09-08 |
| CVE-2026-73276 | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-73812 | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-74835 | inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception | UNKNOWN | — | 26%ile | Microsoft | 2026-09-08 |
| CVE-2026-74994 | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth | UNKNOWN | — | 30%ile | Microsoft | 2026-09-08 |
| CVE-2026-75538 | A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauth | UNKNOWN | — | 41%ile | Microsoft | 2026-09-08 |
| CVE-2026-80822 | mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80883 | drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-80887 | drm/vmwgfx: use check_add_overflow for shader size+offset bound | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-80901 | ipvs: fix the checksum validations | UNKNOWN | — | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-83605 | xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-83607 | xmldom: Element name injection via createElement() bypasses requireWellFormed | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-83608 | xmldom: DocType `name` Injection Bypasses requireWellFormed | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-83610 | xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization | UNKNOWN | — | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-83611 | xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content | UNKNOWN | — | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-83613 | xmldom: Quadratic-time attribute deduplication | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-83614 | xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` | UNKNOWN | — | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-83615 | xmldom: Quadratic-memory consumption | UNKNOWN | — | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-83616 | xmldom: Processing Instruction Target Injection Bypasses requireWellFormed | UNKNOWN | — | 28%ile | Microsoft | 2026-09-08 |
| CVE-2026-83619 | xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-84303 | gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion | UNKNOWN | — | 24%ile | Microsoft | 2026-09-08 |
| CVE-2026-85062 | Colord: Slow rejection of oversized malformed color strings | UNKNOWN | — | 22%ile | Microsoft | 2026-09-08 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-65770 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 10.0 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-65801 | Microsoft Exchange Online Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-65816 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-69502 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-69555 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-69836 | Microsoft Entra ID Remote Code Execution Vulnerability | CRITICAL | 10.0 | 74%ile | Microsoft | 2026-08-11 |
| CVE-2026-50481 | Azure Active Directory Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-50515 | Azure Service Bus Remote Code Execution Vulnerability | CRITICAL | 9.9 | 64%ile | Microsoft | 2026-08-11 |
| CVE-2026-59115 | Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 54%ile | Microsoft | 2026-08-11 |
| CVE-2026-62830 | Azure SRE Agent Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-63509 | Microsoft Fabric Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-68782 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-68789 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-69851 | Microsoft Entra ID Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-52490 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the proces | CRITICAL | 9.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-64562 | KVM: nVMX: Hide shadow VMCS right after VMCLEAR | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-64564 | sctp: don't free the ASCONF's own transport in DEL-IP processing | CRITICAL | 9.8 | 73%ile | Microsoft | 2026-08-11 |
| CVE-2026-64565 | Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() | CRITICAL | 9.8 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-64593 | btrfs: do not trim a device which is not writeable | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68121 | pppoe: reload header pointer after dev_hard_header() | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68127 | ila: reload IPv6 header after pskb_may_pull in checksum adjust | CRITICAL | 9.8 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-68131 | rbd: Reset positive result codes to zero in object map update path | CRITICAL | 9.8 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-68132 | super: fix emergency thaw deadlock on frozen block devices | CRITICAL | 9.8 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68140 | net/iucv: fix use-after-free of a severed iucv_path | CRITICAL | 9.8 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-68142 | geneve: require CAP_NET_ADMIN in the device netns for changelink | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68143 | net: slip: serialize receive against buffer reallocation | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68144 | phonet: pep: fix use-after-free in pep_get_sb() | CRITICAL | 9.8 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-68146 | ftrace: Add global mutex to serialize trace_parser access | CRITICAL | 9.8 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68153 | libceph: remove debugfs files before client teardown | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68166 | userfaultfd: prevent registration of special VMAs | CRITICAL | 9.8 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68176 | tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev | CRITICAL | 9.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68180 | intel_th: fix MSC output device reference leak | CRITICAL | 9.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68185 | LoongArch: Move jump_label_init() before parse_early_param() | CRITICAL | 9.8 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68198 | wifi: ath6kl: fix use-after-free in aggr_reset_state() | CRITICAL | 9.8 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-68207 | media: ti: vpe: unwind v4l2 device registration on probe error | CRITICAL | 9.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68210 | media: stm32: dcmi: unregister notifier on probe failure | CRITICAL | 9.8 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68212 | media: saa7134: Fix a possible memory leak in saa7134_video_init1 | CRITICAL | 9.8 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68214 | media: rtl2832: fix use-after-free in rtl2832_remove() | CRITICAL | 9.8 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68218 | media: pci: dm1105: Free allocated workqueue | CRITICAL | 9.8 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68236 | drm/amd/display: set new_stream to NULL after release | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68287 | drop_monitor: fix size calculations for 64-bit attributes | CRITICAL | 9.8 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-68310 | wifi: mt76: mt7915: guard HE capability lookups | CRITICAL | 9.8 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68324 | iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() | CRITICAL | 9.8 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68325 | iommu/amd: Bound the early ACPI HID map | CRITICAL | 9.8 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68340 | hwmon: occ: validate poll response sensor blocks | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68349 | wifi: carl9170: fix buffer overflow in rx_stream failover path | CRITICAL | 9.8 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68354 | firewire: net: Fix fragmented datagram reassembly | CRITICAL | 9.8 | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-68357 | watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() | CRITICAL | 9.8 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68359 | hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop | CRITICAL | 9.8 | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-68360 | hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop | CRITICAL | 9.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-68364 | drm/amd/display: Fix ISM dc_lock deadlock during suspend | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68377 | net/sched: act_tunnel_key: Defer dst_release to RCU callback | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68391 | Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68395 | ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered | CRITICAL | 9.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68399 | bpf: Fix UAF in sock clone early bailouts | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68402 | wifi: cfg80211: bound element ID read when checking non-inheritance | CRITICAL | 9.8 | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-68406 | wifi: cfg80211: validate PMSR FTM preamble range | CRITICAL | 9.8 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68407 | wifi: nl80211: free RNR data on MBSSID mismatch | CRITICAL | 9.8 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74345 | RDMA/siw: Fix endpoint/socket association handling | CRITICAL | 9.8 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-80607 | tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80616 | ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns() | CRITICAL | 9.8 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80637 | netfilter: synproxy: fix unaligned memory access in timestamp adjustment | CRITICAL | 9.8 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-80650 | media: atomisp: gc2235: fix UAF and memory leak | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80653 | scsi: hisi_sas: Add slave_destroy interface for v3 hw | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80654 | soc: xilinx: Shutdown and free rx mailbox channel | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80681 | vxlan: re-fetch eth header after route_shortcircuit() | CRITICAL | 9.8 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-80686 | mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE | CRITICAL | 9.8 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-80694 | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller | CRITICAL | 9.8 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-80698 | dmaengine: idxd: fix double free of wq, engine, and group structs | CRITICAL | 9.8 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-80709 | s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80715 | igc: remove napi_synchronize() in igc_down() | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80721 | Bluetooth: ISO: ensure no dangling hcon references in iso_conn | CRITICAL | 9.8 | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-59124 | Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability | CRITICAL | 9.8 | 76%ile | Microsoft | 2026-08-11 |
| CVE-2026-62815 | Microsoft QUIC Remote Code Execution Vulnerability | CRITICAL | 9.8 | 68%ile | Microsoft | 2026-08-11 |
| CVE-2026-62873 | Microsoft 365 Admin Center Elevation of Privilege Vulnerability | CRITICAL | 9.8 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-62878 | Windows DNS Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 68%ile | Microsoft | 2026-08-11 |
| CVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 85%ile | Microsoft | 2026-08-11 |
| CVE-2026-65791 | Windows iSCSI Target Service Remote Code Execution Vulnerability | CRITICAL | 9.8 | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-50540 | Kata Containers: Config Path Annotation Arbitrary File Loading | CRITICAL | 9.6 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-56161 | Azure Logic Apps Information Disclosure Vulnerability | CRITICAL | 9.6 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-62896 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-69400 | Azure Logic Apps Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-70332 | Microsoft Office SharePoint Spoofing Vulnerability | CRITICAL | 9.6 | 49%ile | Microsoft | 2026-08-11 |
| CVE-2026-50516 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 9.4 | 56%ile | Microsoft | 2026-08-11 |
| CVE-2026-52491 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtif | CRITICAL | 9.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-59118 | Copilot Cowork Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-62834 | Azure Data Factory Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-70306 | Microsoft Office SharePoint Spoofing Vulnerability | CRITICAL | 9.3 | 53%ile | Microsoft | 2026-08-11 |
| CVE-2026-53791 | rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header | CRITICAL | 9.1 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-68160 | ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() | CRITICAL | 9.1 | 53%ile | Microsoft | 2026-08-11 |
| CVE-2026-73194 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the | CRITICAL | 9.1 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-66309 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-68823 | Azure Confidential Ledger Remote Code Execution Vulnerability | CRITICAL | 9.1 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2025-30156 | Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery | HIGH | 8.9 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-13622 | Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host | HIGH | 8.8 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-14662 | PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound | HIGH | 8.8 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-14664 | PostgreSQL regexp heap buffer overflow executes arbitrary code | HIGH | 8.8 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-14670 | PostgreSQL plperl tied object heap buffer overflow executes arbitrary code | HIGH | 8.8 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-14671 | PostgreSQL refint plan cache type confusion executes arbitrary code | HIGH | 8.8 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-14677 | PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound | HIGH | 8.8 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-14680 | PostgreSQL type confusion via "internal" arguments | HIGH | 8.8 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-15741 | PostgreSQL expression deparse allows SQL injection via EXTRACT argument | HIGH | 8.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-15742 | PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound | HIGH | 8.8 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-16238 | PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code | HIGH | 8.8 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-16239 | PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code | HIGH | 8.8 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-18408 | PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client | HIGH | 8.8 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-19385 | PostgreSQL pg_dump heap buffer overflow executes arbitrary code | HIGH | 8.8 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-63639 | Valkey: UAF in stream deserialization may lead to remote code execution | HIGH | 8.8 | 58%ile | Microsoft | 2026-08-11 |
| CVE-2026-68480 | x86/bugs: Make Safe-RET robust against interrupt injection | HIGH | 8.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-74556 | scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer | HIGH | 8.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-24301 | Microsoft Copilot Information Disclosure Vulnerability | HIGH | 8.8 | 85%ile | Microsoft | 2026-08-11 |
| CVE-2026-49163 | Application Insights Profiler Elevation of Privilege Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-08-11 |
| CVE-2026-49179 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-08-11 |
| CVE-2026-57104 | Azure Storage Explorer Elevation of Privilege Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-08-11 |
| CVE-2026-59113 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-59133 | Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-08-11 |
| CVE-2026-62784 | Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-08-11 |
| CVE-2026-62785 | Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-08-11 |
| CVE-2026-62790 | Windows SMBv3 Server Remote Code Execution Vulnerability | HIGH | 8.8 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-62795 | Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-62800 | Windows SMBv3 Server Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-08-11 |
| CVE-2026-62816 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | HIGH | 8.8 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-62817 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.8 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-62818 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | HIGH | 8.8 | 60%ile | Microsoft | 2026-08-11 |
| CVE-2026-62822 | Windows GDI+ Remote Code Execution Vulnerability | HIGH | 8.8 | 49%ile | Microsoft | 2026-08-11 |
| CVE-2026-62823 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 8.8 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-62824 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 49%ile | Microsoft | 2026-08-11 |
| CVE-2026-62827 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-08-11 |
| CVE-2026-62869 | Azure Entra ID Spoofing Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-08-11 |
| CVE-2026-62872 | .NET Framework Elevation of Privilege Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-62913 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH | 8.8 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-63514 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 73%ile | Microsoft | 2026-08-11 |
| CVE-2026-64901 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 79%ile | Microsoft | 2026-08-11 |
| CVE-2026-64921 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 61%ile | Microsoft | 2026-08-11 |
| CVE-2026-65658 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 71%ile | Microsoft | 2026-08-11 |
| CVE-2026-65660 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-08-11 |
| CVE-2026-65663 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 71%ile | Microsoft | 2026-08-11 |
| CVE-2026-65665 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 86%ile | Microsoft | 2026-08-11 |
| CVE-2026-65668 | Microsoft Purview eDiscovery Elevation of Privilege Vulnerability | HIGH | 8.8 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-65767 | Microsoft Teams for Android Spoofing Vulnerability | HIGH | 8.8 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-65768 | Microsoft Teams Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-65807 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 8.8 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-65811 | Power BI Remote Code Execution Vulnerability | HIGH | 8.8 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-65815 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-08-11 |
| CVE-2026-66805 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 74%ile | Microsoft | 2026-08-11 |
| CVE-2026-66808 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 64%ile | Microsoft | 2026-08-11 |
| CVE-2026-69320 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 8.8 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-70321 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 69%ile | Microsoft | 2026-08-11 |
| CVE-2026-70324 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-70326 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-70329 | Microsoft Outlook Remote Code Execution Vulnerability | HIGH | 8.8 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-70336 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-70337 | Microsoft PowerShell Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-08-11 |
| CVE-2026-72984 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-68451 | s390/zcrypt: Validate length for CCA ECC private key requests | HIGH | 8.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-62836 | Azure SQL Managed Instance Elevation of Privilege Vulnerability | HIGH | 8.7 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-64597 | smb: client: fix double-free in SMB2_close() replay | HIGH | 8.6 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-66800 | Azure Data Factory Information Disclosure Vulnerability | HIGH | 8.6 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-69519 | Azure Stack HCI Information Disclosure Vulnerability | HIGH | 8.6 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-69558 | Microsoft Partner Center Information Disclosure Vulnerability | HIGH | 8.6 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-69419 | Azure Data Manager for Energy Remote Code Execution Vulnerability | HIGH | 8.5 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-69543 | Azure Virtual Machines Elevation of Privilege Vulnerability | HIGH | 8.5 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-70341 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.5 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-56865 | Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog | HIGH | 8.4 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-63388 | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept | HIGH | 8.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-64604 | KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode | HIGH | 8.4 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-70130 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-56179 | Windows Network Address Translation (NAT) Spoofing Vulnerability | HIGH | 8.3 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-72970 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-74649 | staging: rtl8723bs: fix missing shared-key auth challenge length check | HIGH | 8.3 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-49825 | lxml: javascript: URL bypass in Cleaner via xlink:href | HIGH | 8.2 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-68082 | libceph: fix two unsafe bare decodes in decode_lockers() | HIGH | 8.2 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-70456 | rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() | HIGH | 8.2 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-70458 | rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling | HIGH | 8.2 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-70461 | rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry | HIGH | 8.2 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-74611 | tls: rx: restore msg_iter before TLS 1.3 optimistic retry | HIGH | 8.2 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-69306 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.2 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-14668 | PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read | HIGH | 8.1 | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-53783 | rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync | HIGH | 8.1 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-53790 | rsync < 3.5.0 Command Injection via Multiple Code Paths | HIGH | 8.1 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-53795 | rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest | HIGH | 8.1 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-54330 | Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation | HIGH | 8.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-6464 | PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands | HIGH | 8.1 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-68366 | usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer | HIGH | 8.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68470 | wifi: mac80211: validate extension-frame layout before RX | HIGH | 8.1 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-68471 | wifi: ieee80211: validate MLE common info length | HIGH | 8.1 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-70460 | rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink | HIGH | 8.1 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-72398 | sctp: add INIT verification after cookie unpacking | HIGH | 8.1 | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-74488 | wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames | HIGH | 8.1 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-77176 | Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy | HIGH | 8.1 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-62778 | Windows DNS Elevation of Privilege Vulnerability | HIGH | 8.1 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-62781 | RPC Runtime Library Remote Code Execution Vulnerability | HIGH | 8.1 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-62792 | Windows TCP/IP Remote Code Execution Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-62819 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.1 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-62820 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.1 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-62889 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | HIGH | 8.1 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-63520 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.1 | 86%ile | Microsoft | 2026-08-11 |
| CVE-2026-65679 | Windows iSCSI Target Service Remote Code Execution Vulnerability | HIGH | 8.1 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-65789 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.1 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-65796 | Windows iSCSI Target Service Remote Code Execution Vulnerability | HIGH | 8.1 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-66802 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability | HIGH | 8.1 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-70340 | Azure CycleCloud Elevation of Privilege Vulnerability | HIGH | 8.1 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-71331 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability | HIGH | 8.1 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-70454 | rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode | HIGH | 8.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-57105 | Microsoft Office SharePoint Spoofing Vulnerability | HIGH | 8.0 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-62911 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 8.0 | 70%ile | Microsoft | 2026-08-11 |
| CVE-2026-6726 | MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse | HIGH | 7.9 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-13732 | Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf | HIGH | 7.8 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19582 | Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe file | HIGH | 7.8 | — | Microsoft | 2026-08-11 |
| CVE-2026-53803 | rsync < 3.5.0 Symlink Following Arbitrary File Overwrite | HIGH | 7.8 | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-68108 | drm/amdgpu/vce: fix integer overflow in image size | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68152 | amt: fix use-after-free in AMT delayed works | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68181 | mei: bus: access mei_device under device_lock on cleanup | HIGH | 7.8 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68186 | binfmt_misc: set have_execfd only once the interpreter is opened | HIGH | 7.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68188 | Bluetooth: RFCOMM: Fix session UAF in set_termios | HIGH | 7.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68318 | pds_core: fix use-after-free on workqueue during remove | HIGH | 7.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68335 | rds: drop incoming messages that cross network namespace boundaries | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68416 | mtd: fix double free and WARN_ON in add_mtd_device() error paths | HIGH | 7.8 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-72693 | Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login | HIGH | 7.8 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-74443 | drm/vmwgfx: bound DMA command body size against suffix pointer | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74454 | drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74641 | ALSA: usx2y: bound the hwdep mmap fault offset | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74746 | netfilter: flowtable: publish GC-visible tuple last | HIGH | 7.8 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-79655 | Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file wr | HIGH | 7.8 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-79992 | Emacs: local shell command injection through the user field in emacs tramp | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80552 | s390/vfio_ccw: Ensure index for read/write regions are within range | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80560 | openrisc: signal: do not restore privileged SR bits on sigreturn | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80568 | Input: synaptics-rmi4 - block s_input when F54 queue is busy | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80706 | can: softing: fw_parse(): validate firmware record spans | HIGH | 7.8 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-82474 | Sudo through 1.9.17p2 Intercept Policy Bypass via execveat | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-42976 | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-50523 | Microsoft PowerShell Remote Code Execution Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-54981 | Visual Studio Code Python Extension Security Feature Bypass Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-54984 | Windows Imaging Component Remote Code Execution Vulnerability | HIGH | 7.8 | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-56174 | Windows Narrator Braille Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-58641 | .NET Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-58650 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-58651 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-59127 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-61349 | Windows Work Folder Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-61353 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-61355 | Windows Sensor Data Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-61356 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-61357 | Application Information Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-61358 | Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability | HIGH | 7.8 | 89%ile | Microsoft | 2026-08-11 |
| CVE-2026-61359 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-61364 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-61365 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-61367 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-61923 | Windows Display Enhancement Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-61925 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-61926 | Windows USB Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-61930 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 81%ile | Microsoft | 2026-08-11 |
| CVE-2026-61932 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-61934 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-61937 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62688 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-62692 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62695 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62696 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2026-08-11 |
| CVE-2026-62698 | Microsoft Digest Authentication Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-62700 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62701 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62707 | Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62710 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62711 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62712 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-62713 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 79%ile | Microsoft | 2026-08-11 |
| CVE-2026-62717 | Windows Message Queuing Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62719 | Windows Message Queuing Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62721 | Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-62722 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62732 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62733 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62735 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-62736 | Windows DHCP Client Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62737 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 86%ile | Microsoft | 2026-08-11 |
| CVE-2026-62739 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-62741 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 81%ile | Microsoft | 2026-08-11 |
| CVE-2026-62747 | Windows Device Association Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62751 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62752 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62754 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62755 | Windows DHCP Client Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62758 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62761 | Windows DHCP Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-62768 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62770 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62771 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-62772 | Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62776 | Windows DHCP Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-62777 | Windows License Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-62779 | Windows Schannel Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62783 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 79%ile | Microsoft | 2026-08-11 |
| CVE-2026-62797 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-62799 | Windows SMB Client Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-62803 | Windows DHCP Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-62807 | Windows DHCP Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-62811 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-62812 | Windows DHCP Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-62832 | Windows User Profile Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2026-08-11 |
| CVE-2026-62871 | .NET Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-62876 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62877 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62880 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62885 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-62886 | .NET Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-62888 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 79%ile | Microsoft | 2026-08-11 |
| CVE-2026-62890 | Windows GDI+ Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-62894 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-62909 | .NET Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-63513 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-63515 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-63518 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-63519 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-63522 | Azure SQL Database Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-63525 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-63526 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-63527 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-63532 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-63533 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-64898 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64903 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64904 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-64905 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-64906 | Microsoft Access Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-64907 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64908 | Microsoft Access Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-64909 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64910 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64911 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64912 | Microsoft Access Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-64914 | Microsoft Access Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-64915 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-64919 | Microsoft Access Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-64920 | Microsoft Access Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-65656 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-65657 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-65661 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-65664 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-65671 | Remote Access API Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-65672 | Remote Access API Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-65673 | Microsoft Entra Connect Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-65773 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-65774 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-65775 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 85%ile | Microsoft | 2026-08-11 |
| CVE-2026-65786 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-65787 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-65790 | Windows Message Queuing Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-65810 | .NET Framework Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-65814 | Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-66799 | Windows Key Guard Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-66804 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 92%ile | Microsoft | 2026-08-11 |
| CVE-2026-66807 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-68792 | Microsoft Office Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-68793 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-68794 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-68795 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-68796 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-68798 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-68800 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-68801 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-68803 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-68804 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-68805 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-68806 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-68807 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-68810 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-68811 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-68812 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-68814 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-68815 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-68816 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-68817 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-69278 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-69414 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-70311 | Microsoft Office Word Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-70313 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-70335 | GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-70338 | Microsoft PowerShell Security Feature Bypass Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-70344 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-70345 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-70346 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-70347 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-70354 | .NET Core Remote Code Execution Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-68124 | mctp: serial: handle zero-length frames to prevent rx buffer overflow | HIGH | 7.7 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-69855 | Microsoft Copilot in Azure Information Disclosure Vulnerability | HIGH | 7.7 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2025-49506 | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack | HIGH | 7.5 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-14457 | RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate | HIGH | 7.5 | 61%ile | Microsoft | 2026-08-11 |
| CVE-2026-19654 | Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote p | HIGH | 7.5 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-20337 | ClamAV ZIP File Format Processing Memory Corruption Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-20338 | ClamAV ZIP File Format Processing Memory Corruption Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-20339 | ClamAV PESpin File Format Processing Integer Overflow Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-20345 | ClamAV GPT File Format Processing Memory Corruption Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-20346 | ClamAV PDF File Format Processing Memory Corruption Vulnerability | HIGH | 7.5 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-20347 | ClamAV Mach-O File Format Processing Memory Corruption Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-20348 | ClamAV XAR File Format Processing Memory Corruption Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-33818 | Enforce maximum recursion depth in encoding/asn1 | HIGH | 7.5 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-34501 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | HIGH | 7.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-34502 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client | HIGH | 7.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-47895 | In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but no | HIGH | 7.5 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-54874 | Excessive Memory Use Buffering DTLS Records for a Future Epoch | HIGH | 7.5 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-55620 | eml_parser: DoS via deeply nested parens in Received headers | HIGH | 7.5 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-56684 | Valkey: TLS pending-data processing use-after-free may allow remote code execution | HIGH | 7.5 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-56853 | Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http | HIGH | 7.5 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-56859 | Add recursion depth guard during decode in encoding/xml | HIGH | 7.5 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-56862 | Limit handshake messages we are willing to accept post-handshake in crypto/tls | HIGH | 7.5 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-56864 | Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb | HIGH | 7.5 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-63072 | Heap Buffer Overflow in CMS Key Unwrapping | HIGH | 7.5 | 51%ile | Microsoft | 2026-08-11 |
| CVE-2026-63075 | QUIC ACK-only Packet Retention Can Cause Memory Exhaustion | HIGH | 7.5 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-63076 | Invalid Pointer Dereference in CMP Server via Crafted protectionAlg | HIGH | 7.5 | 70%ile | Microsoft | 2026-08-11 |
| CVE-2026-65819 | gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS | HIGH | 7.5 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-66046 | Expat Denial of Service via storeAtts() Quadratic Complexity | HIGH | 7.5 | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-68155 | libceph: Reject monmaps advertising zero monitors | HIGH | 7.5 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-68299 | vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets | HIGH | 7.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-68320 | sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid | HIGH | 7.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68373 | wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() | HIGH | 7.5 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-70453 | rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() | HIGH | 7.5 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-70455 | rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion | HIGH | 7.5 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-70464 | rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall | HIGH | 7.5 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-71217 | Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource e | HIGH | 7.5 | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-72469 | xprtrdma: Fix ep kref imbalance on ADDR_CHANGE | HIGH | 7.5 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-73566 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar w | HIGH | 7.5 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-74480 | net: bridge: stop fast-leave after deleting a port group | HIGH | 7.5 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-74516 | KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active | HIGH | 7.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74621 | net/sched: act_ct: fix sk_buff leak when the header checks reject a packet | HIGH | 7.5 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-74704 | net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter | HIGH | 7.5 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-76098 | Mistune has Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown | HIGH | 7.5 | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-76956 | In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, w | HIGH | 7.5 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-78002 | Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function | HIGH | 7.5 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-80573 | Input: iforce - validate input packet lengths | HIGH | 7.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-82251 | gitoxide before 0.52.1 Path Traversal via Submodule Name | HIGH | 7.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-82252 | gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules | HIGH | 7.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-82253 | gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass | HIGH | 7.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-82254 | gitoxide before 0.69.0 Denial of Service via gix-pack | HIGH | 7.5 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-54113 | Remote Procedure Call Denial of Service Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-08-11 |
| CVE-2026-59132 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.5 | 76%ile | Microsoft | 2026-08-11 |
| CVE-2026-59134 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-61352 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-61363 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-62787 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.5 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-62898 | Microsoft QUIC Information Disclosure Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-08-11 |
| CVE-2026-62901 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-08-11 |
| CVE-2026-62918 | Microsoft Teams Spoofing Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-65681 | Windows iSCSI Target Service Denial of Service Vulnerability | HIGH | 7.5 | 58%ile | Microsoft | 2026-08-11 |
| CVE-2026-14456 | Unbounded Memory Growth in QUIC Server Incoming Channel Queue | HIGH | 7.5 | 53%ile | Microsoft | 2026-08-11 |
| CVE-2026-54876 | Client-Side Memory Leak in OCSP Response Checking | HIGH | 7.5 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-53793 | rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode | HIGH | 7.4 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-63073 | Untrusted Sender DN Used as Format String in CMP Response Validation | HIGH | 7.4 | 59%ile | Microsoft | 2026-08-11 |
| CVE-2026-70452 | rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure | HIGH | 7.4 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-72320 | netfilter: nft_lookup: fix catchall element handling with inverted lookups | HIGH | 7.4 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-74469 | sctp: prevent peer transport count overflow | HIGH | 7.4 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-74597 | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() | HIGH | 7.4 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-74669 | ipvs: clear IPv4 options after rebasing tunnel ICMP errors | HIGH | 7.4 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-58612 | PowerShell Information Disclosure Vulnerability | HIGH | 7.4 | 55%ile | Microsoft | 2026-08-11 |
| CVE-2026-68337 | bpf: Reject redirect helpers without a bpf_net_context | HIGH | 7.3 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-71226 | Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path | HIGH | 7.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-59119 | PowerShell Elevation of Privilege Vulnerability | HIGH | 7.3 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-62914 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 7.3 | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-64900 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-68821 | Windows Package Manager Elevation of Privilege Vulnerability | HIGH | 7.3 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-70355 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | HIGH | 7.3 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-6471 | PostgreSQL logical decoding can dlopen arbitrary file | HIGH | 7.2 | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-47299 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 7.2 | 59%ile | Microsoft | 2026-08-11 |
| CVE-2026-62910 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 7.2 | 51%ile | Microsoft | 2026-08-11 |
| CVE-2026-19589 | Packer vulnerable to arbitrary file write via crafted plugin archive during installation | HIGH | 7.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-49114 | ONNX symlink-following and path-traversal arbitrary file write | HIGH | 7.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-53784 | rsync < 3.5.0 Path Traversal via Symlink Module Root | HIGH | 7.1 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-53785 | rsync < 3.5.0 Path Traversal Write Escape via --relative Mode | HIGH | 7.1 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-53802 | rsync < 3.5.0 Arbitrary File Read via Symlink Following | HIGH | 7.1 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-56136 | In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attack | HIGH | 7.1 | 0%ile | Microsoft | 2026-08-11 |
| CVE-2026-64590 | dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning | HIGH | 7.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68083 | ksmbd: fix path resolution in ksmbd_vfs_kern_path_create | HIGH | 7.1 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-68084 | staging: vme_user: fix location monitor leak in tsi148 bridge | HIGH | 7.1 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68085 | Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled | HIGH | 7.1 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-68088 | usb: gadget: function: rndis: add length check to response query | HIGH | 7.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68104 | drm/amdgpu: invoke pm_genpd_remove() before freeing genpd | HIGH | 7.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68130 | ksmbd: defer destroy_previous_session() until after NTLM authentication | HIGH | 7.1 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68135 | net: hip04: fix RX buffer leak on build_skb failure | HIGH | 7.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68138 | net/sched: serialize qdisc_rtab_list against concurrent get/put | HIGH | 7.1 | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-68162 | sctp: avoid auth_enable sysctl UAF during netns teardown | HIGH | 7.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68165 | mm/damon/core: validate ranges in damon_set_regions() | HIGH | 7.1 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68182 | comedi: comedi_parport: deal with premature interrupt | HIGH | 7.1 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68199 | wifi: ath6kl: fix OOB access from firmware ADDBA window size | HIGH | 7.1 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-68204 | media: vivid: check for vb2_is_busy() when toggling caps | HIGH | 7.1 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68284 | bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() | HIGH | 7.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68286 | drop_monitor: perform u64_stats updates under IRQ-disabled section | HIGH | 7.1 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-68294 | net: qrtr: restrict socket creation to the initial network namespace | HIGH | 7.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68306 | wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() | HIGH | 7.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68348 | ASoC: tas2781: bound firmware description string parsing | HIGH | 7.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68350 | wifi: carl9170: fix OOB read from off-by-two in TX status handler | HIGH | 7.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68351 | wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read | HIGH | 7.1 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68352 | wifi: ath6kl: fix OOB read from firmware IE lengths in connect event | HIGH | 7.1 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-68353 | wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler | HIGH | 7.1 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-68365 | USB: serial: io_edgeport: cap received transmit credits | HIGH | 7.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68368 | usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() | HIGH | 7.1 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68371 | usb: musb: omap2430: Do not put borrowed of_node in probe | HIGH | 7.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68397 | net/iucv: take a reference on the socket found in afiucv_hs_rcv() | HIGH | 7.1 | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-68414 | wifi: cfg80211: cancel sched scan results work on unregister | HIGH | 7.1 | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-71556 | go-git: Worktree operations may follow symlinks | HIGH | 7.1 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-72329 | net/liquidio: drop cached VF pci_dev LUT | HIGH | 7.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-72568 | Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message Handler | HIGH | 7.1 | — | Microsoft | 2026-08-11 |
| CVE-2026-74444 | drm/vmwgfx: validate DRAW_PRIMITIVES header size before division | HIGH | 7.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74739 | net/sched: cls_u32: skip hash tables in u32_bind_class() | HIGH | 7.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74743 | macvlan: inherit needed_headroom and needed_tailroom from lowerdev | HIGH | 7.1 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-77219 | GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader | HIGH | 7.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80536 | xfs: bounds-check buffer log item's dirty bitmap | HIGH | 7.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80551 | s390/vfio_ccw: Ensure first IDAW remains constant | HIGH | 7.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80561 | libceph: fix multiple unsafe decodes in decode_locker() | HIGH | 7.1 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-80562 | gpio: ml-ioh: use raw_spinlock_t for the register lock | HIGH | 7.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80579 | fbdev: clear fb_info->mode before deleting a videomode | HIGH | 7.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80668 | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations | HIGH | 7.1 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-80680 | i2c: amd-mp2: Unregister callback on adapter add failure | HIGH | 7.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80708 | s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() | HIGH | 7.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-82455 | RubyGems before 4.0.13 Path Traversal via Symlink Resolution | HIGH | 7.1 | — | Microsoft | 2026-08-11 |
| CVE-2026-55013 | Windows Remote Help Defense Spoofing Vulnerability | HIGH | 7.1 | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-65675 | CoPilot Chat Security Feature Bypass Vulnerability | HIGH | 7.1 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-68453 | s390/zcrypt: Fix buffer over-read in cca_cipher2protkey | HIGH | 7.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-63387 | Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response | HIGH | 7.0 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-64582 | RDMA/rxe: Fix a use-after-free problem in rxe_mmap | HIGH | 7.0 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68329 | iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() | HIGH | 7.0 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-72383 | sctp: fix addr_wq_timer race in sctp_free_addr_wq() | HIGH | 7.0 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74257 | sockmap: Fix use-after-free in udp_bpf_recvmsg() | HIGH | 7.0 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74334 | RDMA/nldev: Fix locking when accessing mr->pd | HIGH | 7.0 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74446 | drm/amdkfd: hold event_mutex while checkpointing CRIU events | HIGH | 7.0 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74518 | mm/hugetlb: fix list corruption in allocate_file_region_entries() | HIGH | 7.0 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74563 | rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() | HIGH | 7.0 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74586 | sctp: clear new_transport when removing a peer | HIGH | 7.0 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74630 | ipv6: prevent in6_dev_get() from resurrecting inet6_dev | HIGH | 7.0 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74752 | sctp: validate cookie AUTH state before use | HIGH | 7.0 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-50472 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-59122 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-59125 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-59126 | Windows Event Logging Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-61346 | Windows Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-61348 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 74%ile | Microsoft | 2026-08-11 |
| CVE-2026-61361 | Windows DHCP Client Remote Code Execution Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-61366 | Windows Network Connection Broker Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-61927 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-61929 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 76%ile | Microsoft | 2026-08-11 |
| CVE-2026-61938 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-61939 | Winlogon Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-62690 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-62693 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-62705 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-62723 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-62724 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-62725 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-62726 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-62727 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-62728 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-62729 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-62734 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-62748 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-62749 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-62753 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-62766 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.0 | 74%ile | Microsoft | 2026-08-11 |
| CVE-2026-62773 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-62774 | Windows Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-62780 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-62788 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-62892 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-62897 | .NET Framework Remote Code Execution Vulnerability | HIGH | 7.0 | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-62908 | Windows Backup Engine Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-65678 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-65776 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-65778 | Windows Autopilot Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-65779 | Windows Autopilot Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-65780 | Windows Autopilot Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-65781 | Windows Autopilot Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-65782 | Windows Autopilot Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-65783 | Windows Autopilot Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-65788 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.0 | 76%ile | Microsoft | 2026-08-11 |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 93%ile | Microsoft | 2026-08-11 |
| CVE-2026-70307 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-62699 | Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability | MEDIUM | 6.8 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-62702 | Windows Graphics Kernel Denial of Service Vulnerability | MEDIUM | 6.8 | 60%ile | Microsoft | 2026-08-11 |
| CVE-2026-68093 | KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug | MEDIUM | 6.7 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-72198 | ntfs: reject non-resident records for resident-only attributes | MEDIUM | 6.7 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-72200 | ntfs: detect mapping-pairs LCN accumulator overflow | MEDIUM | 6.7 | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-62769 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-62881 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-62883 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-65680 | Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-65795 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-65797 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-65798 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-65799 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-70304 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-70330 | Windows DNS Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-18917 | Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow | MEDIUM | 6.6 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68086 | mm/khugepaged: write all dirty file folios when collapsing | MEDIUM | 6.6 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74458 | can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents | MEDIUM | 6.6 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74498 | ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set | MEDIUM | 6.6 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-61920 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.6 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-14663 | PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext | MEDIUM | 6.5 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-18726 | Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing | MEDIUM | 6.5 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-18727 | Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing | MEDIUM | 6.5 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-18728 | Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing | MEDIUM | 6.5 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-19953 | URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in | MEDIUM | 6.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-53583 | libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend | MEDIUM | 6.5 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-53786 | rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-53788 | rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-53789 | rsync < 3.5.0 Arbitrary File Deletion via Malicious File List | MEDIUM | 6.5 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-53792 | rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-55618 | eml_parser: URL extraction bypass via HTML entities in URLs | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-56135 | In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/sec | MEDIUM | 6.5 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-68098 | ksmbd: bound DACL dedup walk to copied ACEs | MEDIUM | 6.5 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-68116 | vxlan: mdb: Fix source list corruption on a failed replace | MEDIUM | 6.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68125 | mac802154: llsec: reject frames shorter than the authentication tag | MEDIUM | 6.5 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-68129 | gve: fix Rx queue stall on alloc failure | MEDIUM | 6.5 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-68136 | net: gro: fix double aggregation of flush-marked skbs | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-68158 | libceph: Fix multiplication overflow in decode_new_up_state_weight() | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-68159 | libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-08-11 |
| CVE-2026-68411 | wifi: mac80211_hwsim: clamp virtio RX length before skb_put | MEDIUM | 6.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-70368 | Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message | MEDIUM | 6.5 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-70457 | rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-70462 | rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT | MEDIUM | 6.5 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-70622 | tar-rs 0.4.11 - 0.4.46 Symlink Escape via append_dir_all() | MEDIUM | 6.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-71225 | Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries | MEDIUM | 6.5 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-72712 | Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet | MEDIUM | 6.5 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-72816 | go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware | MEDIUM | 6.5 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-72817 | go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For | MEDIUM | 6.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74356 | vhost: fix vhost_get_avail_idx for a non empty ring | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-74588 | sctp: keep chunk->transport in step with the list it is queued on | MEDIUM | 6.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74625 | netfilter: bridge: release template ct on non-IP path | MEDIUM | 6.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74691 | net: thunderbolt: Tear down DMA paths before stopping the rings | MEDIUM | 6.5 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-80722 | wifi: mac80211: validate individual TWT params before driver setup | MEDIUM | 6.5 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-40375 | Microsoft Dynamics Business Central Information Disclosure Vulnerability | MEDIUM | 6.5 | 54%ile | Microsoft | 2026-08-11 |
| CVE-2026-47285 | Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-08-11 |
| CVE-2026-58639 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-08-11 |
| CVE-2026-59138 | Microsoft Remote Registry Service Denial of Service Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2026-08-11 |
| CVE-2026-61345 | Microsoft Remote Registry Service Denial of Service Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2026-08-11 |
| CVE-2026-61918 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-08-11 |
| CVE-2026-61921 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-08-11 |
| CVE-2026-61924 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-08-11 |
| CVE-2026-62714 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-62715 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-62716 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-62718 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-62720 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-62742 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-62745 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-62750 | Windows HTTP Protocol Stack Tampering Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-62782 | Windows SMB Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-08-11 |
| CVE-2026-62814 | Windows DHCP Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-62837 | Microsoft SharePoint Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-08-11 |
| CVE-2026-62839 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 49%ile | Microsoft | 2026-08-11 |
| CVE-2026-62902 | .NET Information Disclosure Vulnerability | MEDIUM | 6.5 | 54%ile | Microsoft | 2026-08-11 |
| CVE-2026-62912 | Microsoft Exchange Server Denial of Service Vulnerability | MEDIUM | 6.5 | 69%ile | Microsoft | 2026-08-11 |
| CVE-2026-62915 | Microsoft Exchange Server Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-63512 | Microsoft SharePoint Server Tampering Vulnerability | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-63516 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 70%ile | Microsoft | 2026-08-11 |
| CVE-2026-65769 | Microsoft Teams iOS Information Disclosure Vulnerability | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-65785 | Windows DHCP Client Denial of Service Vulnerability | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-65794 | Windows SMB Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-65806 | Azure CycleCloud Information Disclosure Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-65813 | Microsoft Exchange Server Elevation of Privilege Vulnerability | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-66301 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-08-11 |
| CVE-2026-66324 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-69550 | Windows App for Mac Information Disclosure Vulnerability | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-70105 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 6.5 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-70327 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-08-11 |
| CVE-2026-70328 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-08-11 |
| CVE-2026-82250 | gitoxide gix-packetline before 0.21.5 Denial of Service | MEDIUM | 6.5 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-72042 | ipmi: Fix user refcount underflow in event delivery | MEDIUM | 6.4 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-72404 | tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy() | MEDIUM | 6.4 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74289 | ipv4: fib: Don't dump dying fib_info in fib_leaf_notify(). | MEDIUM | 6.4 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74314 | bpf: Cancel special fields on map value recycle | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74344 | bpf: Clear rb node linkage when freeing bpf_rb_root | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74347 | netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount | MEDIUM | 6.4 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74450 | drm/amd/pm: fix pptable use-after-free | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74465 | net: openvswitch: fix potential UAF on meter attach failure | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74474 | vxlan: use pskb_network_may_pull() for transmit path header pulls | MEDIUM | 6.4 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-74479 | net: pktgen: fix proc entry use-after-free | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74482 | mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74496 | fou: Fix use-after-free in fou_create() | MEDIUM | 6.4 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74510 | Bluetooth: mgmt: fix UAF in pair command cancellation | MEDIUM | 6.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74511 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | MEDIUM | 6.4 | — | Microsoft | 2026-08-11 |
| CVE-2026-74512 | audit: fix potential use-after-free in audit_del_rule() | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74519 | pinctrl: devicetree: don't free uninitialized dev_name on error path | MEDIUM | 6.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74548 | forcedeth: fix UAF of txrx_stats in nv_remove | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74580 | vhost: reset the vring metadata cache on vring reconfiguration | MEDIUM | 6.4 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74599 | mm/ptdump: always stabilise against page table freeing using init_mm | MEDIUM | 6.4 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74668 | packet: use consistent hard_header_len in TX_RING send path | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-62708 | Windows Kernel Elevation of Privilege Vulnerability | MEDIUM | 6.4 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-53796 | rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling | MEDIUM | 6.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-53799 | rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application | MEDIUM | 6.3 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-64573 | Bluetooth: qca: fix NVM tag length underflow in TLV parser | MEDIUM | 6.3 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68097 | ksmbd: validate ACE size against SID sub-authorities | MEDIUM | 6.3 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-68196 | wifi: wilc1000: validate assoc response length before subtracting header | MEDIUM | 6.3 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-68323 | tipc: serialize udp bearer replicast list updates | MEDIUM | 6.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68361 | hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop | MEDIUM | 6.3 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-71557 | go-git: Malicious reference names may modify files outside the reference storage | MEDIUM | 6.3 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-74302 | Bluetooth: hci_core: Fix UAF in hci_unregister_dev() | MEDIUM | 6.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74490 | tipc: avoid use-after-free in poll trace queue dumps | MEDIUM | 6.3 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-74509 | Bluetooth: hci_sync: Fix advertising data UAFs | MEDIUM | 6.3 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-74531 | Bluetooth: hci_conn: hold conn reference in abort_conn_sync() | MEDIUM | 6.3 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-74549 | hwmon: (nct6775-core) Prevent access to unsupported weight registers | MEDIUM | 6.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74715 | bpf: Fix netns reference imbalance in conntrack kfuncs | MEDIUM | 6.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74724 | ipvs: avoid out-of-bounds write in ip_vs_nat_icmp | MEDIUM | 6.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-75032 | Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder | MEDIUM | 6.3 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-80529 | xfs: don't swallow dquot recovery verification errors | MEDIUM | 6.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74729 | soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read | MEDIUM | 6.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-72522 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same | MEDIUM | 6.2 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-54770 | WebOb: Open redirect in Location header normalization via leading C0 control / space characters | MEDIUM | 6.1 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-56858 | Fix Javascript regexp context tracking in html/template | MEDIUM | 6.1 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-68187 | exec: fix unsigned loop counter wrap in transfer_args_to_stack() | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68273 | drm/amdgpu: Fix context pstate override handling | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68326 | wifi: mwifiex: bound uAP association event IEs to the event buffer | MEDIUM | 6.1 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-74595 | fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() | MEDIUM | 6.1 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-74635 | fbdev: bitblit: bound-check glyph index in bit_cursor() | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-75900 | Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatch | MEDIUM | 6.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80576 | drm/amdgpu: reject oversized IBs with per-ring packet limits | MEDIUM | 6.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80702 | drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68081 | KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state | MEDIUM | 6.0 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-72423 | bpf: Guard conntrack opts error writes | MEDIUM | 6.0 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74553 | hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 | MEDIUM | 6.0 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74616 | xdp: reject clones that overrun skb_shared_info tailroom | MEDIUM | 6.0 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-53572 | KEDA: PostgreSQL connection string parameter injection via incomplete whitespace escaping | MEDIUM | 5.9 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-53801 | rsync < 3.5.0 Symlink Race Condition Directory Traversal | MEDIUM | 5.9 | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-56860 | Avoid quadratic complexity in resolvePath in net/url | MEDIUM | 5.9 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-63074 | CMP Indefinite Cache Growth of ExtraCerts | MEDIUM | 5.9 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-68381 | ksmbd: pin conn during async oplock break notification | MEDIUM | 5.9 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-74455 | can: peak_usb: validate uCAN receive record lengths | MEDIUM | 5.9 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74457 | can: peak_usb: add bounds check for USB channel index | MEDIUM | 5.9 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74473 | vxlan: use pskb_network_may_pull() in route_shortcircuit() | MEDIUM | 5.9 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-74550 | net: do not send ICMP/NDISC Redirects when peer allocation fails | MEDIUM | 5.9 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-74569 | netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() | MEDIUM | 5.9 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-74587 | sctp: fix use-after-free of cached ASCONF chunk | MEDIUM | 5.9 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74624 | netfilter: nf_conntrack: defer invalid log until after unlock | MEDIUM | 5.9 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-74682 | ALSA: usb-audio: fix OOB write on Type II inbound URBs | MEDIUM | 5.9 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74688 | sctp: clear control chunk transport if it is being removed | MEDIUM | 5.9 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74692 | net/smc: fix TOCTOU race between smc_listen_out() and listener close | MEDIUM | 5.9 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-74696 | tcp: fix TFO max_qlen accounting across reuseport migration | MEDIUM | 5.9 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-74697 | bnxt_en: Disable EOP for TPA on all chips to prevent data corruption | MEDIUM | 5.9 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-74705 | udp: fix potential use-after-free in tunnel segmentation | MEDIUM | 5.9 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74730 | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call | MEDIUM | 5.9 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-80558 | libceph: Avoid using invalid osd indices from primary_temp | MEDIUM | 5.9 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-62899 | .NET Security Feature Bypass Vulnerability | MEDIUM | 5.9 | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-62900 | .NET Information Disclosure Vulnerability | MEDIUM | 5.9 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-6727 | MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability | MEDIUM | 5.9 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68819 | Windows Network File System Denial of Service Vulnerability | MEDIUM | 5.9 | 51%ile | Microsoft | 2026-08-11 |
| CVE-2026-74647 | misc: fastrpc: Remove buffer from list prior to unmap operation | MEDIUM | 5.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-15534 | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersiz | MEDIUM | 5.7 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68123 | openvswitch: fix GSO userspace truncation underflow | MEDIUM | 5.7 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-72098 | dm-verity: fix buffer overflow in FEC calculation | MEDIUM | 5.7 | 50%ile | Microsoft | 2026-08-11 |
| CVE-2026-72397 | hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid() | MEDIUM | 5.7 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74499 | ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() | MEDIUM | 5.7 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74582 | packet: use consistent hard_header_len in non-ring send paths | MEDIUM | 5.7 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74607 | KVM: SVM: Serialize accesses to the owner and mirror list with separate lock | MEDIUM | 5.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74670 | ipvs: stop estimator after disabled calc phase | MEDIUM | 5.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-59130 | AMD Zen Information Disclosure Vulnerability | MEDIUM | 5.6 | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-59131 | AMD Zen Information Disclosure Vulnerability | MEDIUM | 5.6 | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-74648 | staging: rtl8723bs: validate monitor transmit frame lengths | MEDIUM | 5.6 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-15059 | systemd-oomd: unprivileged users can terminate arbitrary processes | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19548 | Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19617 | Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-44605 | Rpm: heap buffer overflow in ndb slot table parsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-63623 | Libvirt: information disclosure via world-readable storage volume images during clone/convert | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-64561 | KVM: x86: Check for invalid/obsolete root *after* making MMU pages available | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64563 | rhashtable: clear stale iter->p on table restart | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-64569 | mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-64585 | can: esd_usb: kill anchored URBs before freeing netdevs | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-64586 | wifi: brcmfmac: drain bus_reset work on device removal | MEDIUM | 5.5 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-64598 | smb/client: Fix error code in smb2_aead_req_alloc() | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-64599 | crypto: amlogic - avoid double cleanup in meson_crypto_probe() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68090 | debugobjects: Plug race against a concurrent OOM disable | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68091 | HID: wacom: stop hardware after post-start probe failures | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-68096 | audit: fix recursive locking deadlock in audit_dupe_exe() | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-68102 | drm/amdgpu: fix aperture mapping leak | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68106 | drm/amdgpu: fix division by zero with invalid uvd dimensions | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68109 | drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-68110 | drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68111 | drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68112 | drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68113 | drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68114 | drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-68115 | drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68137 | net/x25: fix use-after-free in x25_kill_by_neigh() | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-68141 | net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-68145 | iomap: fix out-of-bounds bitmap_set() with zero-length range | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68147 | fscrypt: Avoid dynamic allocation in fscrypt_get_devices() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68149 | fs: preserve ACL_DONT_CACHE state in forget_cached_acl() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68154 | libceph: reject zero bucket types in crush_decode | MEDIUM | 5.5 | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-68157 | libceph: guard missing CRUSH type name lookup | MEDIUM | 5.5 | 51%ile | Microsoft | 2026-08-11 |
| CVE-2026-68161 | sctp: close UDP tunnel sockets during netns teardown | MEDIUM | 5.5 | 49%ile | Microsoft | 2026-08-11 |
| CVE-2026-68164 | mm/damon/core: disallow overlapping input ranges for damon_set_regions() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68175 | tracing: Fix resource leak on mmiotrace trace_pipe close | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68183 | firmware: stratix10-svc: fix memory leaks and list corruption bugs | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68184 | cdrom: fix stack out-of-bounds read in CDROMVOLCTRL | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68194 | wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68195 | wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68197 | wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68202 | ALSA: seq: close a re-opened queue timer in the destructor | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68203 | media: vivid: fix cleanup bugs in vivid_init() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68205 | media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68206 | media: v4l2-ctrls: validate HEVC active reference counts | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68215 | media: radio-si476x: Unregister v4l2_device on probe failure | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68216 | media: pwc: Return queued buffers on start_streaming() failure | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68217 | media: pwc: Drain fill_buf on start_streaming() failure | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68219 | media: nxp: imx8-isi: Fix potential out-of-bounds issues | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68222 | media: msi2500: Return queued buffers on start_streaming() failure | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68223 | media: meson: vdec: Fix memory leak in error path of vdec_open | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68231 | media: airspy: Return queued buffers on start_streaming() failure | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68242 | drm/i915/gt: Fix NULL deref on sched_engine alloc failure | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-68243 | drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68246 | drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68247 | drm/i915/bios: range check LFP Data Block panel_type2 | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68249 | drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68250 | drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68251 | drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68252 | drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68253 | drm/i915/hdcp: check streams[] bounds before overflow | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68254 | drm/i915/vrr: require valid min/max vfreq for VRR | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68255 | drm/virtio: bound EDID block reads to the response buffer | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-68257 | drm/amdkfd: fix 32-bit overflow in CWSR total size calculation | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68258 | drm/amdkfd: Check bounds on CRIU restore queue type and mqd size | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68259 | drm/amdkfd: Check bounds in allocate_event_notification_slot | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68271 | drm/nouveau: fix reversed error cleanup order in ucopy functions | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68272 | drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68289 | tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68293 | net/mlx5: Fix MCIA register buffer overflow on 32 dword reads | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68297 | tipc: fix u16 MTU truncation in media and bearer MTU validation | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68300 | sctp: auth: verify auth requirement when auth_chunk is NULL | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-68303 | drm/vc4: hvs/v3d: Fix null dereference in unbind | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-68308 | wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68313 | tipc: fix infinite loop in __tipc_nl_compat_dumpit | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68322 | rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68327 | wan: wanxl: Only reset hardware after BAR mapping | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68328 | nfp: Check resource mutex allocation | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68331 | dpaa2-eth: put MAC endpoint device on disconnect | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68333 | dpaa2-switch: put MAC endpoint device on disconnect | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68336 | bonding: fix devconf_all NULL dereference when IPv6 is disabled | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68338 | net/packet: avoid fanout hook re-registration after unregister | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68339 | Bluetooth: btusb: validate Realtek vendor event length | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68367 | usb: gadget: f_tcm: synchronize delayed set_alt with teardown | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68369 | usb: gadget: printer: fix infinite loop in printer_read() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68370 | usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68374 | usb: core: sysfs: add lock to bos_descriptors_read() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68386 | bpf, sockmap: Reject unhashed UDP sockets on sockmap update | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68389 | Bluetooth: hci_qca: Clear memdump state on invalid dump size | MEDIUM | 5.5 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-68392 | Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68396 | scsi: core: wake eh reliably when using scsi_schedule_eh | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68401 | firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68408 | wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68410 | wifi: libertas: fix memory leak in helper_firmware_cb() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68412 | wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68418 | RDMA/irdma: Prevent user-triggered null deref on QP create | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-68427 | gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68445 | drm/vc4: Prevent shader BO mappings from becoming writable | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68452 | s390/zcrypt: Validate length for CCA AES cipher key requests | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74445 | drm/vmwgfx: reject DX_BIND_QUERY without a DX context | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74453 | drm/vc4: Zero the tile state data array before each BIN job | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74485 | binfmt_misc: reject a flag character as the field delimiter | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74592 | ima: Instantiate file_truncate and path_truncate hooks | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-74600 | mm/page_table_check: skip special zero mappings | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74610 | tls: don't leave a full plaintext sk_msg ring unpushed | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74619 | ovl: don't warn when the mount is completed from another user namespace | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74631 | net: smc: fix splice entry lifetime imbalance in smc_rx_splice | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74653 | serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74654 | serial: 8250_dma: Clear stale RX state on shutdown | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74667 | net/packet: reset the MAC header on the packet-socket transmit path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74722 | btrfs: fix memory leak in btrfs_do_encoded_write() | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74732 | drm/amd/display: Check for tg ops in dce110_set_avmute | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74734 | firewire: ohci: fix NULL pointer dereference in ar_context_release | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74736 | net/sched: cls_bpf: reject dev-bound programs bound to a different device | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74747 | ipvs: revalidate ihl to prevent out-of-bounds access | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74753 | perf: Reject exited events as group leaders | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80527 | ceph: fix hanging __ceph_get_caps() with stale mds_wanted | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-80534 | xfs: fix ilock leak on error in xfs_dq_get_next_id | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80541 | drm/amdgpu: validate GEM_CREATE domain combinations | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80549 | s390/vfio_ccw: Move cp cleanup out of not operational | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80550 | s390/vfio_ccw: Fix out of bounds check on CCW array | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80554 | s390/vfio_ccw: Limit the number of channel program segments | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80559 | Input: sur40 - fix input device registration ordering | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80578 | fbdev: core: Fix pointer desynchronization in fb_io_read() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80584 | s390/qeth: validate user buffer length in SNMP and ARP query ioctls | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80590 | inet: frags: strip GSO state from fragments before reassembly | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-80611 | ACPI: processor_idle: Mark LPI enter functions as __cpuidle | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80629 | octeontx2-af: npc: Fix size of entry2cntr_map | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80631 | btrfs: lzo: reject compressed segment that overflows the compressed input | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-80643 | EDAC/igen6: Fix call trace due to missing release() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80676 | Drivers: hv: vmbus: use generic driver_override infrastructure | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80678 | i2c: imx: Fix slave registration race and error handling | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80679 | s390/dasd: Fix potential NULL pointer dereference | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80684 | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80689 | tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80691 | scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-80695 | hwmon: (sht3x) Fix unaligned accesses | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80697 | erofs: ensure valid f_path for page cache sharing | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-80704 | drm/amd/display: use proper context for logging | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80714 | ipvs: do not propagate one-packet flag to synced conns | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-80718 | mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-54123 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-55015 | Microsoft Remote Help Denial of Service Vulnerability | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-59128 | Windows Encrypting File System (EFS) Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-59135 | Microsoft Windows Search Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-59136 | Microsoft COM for Windows Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-59137 | Windows Event Logging Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-61347 | Windows Event Logging Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-61360 | Windows GDI Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-61928 | Windows Hello Tampering Vulnerability | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-61933 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-61936 | Windows Defender Firewall Service Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-62703 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-62709 | Windows GDI+ Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-62730 | Windows Wired AutoConfig Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-62738 | Windows Management Instrumentation Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-62740 | Windows Imaging Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-62743 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-62746 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-62775 | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-62786 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62793 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62796 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62798 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-62842 | Microsoft Office Graphics Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-62887 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-63517 | Microsoft Office Graphics Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-63521 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-63524 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-63528 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-63529 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-63530 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-63531 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64899 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-64917 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-65662 | Windows GDI Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-65784 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-66806 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-66809 | Microsoft Office Graphics Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-66810 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-68797 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-68799 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-68802 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-68808 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-68809 | Powerpoint Information Disclosure Vulnerability | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-68813 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-70310 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-70312 | Powerpoint Information Disclosure Vulnerability | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-70314 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-70315 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-70316 | Powerpoint Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-70317 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-70318 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-70319 | Microsoft Office Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-70320 | Powerpoint Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-70322 | Powerpoint Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-70323 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-70325 | Powerpoint Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-70348 | Windows Management Services Denial of Service Vulnerability | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-12570 | Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/keras | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68454 | KVM: s390: pci: Fix handling of AIF enable without AISB | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-70367 | Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loo | MEDIUM | 5.4 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74598 | ipv6: fix Route Information option length validation | MEDIUM | 5.4 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-62904 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | MEDIUM | 5.4 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-66323 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | MEDIUM | 5.4 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-70309 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | MEDIUM | 5.4 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-70331 | Microsoft Edge for iOS Spoofing Vulnerability | MEDIUM | 5.4 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-70339 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | MEDIUM | 5.4 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-74651 | staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() | MEDIUM | 5.4 | 20%ile | Microsoft | 2026-08-11 |
| CVE-2022-4996 | mruby bigint.c udiv floating point comparison with incorrect operator | MEDIUM | 5.3 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-14672 | PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle | MEDIUM | 5.3 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-19487 | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends | MEDIUM | 5.3 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-32327 | Apache Portable Runtime Utility: apr-util XML stack recursion crash | MEDIUM | 5.3 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-37236 | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override hea | MEDIUM | 5.3 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-53794 | rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error | MEDIUM | 5.3 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-53798 | rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping | MEDIUM | 5.3 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-55619 | eml_parser: Parser DoS via deeply nested parentheses in e-mail headers | MEDIUM | 5.3 | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-65959 | Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data | MEDIUM | 5.3 | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-68118 | tcp: challenge ACK for non-exact RST in SYN-RECEIVED | MEDIUM | 5.3 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-68156 | libceph: refresh auth->authorizer_buf{,_len} after authorizer update | MEDIUM | 5.3 | 51%ile | Microsoft | 2026-08-11 |
| CVE-2026-68315 | sctp: validate stream count in sctp_process_strreset_inreq() | MEDIUM | 5.3 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-68343 | smb: client: validate DFS referral PathConsumed | MEDIUM | 5.3 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-68432 | vxlan: require CAP_NET_ADMIN in the device netns for changelink | MEDIUM | 5.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-70459 | rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry | MEDIUM | 5.3 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-71218 | Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion | MEDIUM | 5.3 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-72854 | msgpack-c Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-Success Undersized Reservation | MEDIUM | 5.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74540 | Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp | MEDIUM | 5.3 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-74608 | smb: client: Fix use-after-free in cifs_try_adding_channels() | MEDIUM | 5.3 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-74626 | NTB: ntb_netdev: Preserve RX queue depth on allocation failure | MEDIUM | 5.3 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74646 | misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke | MEDIUM | 5.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74695 | netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() | MEDIUM | 5.3 | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-74720 | bpf: Preserve pointer state for commuted arithmetic | MEDIUM | 5.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74737 | net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG | MEDIUM | 5.3 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-77014 | Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses | MEDIUM | 5.3 | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-80586 | mptcp: options: reset DSS fields in case of unexpected size | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-80587 | mptcp: avoid combining some incoming suboptions | MEDIUM | 5.3 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-80717 | sctp: validate Adaptation Indication parameter length | MEDIUM | 5.3 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-62757 | Windows Schannel Security Feature Bypass Vulnerability | MEDIUM | 5.3 | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-65777 | Active Directory Security Feature Bypass Vulnerability | MEDIUM | 5.3 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-52492 | An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result | MEDIUM | 5.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-82417 | qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property | MEDIUM | 5.3 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-74609 | tipc: read le->link under the node lock in tipc_node_link_down() | MEDIUM | 5.2 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74662 | inet: frags: publish queues before arming timer | MEDIUM | 5.2 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-74672 | mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF | MEDIUM | 5.2 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74690 | s390/ism: Fix UAF of sba and ieq during ism_dev_exit() | MEDIUM | 5.2 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74700 | net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers | MEDIUM | 5.2 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-64581 | xfrm: fix sk_dst_cache double-free in xfrm_user_policy() | MEDIUM | 5.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-71227 | Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout retu | MEDIUM | 5.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74612 | veth: fix skb length accounting after XDP frag adjustment | MEDIUM | 5.1 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-74723 | btrfs: lzo: reject inline extents without valid headers | MEDIUM | 5.1 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-68151 | binfmt_elf_fdpic: only honour the first PT_INTERP | MEDIUM | 5.0 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-61368 | Windows Hyper-V Information Disclosure Vulnerability | MEDIUM | 5.0 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-74501 | ALSA: usb-audio: fix use-after-free in ump_to_endpoint() | MEDIUM | 4.9 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-76957 | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur | MEDIUM | 4.9 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-68409 | wifi: mac80211: defer link RX stats percpu free to RCU | MEDIUM | 4.8 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-73282 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat | MEDIUM | 4.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-53797 | rsync < 3.5.0 Symlink Race Condition Information Disclosure | MEDIUM | 4.7 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-53800 | rsync < 3.5.0 Symlink Race Condition via --remove-source-files | MEDIUM | 4.7 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-64572 | ipv4: fib: free fib_alias with kfree_rcu() on insert error path | MEDIUM | 4.7 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68148 | fscrypt: Add missing superblock check in find_or_insert_direct_key() | MEDIUM | 4.7 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-68169 | mptcp: pm: userspace: fix use-after-free in get_local_id | MEDIUM | 4.7 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68189 | Bluetooth: hci_sync: Protect UUID list traversal | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68233 | drm/vc4: Shut down BO cache timer before teardown | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68245 | drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68362 | wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin | MEDIUM | 4.7 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68398 | ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF | MEDIUM | 4.7 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68404 | wifi: cfg80211: use wiphy work for socket owner autodisconnect | MEDIUM | 4.7 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-68405 | wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock | MEDIUM | 4.7 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68426 | xfrm: fix stale skb->prev after async crypto steals a GSO segment | MEDIUM | 4.7 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-68447 | drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size | MEDIUM | 4.7 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-68448 | ovl: check access to copy_file_range source with src mounter creds | MEDIUM | 4.7 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-71497 | jsoup: Cleaner may expose markup with custom raw-text elements | MEDIUM | 4.7 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-72203 | ntfs: skip extent mft records in writeback to prevent deadlock | MEDIUM | 4.7 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-72472 | nfs: use nfsi->rwsem to protect traversal of the file lock list | MEDIUM | 4.7 | 49%ile | Microsoft | 2026-08-11 |
| CVE-2026-74493 | net/smc: fix socket use-after-free during link group termination | MEDIUM | 4.7 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74546 | hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read | MEDIUM | 4.7 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74552 | hwmon: (lm90) Only report alarms if driver is ready | MEDIUM | 4.7 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74565 | netfilter: nf_tables: make nft_object rhltable per table | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74572 | btrfs: zoned: fix deadlock between metadata writeback and transaction commit | MEDIUM | 4.7 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-74594 | sched/psi: Shut down rtpoll_timer in psi_cgroup_free() | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74613 | vsock/virtio: avoid refilling the RX queue after teardown | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74614 | vsock/virtio: read virtqueues under worker locks | MEDIUM | 4.7 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74628 | net/x25: fix use-after-free of the socket by its timers | MEDIUM | 4.7 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74632 | mm/huge_memory: fix huge_zero_pfn race | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74638 | drm/v3d: Serialize the scheduler timeout handlers | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74675 | vt: stabilize tty reference in kbd_keycode with tty_port_tty_get | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74683 | Input: evdev - sanitize event type index when fetching event masks | MEDIUM | 4.7 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-74714 | bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74726 | bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74744 | ipvlan: inherit needed_headroom and needed_tailroom from phy_dev | MEDIUM | 4.7 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-80521 | af_unix: Unlink scc_entry in unix_del_edge(). | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80528 | ceph: avoid fs reclaim while using current->journal_info | MEDIUM | 4.7 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-80556 | mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80570 | Input: synaptics-rmi4 - zero report size on F54 work error | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80572 | Input: byd - synchronize timer deletion before freeing private data | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80589 | block: stop the timeout timer when releasing a never added disk | MEDIUM | 4.7 | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-80692 | Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks | MEDIUM | 4.7 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-81893 | Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68241 | drm/i915/mst: limit DP MST ESI service loop | MEDIUM | 4.6 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68278 | drm/dp/mst: fix buffer overflows in sideband chunk accumulation | MEDIUM | 4.6 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-80569 | Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer | MEDIUM | 4.6 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-61350 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 4.6 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-62829 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-62917 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-64897 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-64902 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-64916 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-64922 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-74585 | thunderbolt: Bound the DROM dual link port number before indexing sw->ports | MEDIUM | 4.6 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-13002 | Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing | MEDIUM | 4.4 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-18477 | Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape | MEDIUM | 4.4 | 0%ile | Microsoft | 2026-08-11 |
| CVE-2026-18508 | Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite | MEDIUM | 4.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-64567 | btrfs: reject free space cache with more entries than pages | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68103 | drm/amdgpu: reject mapping a reserved doorbell to a new queue | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68388 | smb/client: handle overlapping allocated ranges in fallocate | MEDIUM | 4.4 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-68419 | RDMA/irdma: Prevent rereg_mr for non-mem regions | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68441 | net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains | MEDIUM | 4.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74258 | bpf: Guard __get_user acesss with access_ok for uprobe_multi data | MEDIUM | 4.4 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74269 | bnxt: fix head underflow on XDP head-grow | MEDIUM | 4.4 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-74481 | mm/page_reporting: use system_freezable_wq to fix UAF during suspend | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74547 | hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74566 | keys: make keyring key-chunk byte order agree with keyring_diff_objects() | MEDIUM | 4.4 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74581 | net: ipv6: clear suppressed fib6 rule result | MEDIUM | 4.4 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-74615 | vxlan: do not arm the ageing timer on a device that is down | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74620 | net/sched: act_gact, act_police: range check the fallback control action | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74622 | net: atlantic: free RX pages of consumed but not refilled buffers | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74623 | net: atlantic: free stranded TX buffers on ring deinit | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74657 | ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74663 | net/sched: reject overly deep qdisc hierarchies | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74664 | net: openvswitch: reallocate update replies for mismatched IDs | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74684 | net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() | MEDIUM | 4.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74689 | net/atm: fix slab-out-of-bounds read in vcc_setsockopt() | MEDIUM | 4.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74693 | net: prestera: validate firmware header length | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74694 | net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74701 | net/openvswitch: check Ethernet header length in key_extract() | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74713 | vhost_iotlb: bound map allocation in add_range | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74718 | devlink: fix net namespace reference leak in reload | MEDIUM | 4.4 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80526 | ASoC: tas2562: Validate values for volume writes | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80567 | Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue | MEDIUM | 4.4 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80703 | drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE | MEDIUM | 4.4 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-58616 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability | MEDIUM | 4.4 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-14678 | PostgreSQL pg_trgm picksplit reads past end of buffer | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-18024 | PostgreSQL ascii() function reads past end of buffer | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-53584 | libgit2: Submodule path traversal | MEDIUM | 4.3 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-6470 | PostgreSQL fails to check type USAGE privilege | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68099 | ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL | MEDIUM | 4.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68100 | ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl | MEDIUM | 4.3 | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-68190 | staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() | MEDIUM | 4.3 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68235 | drm/amd/display: dce100: skip non-DP stream encoders for DP MST | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68425 | IB/mad: Drop unmatched RMPP responses before reassembly | MEDIUM | 4.3 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-74460 | can: ems_usb: validate CPC message lengths | MEDIUM | 4.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74497 | ALSA: usb-audio: Clamp frame size in implicit-feedback mode | MEDIUM | 4.3 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74508 | Bluetooth: HIDP: reject frames without a transaction header | MEDIUM | 4.3 | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-74557 | scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer | MEDIUM | 4.3 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-74650 | staging: rtl8723bs: fix OOB read in WMM_param_handler() | MEDIUM | 4.3 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80574 | Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet | MEDIUM | 4.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-62882 | Microsoft Outlook Spoofing Vulnerability | MEDIUM | 4.3 | 48%ile | Microsoft | 2026-08-11 |
| CVE-2026-66798 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | MEDIUM | 4.3 | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-14666 | PostgreSQL row security caching disregards role modifications | MEDIUM | 4.2 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74677 | net: usb: ipheth: fix carrier_work UAF on disconnect | MEDIUM | 4.2 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-64574 | wifi: mac80211: tear down new links on vif update error path | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-64576 | nexthop: initialize extack in nh_res_bucket_migrate() | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-64579 | xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert | MEDIUM | 4.1 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-64580 | xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68105 | drm/amdgpu: Fix kernel panic during driver load failure | MEDIUM | 4.1 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-68126 | mac802154: hold an interface reference across the scan worker | MEDIUM | 4.1 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68192 | wifi: brcmfmac: make release_scratchbuffers idempotent | MEDIUM | 4.1 | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-68317 | pds_core: fix auxiliary device add/del races | MEDIUM | 4.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68428 | KVM: x86/mmu: Fix use-after-free on vendor module reload | MEDIUM | 4.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68430 | drm/amdgpu/gfx8: drop unecessary BUG_ON() | MEDIUM | 4.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68436 | drm/amd/display: use kvzalloc to allocate struct dc | MEDIUM | 4.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-68444 | firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() | MEDIUM | 4.1 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-72392 | ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump | MEDIUM | 4.1 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-72405 | net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-72420 | md/raid5: avoid R5_Overlap races while breaking stripe batches | MEDIUM | 4.1 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-72434 | netfilter: ipset: make sure gc is properly stopped | MEDIUM | 4.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-72440 | md/raid1: fix writes_pending and barrier reference leaks on write failures | MEDIUM | 4.1 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-72493 | net: serialize netif_running() check in enqueue_to_backlog() | MEDIUM | 4.1 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-72496 | RDMA/bnxt_re: Proper rollback if the ioremap fails | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74264 | net: watchdog: fix refcount tracking races | MEDIUM | 4.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74374 | md/raid1,raid10: fix error-path detection with md_cloned_bio() | MEDIUM | 4.1 | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-74405 | OPP: Fix race between OPP addition and lookup | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74461 | i2c: imx: Cancel hrtimer before clearing slave pointer | MEDIUM | 4.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74470 | scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74471 | tracing: Check return value of __register_event() in trace_module_add_events() | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74476 | veth: convert frag_list skbs before running XDP | MEDIUM | 4.1 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-74492 | netfilter: ipset: do not update comments from kernel-side hash adds | MEDIUM | 4.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74507 | Bluetooth: HIDP: validate numbered report payloads | MEDIUM | 4.1 | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-74523 | qede: sync udp_tunnel ports outside qede_lock in the recovery path | MEDIUM | 4.1 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74583 | net/sched: cls_route: fix fastmap use-after-free on filter | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74589 | bpf, sockmap: Fix sk_redir use-after-free in send verdict | MEDIUM | 4.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74601 | ring-buffer: Use current_context for safe per-CPU buffer swap | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74604 | Revert "thermal/drivers/hwmon: Cleanup coding style a bit" | MEDIUM | 4.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-74605 | eventfs: Use children field for rcu head and add memory barriers | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74606 | eventfs: Fix use-after-free in eventfs_remove_rec() | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74636 | tracing: Fix race between update_event_fields and, event_define_fields | MEDIUM | 4.1 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74637 | perf/core: Fix group leader use-after-free after sibling detach | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74656 | ipv4: fix use-after-free in fib_nhc_update_mtu() | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74661 | mac802154: fix netdev use-after-free in beacon worker | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74666 | packet: synchronize pressure clearing with ring reconfiguration | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74687 | watchdog: at91sam9_wdt: prevent timer rearm during teardown | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74717 | net/mlx5: fw_tracer, return NULL on create error | MEDIUM | 4.1 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-74725 | enic: fix tx_hang_reset use-after-free on device removal | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74740 | net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain | MEDIUM | 4.1 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74748 | netfilter: ipset: fix refcount race between list:set GC and swap | MEDIUM | 4.1 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80553 | s390/vfio_ccw: Cancel existing workqueues | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-19411 | Shim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns null | LOW | 3.9 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-14673 | PostgreSQL amcheck does not clear untrusted search path | LOW | 3.8 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-6469 | PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership | LOW | 3.8 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-74456 | can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error | LOW | 3.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-60589 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE | LOW | 3.7 | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-68376 | sctp: fix auth_hmacs array size in struct sctp_cookie | LOW | 3.7 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-68433 | libceph: bound get_version reply decode to front len | LOW | 3.7 | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-74268 | tcp: clear sock_ops cb flags before force-closing a child socket | LOW | 3.7 | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-74475 | vxlan: use neigh_ha_snapshot() in route_shortcircuit() | LOW | 3.7 | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-74719 | net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() | LOW | 3.7 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80585 | mptcp: fastopen: only mark MPTFO subflows with SYN data | LOW | 3.7 | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-68117 | tipc: clear sock->sk on the failed-insert path in tipc_sk_create() | LOW | 3.6 | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-80628 | ALSA: seq: oss: Serialize readq reset state with q->lock | LOW | 3.6 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-73281 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi | LOW | 3.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74711 | hwmon: (pmbus) Fix type confusion in notification logic | LOW | 3.5 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-80566 | Input: hynitron_cstxxx - validate touch count and finger IDs | LOW | 3.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-74579 | netfilter: nft_payload: fix mask build for partial field offload | LOW | 3.4 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74671 | ima: fix out-of-bounds read in xattr_verify() | LOW | 3.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-64652 | GitHub CLI: Partial token disclosure in `gh auth status` output | LOW | 3.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68209 | media: sun4i-csi: Return queued buffers on start_streaming() failure | LOW | 3.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68220 | media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe | LOW | 3.3 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68229 | media: cedrus: skip invalid H.264 reference list entries | LOW | 3.3 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68234 | drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved | LOW | 3.3 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68238 | drm/amdgpu: Release VFCT ACPI table reference | LOW | 3.3 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68244 | drm/i915/gem: Do not leak siblings[] on proto context error | LOW | 3.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68256 | drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference | LOW | 3.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68277 | drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers | LOW | 3.3 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68280 | drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() | LOW | 3.3 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68288 | net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD | LOW | 3.3 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68301 | net: hsr: fix memory leak on slave unregistration by removing synced VLANs | LOW | 3.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68302 | amt: re-read skb header pointers after every pull | LOW | 3.3 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-68304 | wifi: brcmfmac: fix 802.1X-SHA256 call trace warning | LOW | 3.3 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68312 | cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths | LOW | 3.3 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-68422 | btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() | LOW | 3.3 | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-68446 | drm/vmwgfx: Validate vmw_surface_metadata::array_size | LOW | 3.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-72495 | RDMA/bnxt_re: Avoid repeated requests to allocate WC pages | LOW | 3.3 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-73071 | Vim: Use-after-free in JSON Decoding | LOW | 3.3 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-74544 | net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds | LOW | 3.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74577 | net: mpls: initialize rtm_tos in mpls_getroute() | LOW | 3.3 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74603 | ptp: ocp: Fix board ID over-read | LOW | 3.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74655 | serial: qcom-geni: fix TX DMA buffer flush | LOW | 3.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74673 | Input: evdev - fix information leak in evdev_pass_values() | LOW | 3.3 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74676 | vt: add permission check for KDSKBMETA ioctl | LOW | 3.3 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80539 | drm/amdgpu: disallow multiple FENCE chunks in one submit | LOW | 3.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-80540 | drm/amdgpu: Fix UVD decode image min size calculation | LOW | 3.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80580 | fbdev: bound mode sysfs output to the sysfs buffer | LOW | 3.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80581 | ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout | LOW | 3.3 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-80583 | ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses | LOW | 3.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-80598 | ntfs3: fix out-of-bounds read in decompress_lznt | LOW | 3.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80670 | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() | LOW | 3.3 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-80707 | can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer | LOW | 3.3 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-82327 | Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist da | LOW | 3.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-64571 | wifi: p54: validate RX frame length in p54_rx_eeprom_readback() | LOW | 3.2 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-74733 | gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock | LOW | 3.0 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-18739 | Popt-devel: popt-static: off-by-one in poptstuffargs | LOW | 2.5 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-68107 | drm/amdgpu/vcn4: avoid rereading IB param length | LOW | 2.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-68226 | media: cx23885: add ioremap return check and cleanup | LOW | 2.5 | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-68248 | drm/i915: Return NULL on error in active_instance | LOW | 2.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68269 | drm/i915/gem: Add missing nospec on parallel submit slot | LOW | 2.5 | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-68309 | wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() | LOW | 2.5 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-68355 | wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() | LOW | 2.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68403 | wifi: brcmfmac: initialize SDIO data work before cleanup | LOW | 2.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68417 | RDMA/siw: publish QP after initialization | LOW | 2.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-73283 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar | LOW | 2.5 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-74448 | drm/amdkfd: fix QID bit leak in pqm_create_queue() | LOW | 2.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74495 | igbvf: Fix leak in TX DMA error cleanup | LOW | 2.5 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-74567 | keys: fix out-of-bounds read in keyring_get_key_chunk() | LOW | 2.5 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74658 | futex: Prevent robust futex exit race some more | LOW | 2.5 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74678 | net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() | LOW | 2.5 | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-74754 | scsi: core: pair EH runtime PM get and put | LOW | 2.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-80547 | s390/vfio_ccw: Implement a crw lock | LOW | 2.5 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-80623 | coresight: ete: Always save state on power down | LOW | 2.5 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-80634 | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag | LOW | 2.5 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-68279 | drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers | LOW | 2.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74680 | usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() | LOW | 2.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74679 | usb: gadget: f_ncm: Use unsigned int for ndp_index | LOW | 2.4 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-61477 | Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection | LOW | 2.3 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-74338 | bpf: Reject sleepable BPF_LSM_CGROUP programs at load time | LOW | 2.3 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-74564 | netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH | LOW | 2.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74659 | net: bridge: mrp: fix uninitialised bytes on the wire | LOW | 2.3 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-18839 | Popt-devel: popt-static: size_t underflow in singleoptionhelp | LOW | 2.2 | 0%ile | Microsoft | 2026-08-11 |
| CVE-2026-82631 | valkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free | LOW | 2.2 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-74532 | Bluetooth: btintel: Validate length before parsing diagnostics TLV | LOW | 2.1 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-68363 | wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request | LOW | 2.0 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-68171 | arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates | LOW | 1.9 | — | Microsoft | 2026-08-11 |
| CVE-2026-68413 | wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() | LOW | 1.9 | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-68450 | btrfs: free mapping node on duplicate reloc root insert | LOW | 1.9 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-72315 | smb: client: fix busy dentry warning on unmount after DIO | LOW | 1.9 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-72438 | md/raid10: fix writes_pending and barrier reference leaks on discard failures | LOW | 1.9 | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-74317 | ixgbe: do not configure xps for XDP queues | LOW | 1.9 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-74464 | net: openvswitch: fix skb leak on flow key update failure during ct | LOW | 1.9 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-74525 | net: sxgbe: free TX rings on RX allocation failure | LOW | 1.9 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-80565 | crypto: qce - fix error path in devm_qce_register_algs | LOW | 1.9 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-68429 | drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() | LOW | 1.8 | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-15310 | zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits | UNKNOWN | — | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-15806 | `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching | UNKNOWN | — | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-17084 | stringprep.map_table_b2() deviates from RFC 3454 Table B.2 | UNKNOWN | — | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-17106 | Tar extraction in moby/go-archive can write outside the destination directory via link following | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-18503 | Super-linear CPU usage for unbounded input to csv.Sniffer.sniff() | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19023 | HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19024 | HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message | UNKNOWN | — | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-19025 | HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19026 | Nbit filter NULL/short parameter-array dereference | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19027 | HDF5 out-of-bounds heap read in N-Bit filter decompression | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19028 | HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-19672 | tarfile extraction filter bypass allows creation of directories outside the destination | UNKNOWN | — | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-43971 | Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1 | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-47243 | Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs | UNKNOWN | — | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-55893 | Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode | UNKNOWN | — | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-55894 | Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode | UNKNOWN | — | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-61711 | BuildKit: Custom frontend could bypass Seccomp/AppArmor | UNKNOWN | — | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-61712 | BuildKit: Possible runtime DoS via unbounded group parsing | UNKNOWN | — | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-63379 | Libevent: HTTP Header smuggling | UNKNOWN | — | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-63381 | Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-63383 | Libevent: decode_tag_internal() can lead to out-of-bounds read | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-63384 | Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value. | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-63385 | Libevent: HTTP header handling bugs create risk of access control bypass. | UNKNOWN | — | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-6368 | wordexp with WRDE_APPEND can return or use invalid memory | UNKNOWN | — | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-64653 | GitHub CLI: Unescaped variable components in request URLs could allow path traversal | UNKNOWN | — | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-64654 | GitHub CLI: Terminal escape sequence injection in multiple `gh` commands | UNKNOWN | — | 53%ile | Microsoft | 2026-08-11 |
| CVE-2026-64655 | GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching | UNKNOWN | — | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-66484 | Path Traversal in GNU cpio | UNKNOWN | — | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-66485 | Uncontrolled Memory Allocation in GNU cpio | UNKNOWN | — | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-66486 | Improper Output Encoding in GNU cpio | UNKNOWN | — | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-6791 | Potential stack-based buffer clash during tilde expansion in wordexp | UNKNOWN | — | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-69249 | python-cryptography: Duplicate self-signed intermediates can cause exponential path-building | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-72924 | GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default | UNKNOWN | — | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-73070 | Vim: Stack Buffer Overflow in the Vim Socket Server | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-73072 | Vim: Heap Buffer Overflow when Loading a Spell File | UNKNOWN | — | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-73073 | Vim: Arbitrary Ex Command Execution in C Omni-Completion | UNKNOWN | — | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-73074 | Vim: Heap Buffer Overflow in Text Property Handling | UNKNOWN | — | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-73075 | Vim: Out-of-bounds Access in Popup Opacity Handling | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-73076 | Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim` | UNKNOWN | — | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-73077 | Vim: Arbitrary Code Execution via Shell Keyword Lookup | UNKNOWN | — | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-73078 | Vim: Arbitrary Code Execution via Netrw Menu Construction | UNKNOWN | — | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-73499 | etcd: Watch API authorization bypass via open-ended range requests | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-73500 | etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline | UNKNOWN | — | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-75593 | BuildKit: Malicious client can bypass destination directory validation on local sources upload | UNKNOWN | — | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-19137 | CVE-2026-19137 Use after free in WebGL | UNKNOWN | — | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-19138 | CVE-2026-19138 Heap buffer overflow in CrashReporting | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-19139 | CVE-2026-19139 Race in CredentialProvider | UNKNOWN | — | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-19140 | CVE-2026-19140 Use after free in GPU | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-19142 | CVE-2026-19142 Use after free in Views | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-19144 | CVE-2026-19144 Use after free in HTML | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-19145 | CVE-2026-19145 Use after free in Translate | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-19146 | CVE-2026-19146 Uninitialized Use in GPU | UNKNOWN | — | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-19147 | CVE-2026-19147 Use after free in Aura | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-19148 | CVE-2026-19148 Out of bounds write in GPU | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-19149 | CVE-2026-19149 Use after free in Aura | UNKNOWN | — | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-19150 | CVE-2026-19150 Inappropriate implementation in V8 | UNKNOWN | — | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-19151 | CVE-2026-19151 Use after free in V8 | UNKNOWN | — | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-19152 | CVE-2026-19152 Inappropriate implementation in Navigation | UNKNOWN | — | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-19153 | CVE-2026-19153 Insufficient validation of untrusted input in Workers | UNKNOWN | — | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-19155 | CVE-2026-19155 Use after free in Payments | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-19156 | CVE-2026-19156 Heap buffer overflow in Base | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-19157 | CVE-2026-19157 Out of bounds write in ANGLE | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-19158 | CVE-2026-19158 Use after free in Views | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-19159 | CVE-2026-19159 Use after free in Views | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-19160 | CVE-2026-19160 Uninitialized Use in Skia | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-19161 | CVE-2026-19161 Uninitialized Use in Skia | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-19162 | CVE-2026-19162 Out of bounds write in V8 | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-19163 | CVE-2026-19163 Use after free in Media | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-19164 | CVE-2026-19164 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-19165 | CVE-2026-19165 Use after free in Extensions | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-19166 | CVE-2026-19166 Use after free in Web Authentication | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-19167 | CVE-2026-19167 Integer overflow in GPU | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-19168 | CVE-2026-19168 Inappropriate implementation in V8 | UNKNOWN | — | 44%ile | Microsoft | 2026-08-11 |
| CVE-2026-19169 | CVE-2026-19169 Insufficient validation of untrusted input in Contextual Tasks | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-19170 | CVE-2026-19170 Use after free in WebGL | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-19171 | CVE-2026-19171 Use after free in Media | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-19172 | CVE-2026-19172 Use after free in Views | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-19173 | CVE-2026-19173 Out of bounds write in Skia | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-19174 | CVE-2026-19174 Integer overflow in V8 | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-19175 | CVE-2026-19175 Use after free in Payments | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-19176 | CVE-2026-19176 Use after free in Skia | UNKNOWN | — | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-19177 | CVE-2026-19177 Insufficient validation of untrusted input in UI | UNKNOWN | — | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-19556 | Chromium: CVE-2026-19556 Use after free in V8 | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-19557 | Chromium: CVE-2026-19557 Use after free in TabStrip | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-19558 | Chromium: CVE-2026-19558 Use after free in Extensions | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-19559 | Chromium: CVE-2026-19559 Use after free in HTML | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-19560 | Chromium: CVE-2026-19560 Use after free in Blink | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-76033 | Chromium: CVE-2026-76033 Inappropriate implementation in CORS | UNKNOWN | — | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-76034 | Chromium: CVE-2026-76034 Buffer overflow in WebGL | UNKNOWN | — | 52%ile | Microsoft | 2026-08-11 |
| CVE-2026-76035 | Chromium: CVE-2026-76035 Inappropriate implementation in Media | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-76037 | Chromium: CVE-2026-76037 Link following in CredentialProvider | UNKNOWN | — | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-76038 | Chromium: CVE-2026-76038 Type confusion in V8 | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-76040 | Chromium: CVE-2026-76040 Use after free in Browser | UNKNOWN | — | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-76041 | Chromium: CVE-2026-76041 Information leak in Skia | UNKNOWN | — | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-76042 | Chromium: CVE-2026-76042 Use of uninitialized resource in GPU | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-76043 | Chromium: CVE-2026-76043 Incorrect calculation in V8 | UNKNOWN | — | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-76044 | Chromium: CVE-2026-76044 Race condition in USB | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-76045 | Chromium: CVE-2026-76045 Use after free in WebGL | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-76047 | Chromium: CVE-2026-76047 Type confusion in V8 | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-78891 | Chromium: CVE-2026-78891 Buffer overflow in WebRTC | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-78892 | Chromium: CVE-2026-78892 Incorrect authorization in Chromoting | UNKNOWN | — | 0%ile | Microsoft | 2026-08-11 |
| CVE-2026-78893 | Chromium: CVE-2026-78893 Information leak in QUIC | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-78894 | Chromium: CVE-2026-78894 Race condition in Payments | UNKNOWN | — | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-78895 | Chromium: CVE-2026-78895 Information leak in Paint | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-78896 | Chromium: CVE-2026-78896 Information leak in StorageAccessAPI | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-78897 | Chromium: CVE-2026-78897 Missing authorization in BrowserTag | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-78898 | Chromium: CVE-2026-78898 Incorrect authorization in Downloads | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-78899 | Chromium: CVE-2026-78899 Use after free in V8 | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-78900 | Chromium: CVE-2026-78900 Improper input validation in Media | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-78901 | Chromium: CVE-2026-78901 Race condition in V8 | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-78903 | Chromium: CVE-2026-78903 Incomplete cleanup in SiteIsolation | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-78904 | Chromium: CVE-2026-78904 Type confusion in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-78905 | Chromium: CVE-2026-78905 Type confusion in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-78906 | Chromium: CVE-2026-78906 Race condition in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-78907 | Chromium: CVE-2026-78907 Incorrect authorization in WebProtect | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-78908 | Chromium: CVE-2026-78908 Information leak in Canvas | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-78909 | Chromium: CVE-2026-78909 Use after free in Views | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-78910 | Chromium: CVE-2026-78910 Buffer overflow in V8 | UNKNOWN | — | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-78911 | Chromium: CVE-2026-78911 Incorrect authorization in USB | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-78912 | Chromium: CVE-2026-78912 UI misrepresentation in Browser | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-78913 | Chromium: CVE-2026-78913 Use after free in Chromoting | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-78914 | Chromium: CVE-2026-78914 Uninitialized resource in Skia | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-78915 | Chromium: CVE-2026-78915 Race condition in Enterprise | UNKNOWN | — | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-78934 | Chromium: CVE-2026-78934 Race condition in ReadAloud | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-78938 | Chromium: CVE-2026-78938 Type confusion in V8 | UNKNOWN | — | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-78939 | Chromium: CVE-2026-78939 Use after free in Chromecast | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-78940 | Chromium: CVE-2026-78940 Improper initialization in Network | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-78941 | Chromium: CVE-2026-78941 Information leak in Core | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-78942 | Chromium: CVE-2026-78942 Incorrect reference resolution in Loader | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-78943 | Chromium: CVE-2026-78943 Improper input validation in Editing | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-78944 | Chromium: CVE-2026-78944 Use after free in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-78945 | Chromium: CVE-2026-78945 Use after free in Views | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-78946 | Chromium: CVE-2026-78946 Incorrect authorization in Select | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-78947 | Chromium: CVE-2026-78947 Incomplete cleanup in Chromium | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-78948 | Chromium: CVE-2026-78948 Buffer overflow in WebGL | UNKNOWN | — | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-78950 | Chromium: CVE-2026-78950 Integer overflow in WebRTC | UNKNOWN | — | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-78951 | Chromium: CVE-2026-78951 Use after free in ServiceWorker | UNKNOWN | — | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-78952 | Chromium: CVE-2026-78952 Out of bounds write in Crashpad | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-78953 | Chromium: CVE-2026-78953 Missing authorization in SiteIsolation | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-78954 | Chromium: CVE-2026-78954 Incorrect authorization in Extensions | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-78955 | Chromium: CVE-2026-78955 Observable discrepancy in PerformanceAPIs | UNKNOWN | — | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-78956 | Chromium: CVE-2026-78956 Type confusion in V8 | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-78958 | Chromium: CVE-2026-78958 Uninitialized resource in Skia | UNKNOWN | — | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-78959 | Chromium: CVE-2026-78959 Improper handling of case sensitivity in FileSystem | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-78960 | Chromium: CVE-2026-78960 Information leak in Extensions | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-78961 | Chromium: CVE-2026-78961 Incorrect authorization in Core | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-78962 | Chromium: CVE-2026-78962 Uninitialized resource in WebXR | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-78963 | Chromium: CVE-2026-78963 Improper input validation in Media | UNKNOWN | — | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-78964 | Chromium: CVE-2026-78964 Use after free in Sync | UNKNOWN | — | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-78965 | Chromium: CVE-2026-78965 Uninitialized resource in ANGLE | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-78966 | Chromium: CVE-2026-78966 Externally controlled reference in QUIC | UNKNOWN | — | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-78967 | Chromium: CVE-2026-78967 Missing authorization in BFCache | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-78968 | Chromium: CVE-2026-78968 Missing authorization in Core | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-78969 | Chromium: CVE-2026-78969 Uninitialized resource in Video | UNKNOWN | — | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-78974 | Chromium: CVE-2026-78974 UI misrepresentation in Linux Toolkit Theming | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-78975 | Chromium: CVE-2026-78975 Incorrect authorization in DOM | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-78976 | Chromium: CVE-2026-78976 Improper input validation in StorageAccessAPI | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-78977 | Chromium: CVE-2026-78977 Uninitialized resource in GPU | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-78978 | Chromium: CVE-2026-78978 Out of bounds read in ANGLE | UNKNOWN | — | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-78979 | Chromium: CVE-2026-78979 Race condition in Core | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-78980 | Chromium: CVE-2026-78980 Improper input validation in ReaderMode | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-78983 | Chromium: CVE-2026-78983 Use after free in Views | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-78984 | Chromium: CVE-2026-78984 Uninitialized resource in GPU | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-78985 | Chromium: CVE-2026-78985 Incorrect reference resolution in FileSystem | UNKNOWN | — | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-78986 | Chromium: CVE-2026-78986 Uninitialized resource in GPU | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-78987 | Chromium: CVE-2026-78987 Information leak in Canvas | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-78989 | Chromium: CVE-2026-78989 Out of bounds read in ANGLE | UNKNOWN | — | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-78990 | Chromium: CVE-2026-78990 Use after free in Compositing | UNKNOWN | — | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-78991 | Chromium: CVE-2026-78991 Race condition in WebProtect | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-78999 | Chromium: CVE-2026-78999 Improper privilege management in Navigation | UNKNOWN | — | 39%ile | Microsoft | 2026-08-11 |
| CVE-2026-79000 | Chromium: CVE-2026-79000 Improper input validation in DeviceBoundSessionCredentials | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79001 | Chromium: CVE-2026-79001 Information leak in Bluetooth | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79002 | Chromium: CVE-2026-79002 Incorrect authorization in SiteIsolation | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-79003 | Chromium: CVE-2026-79003 Incorrect authorization in Device | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79004 | Chromium: CVE-2026-79004 Out of bounds read in Media | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79005 | Chromium: CVE-2026-79005 Incorrect authorization in StorageAccessAPI | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79006 | Chromium: CVE-2026-79006 Protection mechanism failure in HttpsUpgrades | UNKNOWN | — | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-79007 | Chromium: CVE-2026-79007 Uninitialized resource in GPU | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79009 | Chromium: CVE-2026-79009 UI misrepresentation in UI | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79010 | Chromium: CVE-2026-79010 Operation on a resource after expiration or release in Network | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-79011 | Chromium: CVE-2026-79011 UI misrepresentation in Browser | UNKNOWN | — | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-79012 | Chromium: CVE-2026-79012 Use after free in Safebrowsing | UNKNOWN | — | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-79013 | Chromium: CVE-2026-79013 Improper input validation in Sync | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79014 | Chromium: CVE-2026-79014 Race condition in Autofill | UNKNOWN | — | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-79015 | Chromium: CVE-2026-79015 Improper input validation in ServiceWorker | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79016 | Chromium: CVE-2026-79016 Observable discrepancy in SVG | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-79017 | Chromium: CVE-2026-79017 Race condition in Extensions | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79018 | Chromium: CVE-2026-79018 Information leak in FoldableAPIs | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79019 | Chromium: CVE-2026-79019 Out of bounds write in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79020 | Chromium: CVE-2026-79020 Out of bounds read in Skia | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-79021 | Chromium: CVE-2026-79021 Missing authorization in InterestGroups | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-79022 | Chromium: CVE-2026-79022 UI misrepresentation in Transactions Platform | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79023 | Chromium: CVE-2026-79023 Incorrect authorization in Editing | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-79024 | Chromium: CVE-2026-79024 Information leak in ServiceWorker | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-79025 | Chromium: CVE-2026-79025 Improper input validation in Workers | UNKNOWN | — | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-79026 | Chromium: CVE-2026-79026 Use after free in Extensions | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-79027 | Chromium: CVE-2026-79027 Use after free in WebRTC | UNKNOWN | — | 47%ile | Microsoft | 2026-08-11 |
| CVE-2026-79028 | Chromium: CVE-2026-79028 Observable discrepancy in Network | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-79030 | Chromium: CVE-2026-79030 Observable discrepancy in Autofill | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-79031 | Chromium: CVE-2026-79031 Improper resource exposure in Preload | UNKNOWN | — | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-79032 | Chromium: CVE-2026-79032 Improper input validation in Network | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79033 | Chromium: CVE-2026-79033 Insufficient control flow management in DevTools | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79034 | Chromium: CVE-2026-79034 Information leak in CORS | UNKNOWN | — | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-79038 | Chromium: CVE-2026-79038 Incorrect authorization in WebProtect | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-79040 | Chromium: CVE-2026-79040 Uninitialized resource in GPU | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79041 | Chromium: CVE-2026-79041 Missing authorization in Browser | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-79042 | Chromium: CVE-2026-79042 Missing authorization in Payments | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79043 | Chromium: CVE-2026-79043 Out of bounds write in ANGLE | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-79045 | Chromium: CVE-2026-79045 Type confusion in V8 | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-79047 | Chromium: CVE-2026-79047 Use after free in Views | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-79048 | Chromium: CVE-2026-79048 Out of bounds write in ANGLE | UNKNOWN | — | 45%ile | Microsoft | 2026-08-11 |
| CVE-2026-79049 | Chromium: CVE-2026-79049 Incorrect reference resolution in Passwords | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-79050 | Chromium: CVE-2026-79050 Incorrect authorization in Network | UNKNOWN | — | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-79051 | Chromium: CVE-2026-79051 Incorrect authorization in Loader | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79052 | Chromium: CVE-2026-79052 Use after free in Aura | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-79053 | Chromium: CVE-2026-79053 Missing authorization in Lighthouse | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79054 | Chromium: CVE-2026-79054 Use after free in Chromecast | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-79055 | Chromium: CVE-2026-79055 Information leak in Sharing | UNKNOWN | — | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-79056 | Chromium: CVE-2026-79056 Use after free in ServiceWorker | UNKNOWN | — | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-79058 | Chromium: CVE-2026-79058 Missing authorization in Passwords | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-79059 | Chromium: CVE-2026-79059 Information leak in BFCache | UNKNOWN | — | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-79060 | Chromium: CVE-2026-79060 Incorrect authorization in StorageAccessAPI | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79064 | Chromium: CVE-2026-79064 Use after free in Network | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-79065 | Chromium: CVE-2026-79065 Improper input validation in Network | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-79066 | Chromium: CVE-2026-79066 Improper input validation in Navigation | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79067 | Chromium: CVE-2026-79067 Missing authorization in Network | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-79068 | Chromium: CVE-2026-79068 Improper resource exposure in StreamsAPI | UNKNOWN | — | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-79069 | Chromium: CVE-2026-79069 Memory corruption in Tint | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79070 | Chromium: CVE-2026-79070 Incorrect reference resolution in Cache | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79071 | Chromium: CVE-2026-79071 Race condition in GPU | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79072 | Chromium: CVE-2026-79072 Improper state validation in Performance | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79073 | Chromium: CVE-2026-79073 Improper state validation in Parser | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79074 | Chromium: CVE-2026-79074 Information leak in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79075 | Chromium: CVE-2026-79075 Information leak in Geolocation | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79076 | Chromium: CVE-2026-79076 Improper input validation in Sync | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79077 | Chromium: CVE-2026-79077 Incorrect authorization in WebProtect | UNKNOWN | — | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-79078 | Chromium: CVE-2026-79078 Use after free in FedCM | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79082 | Chromium: CVE-2026-79082 Incorrect authorization in Transactions Platform | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79083 | Chromium: CVE-2026-79083 Improper enforcement of behavioral workflow in Media | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79084 | Chromium: CVE-2026-79084 Inadequate encryption strength in Notifications | UNKNOWN | — | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-79085 | Chromium: CVE-2026-79085 Missing authorization in Network | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79087 | Chromium: CVE-2026-79087 Injection in Chrome Tabs | UNKNOWN | — | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-79088 | Chromium: CVE-2026-79088 Incorrect authorization in FileSystem | UNKNOWN | — | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-79089 | Chromium: CVE-2026-79089 Race condition in Transactions Platform | UNKNOWN | — | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-79090 | Chromium: CVE-2026-79090 Improper privilege management in Actor | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-79091 | Chromium: CVE-2026-79091 Use after free in Bluetooth | UNKNOWN | — | 27%ile | Microsoft | 2026-08-11 |
| CVE-2026-79093 | Chromium: CVE-2026-79093 Incorrect authorization in Paint | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79094 | Chromium: CVE-2026-79094 Race condition in Workers | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79095 | Chromium: CVE-2026-79095 Information leak in Payments | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79097 | Chromium: CVE-2026-79097 Use after free in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79098 | Chromium: CVE-2026-79098 UI misrepresentation in PermissionElement | UNKNOWN | — | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-79099 | Chromium: CVE-2026-79099 Missing authorization in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79103 | Chromium: CVE-2026-79103 Incorrect reference resolution in Speech | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79104 | Chromium: CVE-2026-79104 Missing authorization in Sensor | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-79106 | Chromium: CVE-2026-79106 Improper input validation in Input | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79107 | Chromium: CVE-2026-79107 Incorrect authorization in TabGroups | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79108 | Chromium: CVE-2026-79108 UI misrepresentation in Web Authentication (Passkeys & Security Keys) | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79109 | Chromium: CVE-2026-79109 Improper input validation in Printing | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79110 | Chromium: CVE-2026-79110 Missing authorization in Preload | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79111 | Chromium: CVE-2026-79111 Improper input validation in Dawn | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79112 | Chromium: CVE-2026-79112 Out of bounds read in Skia | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79116 | Chromium: CVE-2026-79116 Missing authorization in Viz | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-79118 | Chromium: CVE-2026-79118 Uninitialized resource in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79119 | Chromium: CVE-2026-79119 Use after free in PDF | UNKNOWN | — | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-79120 | Chromium: CVE-2026-79120 Uninitialized resource in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79121 | Chromium: CVE-2026-79121 Improper input validation in Chromecast | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79122 | Chromium: CVE-2026-79122 Information leak in SignIn | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79123 | Chromium: CVE-2026-79123 Improper input validation in NTP Footer | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79124 | Chromium: CVE-2026-79124 Information leak in Intents | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79125 | Chromium: CVE-2026-79125 Information leak in XR | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79126 | Chromium: CVE-2026-79126 Incorrect provision of specified functionality in Proxy | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79127 | Chromium: CVE-2026-79127 Out of bounds write in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79128 | Chromium: CVE-2026-79128 Use after free in Views | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79130 | Chromium: CVE-2026-79130 Buffer overflow in ANGLE | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-79131 | Chromium: CVE-2026-79131 Out of bounds write in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79133 | Chromium: CVE-2026-79133 Incorrect authorization in Forms | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-79134 | Chromium: CVE-2026-79134 Incorrect authorization in GetUserMedia | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-79136 | Chromium: CVE-2026-79136 Incorrect authorization in ServiceWorker | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-79137 | Chromium: CVE-2026-79137 Incorrect authorization in Extensions | UNKNOWN | — | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-79138 | Chromium: CVE-2026-79138 Out of bounds write in ANGLE | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79139 | Chromium: CVE-2026-79139 Improper input validation in Media | UNKNOWN | — | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-79140 | Chromium: CVE-2026-79140 Use after free in Views | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79141 | Chromium: CVE-2026-79141 Incorrect authorization in Browser | UNKNOWN | — | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-79142 | Chromium: CVE-2026-79142 Buffer overflow in ANGLE | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-79143 | Chromium: CVE-2026-79143 Incorrect authorization in FileSystem | UNKNOWN | — | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-79144 | Chromium: CVE-2026-79144 Information leak in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79147 | Chromium: CVE-2026-79147 Information leak in Skia | UNKNOWN | — | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-79148 | Chromium: CVE-2026-79148 Off-by-one error in DevTools | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79149 | Chromium: CVE-2026-79149 Use after free in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79150 | Chromium: CVE-2026-79150 Use after free in Views | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79151 | Chromium: CVE-2026-79151 Improper input validation in Safebrowsing | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79154 | Chromium: CVE-2026-79154 Missing authorization in DevTools | UNKNOWN | — | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-79155 | Chromium: CVE-2026-79155 Race condition in FileSystem | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79173 | Chromium: CVE-2026-79173 UI misrepresentation in WebAppInstalls | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79174 | Chromium: CVE-2026-79174 Incorrect authorization in Extensions | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79175 | Chromium: CVE-2026-79175 Type confusion in Accessibility | UNKNOWN | — | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-79176 | Chromium: CVE-2026-79176 UI misrepresentation in Extensions | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79177 | Chromium: CVE-2026-79177 Incorrect authorization in Media | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79178 | Chromium: CVE-2026-79178 Incorrect authorization in Web Authentication (Passkeys & Security Keys) | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-79179 | Chromium: CVE-2026-79179 Incorrect authorization in DOM | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-79181 | Chromium: CVE-2026-79181 Observable discrepancy in Glic | UNKNOWN | — | 13%ile | Microsoft | 2026-08-11 |
| CVE-2026-79182 | Chromium: CVE-2026-79182 Improper input validation in Media | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79183 | Chromium: CVE-2026-79183 Use after free in Accessibility | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79184 | Chromium: CVE-2026-79184 Missing authorization in Preload | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79185 | Chromium: CVE-2026-79185 Information leak in DOM | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79186 | Chromium: CVE-2026-79186 Incorrect authorization in Network | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79187 | Chromium: CVE-2026-79187 Use after free in WebRTC | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79188 | Chromium: CVE-2026-79188 Out of bounds write in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79189 | Chromium: CVE-2026-79189 Out of bounds write in ANGLE | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79190 | Chromium: CVE-2026-79190 Incorrect authorization in Extensions | UNKNOWN | — | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-79191 | Chromium: CVE-2026-79191 Incorrect authorization in SiteIsolation | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79192 | Chromium: CVE-2026-79192 Improper input validation in Variations | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79193 | Chromium: CVE-2026-79193 Information leak in Canvas | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79194 | Chromium: CVE-2026-79194 Use after free in Chromoting | UNKNOWN | — | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-79195 | Chromium: CVE-2026-79195 Use after free in Script | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79196 | Chromium: CVE-2026-79196 Race condition in Editing | UNKNOWN | — | 7%ile | Microsoft | 2026-08-11 |
| CVE-2026-79197 | Chromium: CVE-2026-79197 Use after free in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79198 | Chromium: CVE-2026-79198 Use after free in Platform | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79199 | Chromium: CVE-2026-79199 Incorrect authorization in Network | UNKNOWN | — | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-79200 | Chromium: CVE-2026-79200 Use after free in Aura | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79201 | Chromium: CVE-2026-79201 Improper access control in Workers | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79202 | Chromium: CVE-2026-79202 Use after free in Chromecast | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79203 | Chromium: CVE-2026-79203 Improper input validation in DevTools | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79204 | Chromium: CVE-2026-79204 UI misrepresentation in Input | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79205 | Chromium: CVE-2026-79205 Incorrect authorization in Network | UNKNOWN | — | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-79206 | Chromium: CVE-2026-79206 Out of bounds read in FileSystem | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79208 | Chromium: CVE-2026-79208 Missing authorization in HTTP2 | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79209 | Chromium: CVE-2026-79209 Type confusion in Animation | UNKNOWN | — | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-79211 | Chromium: CVE-2026-79211 Incorrect authorization in USB | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79212 | Chromium: CVE-2026-79212 Missing authorization in Passwords | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79214 | Chromium: CVE-2026-79214 Improper input validation in Preload | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79215 | Chromium: CVE-2026-79215 Integer overflow in WebGL | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79216 | Chromium: CVE-2026-79216 Buffer overflow in Blink | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-79218 | Chromium: CVE-2026-79218 Incorrect authorization in Sandbox | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79219 | Chromium: CVE-2026-79219 Use after free in Bluetooth | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-79220 | Chromium: CVE-2026-79220 Information leak in Network | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79221 | Chromium: CVE-2026-79221 Uninitialized resource in Dawn | UNKNOWN | — | 19%ile | Microsoft | 2026-08-11 |
| CVE-2026-79223 | Chromium: CVE-2026-79223 Integer overflow in Chromium | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79224 | Chromium: CVE-2026-79224 Use after free in Chromecast | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-79225 | Chromium: CVE-2026-79225 Incorrect authorization in Browser | UNKNOWN | — | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-79226 | Chromium: CVE-2026-79226 Improper privilege management in Regional Capabilities | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79227 | Chromium: CVE-2026-79227 Type confusion in DevTools | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-79228 | Chromium: CVE-2026-79228 Incorrect authorization in SiteIsolation | UNKNOWN | — | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-79229 | Chromium: CVE-2026-79229 Uninitialized resource in ANGLE | UNKNOWN | — | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-79230 | Chromium: CVE-2026-79230 Improper input validation in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79231 | Chromium: CVE-2026-79231 Buffer overflow in Media | UNKNOWN | — | 36%ile | Microsoft | 2026-08-11 |
| CVE-2026-79232 | Chromium: CVE-2026-79232 Use after free in Aura | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79234 | Chromium: CVE-2026-79234 Injection in CSS | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79235 | Chromium: CVE-2026-79235 Use after free in WebGL | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79236 | Chromium: CVE-2026-79236 Type confusion in V8 | UNKNOWN | — | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-79237 | Chromium: CVE-2026-79237 Incorrect authorization in Navigation | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79238 | Chromium: CVE-2026-79238 Incorrect authorization in ServiceWorker | UNKNOWN | — | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-79239 | Chromium: CVE-2026-79239 Out of bounds read in Tint | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79240 | Chromium: CVE-2026-79240 Out of bounds write in ANGLE | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79242 | Chromium: CVE-2026-79242 Observable discrepancy in HTML | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79243 | Chromium: CVE-2026-79243 Improper input validation in ReadingList | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79244 | Chromium: CVE-2026-79244 Use after free in Animation | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79245 | Chromium: CVE-2026-79245 Use after free in UI | UNKNOWN | — | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-79246 | Chromium: CVE-2026-79246 Information leak in DataTransfer | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79247 | Chromium: CVE-2026-79247 Use after free in Chromoting | UNKNOWN | — | 32%ile | Microsoft | 2026-08-11 |
| CVE-2026-79248 | Chromium: CVE-2026-79248 Incorrect authorization in Input | UNKNOWN | — | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-79249 | Chromium: CVE-2026-79249 Code injection in Bisection | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79250 | Chromium: CVE-2026-79250 UI misrepresentation in Navigation | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79251 | Chromium: CVE-2026-79251 Improper input validation in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79252 | Chromium: CVE-2026-79252 Information leak in ServiceWorker | UNKNOWN | — | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-79253 | Chromium: CVE-2026-79253 Improper input validation in Network | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79255 | Chromium: CVE-2026-79255 Improper input validation in WebRTC | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-79257 | Chromium: CVE-2026-79257 Use after free in Views | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79258 | Chromium: CVE-2026-79258 Incorrect authorization in WebXR | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79259 | Chromium: CVE-2026-79259 Improper input validation in Safebrowsing | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79260 | Chromium: CVE-2026-79260 Improper input validation in Cookies | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79261 | Chromium: CVE-2026-79261 Incorrect authorization in Controls | UNKNOWN | — | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-79262 | Chromium: CVE-2026-79262 Incorrect authorization in Network | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-79263 | Chromium: CVE-2026-79263 Race condition in Extensions | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79264 | Chromium: CVE-2026-79264 Incorrect reference resolution in Preload | UNKNOWN | — | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-79265 | Chromium: CVE-2026-79265 Incomplete cleanup in GetUserMedia | UNKNOWN | — | 22%ile | Microsoft | 2026-08-11 |
| CVE-2026-79266 | Chromium: CVE-2026-79266 Use after free in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-08-11 |
| CVE-2026-79267 | Chromium: CVE-2026-79267 Race condition in Workers | UNKNOWN | — | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-79269 | Chromium: CVE-2026-79269 Uninitialized resource in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79270 | Chromium: CVE-2026-79270 Uninitialized resource in ANGLE | UNKNOWN | — | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-79271 | Chromium: CVE-2026-79271 Information leak in DOM | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-79272 | Chromium: CVE-2026-79272 Improper input validation in FindInPage | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79274 | Chromium: CVE-2026-79274 Information leak in GPU | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79275 | Chromium: CVE-2026-79275 Use after free in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79276 | Chromium: CVE-2026-79276 Improper privilege management in FileSystem | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79283 | Chromium: CVE-2026-79283 UI misrepresentation in Geometry | UNKNOWN | — | 10%ile | Microsoft | 2026-08-11 |
| CVE-2026-79284 | Chromium: CVE-2026-79284 UI misrepresentation in Core | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79285 | Chromium: CVE-2026-79285 Uninitialized resource in ANGLE | UNKNOWN | — | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-79287 | Chromium: CVE-2026-79287 Observable discrepancy in Forms | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79289 | Chromium: CVE-2026-79289 Improper control of a resource through its lifetime in Workers | UNKNOWN | — | 12%ile | Microsoft | 2026-08-11 |
| CVE-2026-79290 | Chromium: CVE-2026-79290 Use after free in Aura | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79291 | Chromium: CVE-2026-79291 Information leak in CSS | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79292 | Chromium: CVE-2026-79292 Integer overflow in Chromecast | UNKNOWN | — | 35%ile | Microsoft | 2026-08-11 |
| CVE-2026-79293 | Chromium: CVE-2026-79293 Information leak in Animation | UNKNOWN | — | 24%ile | Microsoft | 2026-08-11 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-44210 | Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations | CRITICAL | 9.9 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-45499 | Azure OpenAI Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50517 | Microsoft M365 Copilot Remote Code Execution Vulnerability | CRITICAL | 9.9 | 68%ile | Microsoft | 2026-07-14 |
| CVE-2026-54120 | Microsoft Surface Remote Code Execution Vulnerability | CRITICAL | 9.9 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-57092 | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-57100 | Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-15043 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-17543 | SQL injection in ext-pgsql via E'...' backslash breakout | CRITICAL | 9.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-38968 | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ide | CRITICAL | 9.8 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-53374 | drm/amdgpu: zero-initialize GART table on allocation | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53376 | drm/amdkfd: Add upper bound check for num_of_nodes | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53384 | serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails | CRITICAL | 9.8 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-53403 | fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-55971 | Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() | CRITICAL | 9.8 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-57433 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record | CRITICAL | 9.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-63800 | pNFS: Fix use-after-free in pnfs_update_layout() | CRITICAL | 9.8 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-63824 | KEYS: fix overflow in keyctl_pkey_params_get_2() | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63827 | apparmor: fix use-after-free in rawdata dedup loop | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-63828 | apparmor: mediate the implicit connect of TCP fast open sendmsg | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63833 | ntfs3: reject direct userspace writes to reserved $LX* xattrs | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-63881 | drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger | CRITICAL | 9.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-63882 | drm/amdkfd: fix NULL pointer bug in svm_range_set_attr | CRITICAL | 9.8 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-63959 | usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT | CRITICAL | 9.8 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-63974 | Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close | CRITICAL | 9.8 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-63979 | net/handshake: hand off the pinned file reference to accept_doit | CRITICAL | 9.8 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-63983 | net/sched: fix packet loop on netem when duplicate is on | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-63999 | ethtool: rss: fix indir_table and hkey leak on get_rxfh failure | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64017 | blk-mq: pop cached request if it is usable | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64070 | powerpc/hv-gpci: fix preempt count leak in sysfs show paths | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64076 | netfilter: bridge: eb_tables: close module init race | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64078 | netfilter: x_tables: add and use xtables_unregister_table_exit | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64079 | netfilter: x_tables: allocate hook ops while under mutex | CRITICAL | 9.8 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-64138 | ksmbd: validate SID in parent security descriptor during ACL inheritance | CRITICAL | 9.8 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-42990 | SQL Server ODBC driver Elevation of Privilege Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-49172 | Windows FTP Service Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-50447 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-50518 | Windows DHCP Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100%ile | Microsoft | 2026-07-14 |
| CVE-2026-54117 | Microsoft SQL Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-54118 | Microsoft SQL Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-54990 | Remote Desktop Client Remote Code Execution Vulnerability | CRITICAL | 9.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-55010 | Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-55944 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 74%ile | Microsoft | 2026-07-14 |
| CVE-2026-56159 | DHCP Server Service Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-56165 | Microsoft Account Remote Code Execution Vulnerability | CRITICAL | 9.8 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-56188 | Windows Server Network driver Remote Code Execution Vulnerability | CRITICAL | 9.8 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-56190 | Remote Desktop Protocol Remote Code Execution Vulnerability | CRITICAL | 9.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 97%ile | Microsoft | 2026-07-14 |
| CVE-2026-50380 | Windows GDI+ Remote Code Execution Vulnerability | CRITICAL | 9.6 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-55008 | Microsoft Exchange Server Spoofing Vulnerability | CRITICAL | 9.6 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-41106 | Microsoft 365 Copilot Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-49798 | Windows Kernel Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-62835 | Azure Portal Information Disclosure Vulnerability | CRITICAL | 9.3 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-11564 | Native CA trust persist | CRITICAL | 9.1 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-14740 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment | CRITICAL | 9.1 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-48144 | Apache Thrift: c_glib TLS Client Missing Hostname Verification | CRITICAL | 9.1 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-58023 | Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path | CRITICAL | 9.1 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-58662 | Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass | CRITICAL | 9.1 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-60082 | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row | CRITICAL | 9.1 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-8924 | trailing dot domain super cookie | CRITICAL | 9.1 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | CRITICAL | 9.1 | 99%ile | Microsoft | 2026-07-14 |
| CVE-2026-58289 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | CRITICAL | 9.0 | 80%ile | Microsoft | 2026-07-14 |
| CVE-2026-14380 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile | HIGH | 8.8 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-58253 | NATS Server: Route API Auth Bypass | HIGH | 8.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-63807 | KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level | HIGH | 8.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64475 | vfio/pci: Release the VGA arbiter client on register_device() failure | HIGH | 8.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-66032 | libssh2 Double-Free Heap Corruption via sftp_open() | HIGH | 8.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-47295 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 61%ile | Microsoft | 2026-07-14 |
| CVE-2026-47300 | ASP.NET Core Elevation of Privilege Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-47301 | Configuration Manager Elevation of Privilege Vulnerability | HIGH | 8.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-47303 | ASP.NET Core Elevation of Privilege Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-47632 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 8.8 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-48564 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-49178 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-49795 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50342 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 8.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50360 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50369 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50370 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 8.8 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50382 | DirectX Graphics Kernel Remote Code Execution Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50385 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 8.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50398 | Windows Media Elevation of Privilege Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-50413 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50438 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 8.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-50444 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50474 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-50477 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50489 | Win32k Elevation of Privilege Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50663 | Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-50666 | Windows Remote Access Elevation of Privilege Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-50670 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50687 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50692 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-54107 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-54121 | Active Directory Certificate Services Elevation of Privilege Vulnerability | HIGH | 8.8 | 77%ile | Microsoft | 2026-07-14 |
| CVE-2026-54982 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-54998 | Microsoft Exchange Online Elevation of Privilege Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-54999 | Windows TCP/IP Remote Code Execution Vulnerability | HIGH | 8.8 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-55002 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-55005 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH | 8.8 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-55052 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-56194 | Windows NFS Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-56196 | Windows Admin Center (WAC) Remote Code Execution Vulnerability | HIGH | 8.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-56197 | Windows Admin Center (WAC) Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-56642 | Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-56645 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-56647 | Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-57087 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-57090 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-57094 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-57102 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-57969 | Azure CycleCloud Elevation of Privilege Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-57974 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-57981 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-58277 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-58534 | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58594 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-58608 | Windows Print Spooler Remote Code Execution Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-58626 | Windows Remote Desktop Services Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-62870 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 8.8 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-57983 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | HIGH | 8.7 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-13321 | DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field | HIGH | 8.6 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14739 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho | HIGH | 8.6 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-53366 | ipv4: account for fraggap on the paged allocation path | HIGH | 8.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-56001 | libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow | HIGH | 8.5 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-56002 | libXfont2 PCF Font Parsing Heap Buffer Overflow | HIGH | 8.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-56003 | libXfont2 computeProps Property Buffer Heap Buffer Overflow | HIGH | 8.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50340 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 8.5 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-56167 | Azure AI Search Elevation of Privilege Vulnerability | HIGH | 8.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-63803 | hdlc_ppp: sync per-proto timers before freeing hdlc state | HIGH | 8.4 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63823 | keys: Pin request_key_auth payload in instantiate paths | HIGH | 8.4 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64320 | nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page | HIGH | 8.4 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-64456 | hwrng: virtio: clamp device-reported used.len at copy_data() | HIGH | 8.4 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64513 | KVM: x86: Unconditionally recompute CR8 intercept on PPR update | HIGH | 8.4 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-49184 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 8.4 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50520 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 8.4 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-54122 | Windows GDI+ Remote Code Execution Vulnerability | HIGH | 8.4 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-54128 | Windows DHCP Client Remote Code Execution Vulnerability | HIGH | 8.4 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-54992 | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability | HIGH | 8.4 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55045 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-56181 | Windows Network Address Translation (NAT) Spoofing Vulnerability | HIGH | 8.3 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-58281 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-58284 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-58285 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-58287 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-58288 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-58295 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | HIGH | 8.3 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-58596 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | HIGH | 8.3 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-60005 | NGINX ngx_http_slice_module vulnerability | HIGH | 8.2 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-63829 | net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink | HIGH | 8.2 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64380 | smb: client: harden POSIX SID length parsing | HIGH | 8.2 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50338 | Azure Spring Apps Elevation of Privilege Vulnerability | HIGH | 8.2 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-50429 | Windows Kernel Information Disclosure Vulnerability | HIGH | 8.2 | 63%ile | Microsoft | 2026-07-14 |
| CVE-2026-50528 | .NET Security Feature Bypass Vulnerability | HIGH | 8.2 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-50680 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 8.2 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58525 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | HIGH | 8.2 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-42533 | NGINX Map directive and Regex matching vulnerability | HIGH | 8.1 | 91%ile | Microsoft | 2026-07-14 |
| CVE-2026-50721 | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload | HIGH | 8.1 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-50722 | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload | HIGH | 8.1 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-53381 | virtiofs: fix UAF on submount umount | HIGH | 8.1 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64448 | smb: client: restrict implied bcc[0] exemption to responses without data area | HIGH | 8.1 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-8286 | wrong STARTTLS connection reuse | HIGH | 8.1 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-42900 | Microsoft Windows App Store Elevation of Privilege Vulnerability | HIGH | 8.1 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-47304 | .NET Security Feature Bypass Vulnerability | HIGH | 8.1 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-49164 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.1 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-50439 | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability | HIGH | 8.1 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-50460 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 8.1 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-50487 | Windows DNS Client Elevation of Privilege Vulnerability | HIGH | 8.1 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-50686 | Windows OLE Remote Code Execution Vulnerability | HIGH | 8.1 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50694 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | HIGH | 8.1 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-54995 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | HIGH | 8.1 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-56169 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 8.1 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-56186 | Windows Secure Channel Information Disclosure Vulnerability | HIGH | 8.1 | 64%ile | Microsoft | 2026-07-14 |
| CVE-2026-58282 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 8.1 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-58283 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 8.1 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-58286 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 8.1 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-58293 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.1 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-58595 | Microsoft Bing App for IOS Spoofing Vulnerability | HIGH | 8.1 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-58617 | M365 Copilot for iOS Elevation of Privilege Vulnerability | HIGH | 8.1 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-66318 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 8.1 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-35425 | Azure API Management (APIM) Remote Code Execution Vulnerability | HIGH | 8.0 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-40400 | Windows PowerShell Remote Code Execution Vulnerability | HIGH | 8.0 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-42975 | Windows Bluetooth Port Driver Remote Code Execution | HIGH | 8.0 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-49169 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50365 | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | HIGH | 8.0 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-50502 | Windows Event Logging Service Remote Code Execution Vulnerability | HIGH | 8.0 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-50683 | Windows DHCP Client Elevation of Privilege Vulnerability | HIGH | 8.0 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-58647 | Microsoft PowerBI Report Server Spoofing Vulnerability | HIGH | 8.0 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14191 | WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader | HIGH | 7.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-16493 | Ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332) | HIGH | 7.8 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-3842 | Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-39822 | Root escape via symlink plus trailing slash in os | HIGH | 7.8 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-53388 | fuse: re-lock request before replacing page cache folio | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-59856 | Vim: Arbitrary Code Execution via PHP Omni-Completion | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-63794 | KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path | HIGH | 7.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-63802 | blk-cgroup: fix UAF in __blkcg_rstat_flush() | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63831 | mac802154: llsec: add skb_cow_data() before in-place crypto | HIGH | 7.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-63832 | wifi: mt76: add wcid publish check in mt76_sta_add | HIGH | 7.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-63853 | drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63858 | netfilter: nf_tables: add hook transactions for device deletions | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64191 | i2c: stub: Reject I2C block transfers with invalid length | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64192 | bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64266 | fuse: re-lock request before returning from fuse_ref_folio() | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64298 | NFSv4: include MAY_WRITE in open permission mask for O_TRUNC | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64305 | crypto: qat - protect service table iterations with service_lock | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64313 | crypto: ecc - Fix carry overflow in vli multiplication | HIGH | 7.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-64322 | udf: validate sparing table length as an entry count, not a byte count | HIGH | 7.8 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64341 | USB: iowarrior: fix use-after-free on disconnect race | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64382 | smb: client: fix double-free in SMB2_open() replay | HIGH | 7.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-64389 | ksmbd: validate NTLMv2 response before updating session key | HIGH | 7.8 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64391 | ksmbd: use opener credentials for ADS I/O | HIGH | 7.8 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64423 | ipv4: igmp: remove multicast group from hash table on device destruction | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64481 | ALSA: hda/cs35l41: Fix firmware load work teardown | HIGH | 7.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64508 | bpf: Support for hardening against JIT spraying | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64556 | perf/core: Detach event groups during remove_on_exec | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64600 | xfs: resample the data fork mapping after cycling ILOCK | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-42982 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-44800 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-47290 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-47305 | Visual Studio Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-47642 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-48581 | Surface Broker SDMA Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-49166 | Windows Print Configuration Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-49170 | Windows StateRepository API Server file Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-49173 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-49175 | Windows DNS Client Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-49176 | Windows WalletService Elevation of Privilege Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-49783 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-49792 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-49793 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-49796 | Windows GDI+ Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-49797 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-49800 | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-49808 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50293 | Windows Internal Task Bar Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50301 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50305 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50306 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50308 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50309 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50311 | Windows Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50313 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50314 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50315 | Windows Image Acquisition Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50317 | Windows Operating Systems Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50318 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50321 | Windows USB Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50326 | Windows Unified Consent System Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50327 | Windows Media Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50329 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50331 | Windows Application Model Core API Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50332 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50333 | Windows Spaceport.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50335 | Windows Operating Systems Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50336 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50337 | Windows Notification Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50343 | Microsoft Install Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50344 | Windows OLE Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50346 | Netlogon RPC Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50347 | Windows Data.dll Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-50351 | Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50353 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50357 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50361 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50362 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50363 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50367 | Windows Sensor Data Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50373 | Windows Search Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50378 | Windows Key Guard Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50386 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50387 | Windows GDI Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50388 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50391 | Windows Group Policy Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50399 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50400 | Windows App Package Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50402 | NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50405 | Windows Filtering Platform Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50407 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50412 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50417 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50421 | Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50422 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50423 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50425 | Windows Internal System User Profile Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50427 | Content Delivery Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50433 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50435 | Windows Overlay Filter Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50436 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50440 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50441 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50448 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50450 | Windows Network Connections Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50454 | Windows User Interface Core Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-50457 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50458 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50461 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50462 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-50466 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50467 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50469 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-50471 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50476 | Windows Network Connections Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50478 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50479 | Windows USB Hub Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50480 | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50484 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50486 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50488 | Clipboard User Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50493 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50494 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50498 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-50499 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50501 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-50509 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | HIGH | 7.8 | 89%ile | Microsoft | 2026-07-14 |
| CVE-2026-50510 | GitHub Copilot Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-50646 | .NET Framework Remote Code Execution Vulnerability | HIGH | 7.8 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-50649 | .NET Remote Code Execution Vulnerability | HIGH | 7.8 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-50650 | .NET Framework Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50655 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50665 | Microsoft Office Information Disclosure Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50667 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50673 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50675 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50676 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50677 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50679 | Windows Search Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50688 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50689 | Windows Clipboard Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50697 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-54109 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-54112 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-54114 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-54115 | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-54124 | Windows Terminal Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-54125 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-54131 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-54986 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-54987 | Windows Overlay Filter Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-54991 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-54993 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55001 | Active Directory Domain Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55004 | Windows Print Configuration Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55006 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55009 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 84%ile | Microsoft | 2026-07-14 |
| CVE-2026-55011 | Microsoft Defender Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-55012 | Microsoft Defender Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-55014 | Windows Remote Help Defense Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55017 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55018 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55022 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55024 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55025 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55029 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55031 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55032 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55033 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55036 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55037 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55038 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55039 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55041 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55043 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55044 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55048 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55049 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55053 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55055 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55056 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55058 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55120 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55123 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55125 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55127 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55128 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55129 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55130 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55131 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55132 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55133 | Microsoft OneNote Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55134 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55136 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55137 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55140 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55141 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55899 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55947 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55948 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55949 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-56156 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-56175 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-56176 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-56182 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-56189 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-56643 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-56644 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-56650 | Windows Network File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-57088 | Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-57091 | Windows File History Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-57096 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-57107 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-57968 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58527 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-58530 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-58532 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58536 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58537 | Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58538 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58540 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-58541 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58542 | Windows Media Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-58601 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58602 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58609 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-58610 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-58613 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-58618 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-58628 | Windows Wireless Network Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-58631 | Windows Admin Center (WAC) Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-58632 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58633 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58634 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58635 | Windows Narrator Braille Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-58636 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-15392 | DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location | HIGH | 7.7 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17527 | Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes | HIGH | 7.7 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-55953 | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication | HIGH | 7.7 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-58207 | NATS Server: Remote crash via integer overflow in Connz pagination | HIGH | 7.7 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-60002 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This | HIGH | 7.7 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-63940 | KVM: SEV: Ignore Port I/O requests of length '0' | HIGH | 7.7 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-66310 | Microsoft Edge for Android Information Disclosure Vulnerability | HIGH | 7.7 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-57985 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.6 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2025-63913 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI fu | HIGH | 7.5 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-11331 | Potential wildcard CNAME RPZ policy bypass | HIGH | 7.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-11352 | QUIC zero-length UDP datagrams busy-loop | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-11586 | WS Auto-PONG memory exhaustion | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-11605 | Unnecessary validation of DNSSEC signed records | HIGH | 7.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-11622 | Potential memory usage beyond configured limits | HIGH | 7.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-11721 | Cache poisoning possible with label count discrepancy, RRSIG, and wildcards | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-12413 | IKEv2 Denial of Service via malformed fragmentation | HIGH | 7.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-12617 | Record ordering based unexpected exit with CNAME or DNAME | HIGH | 7.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-13204 | Unexpected exit in certain situations with NSEC and NSEC3 both present | HIGH | 7.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-15308 | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations | HIGH | 7.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-15709 | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of s | HIGH | 7.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-15711 | Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol viola | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-16313 | Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export | HIGH | 7.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-20213 | ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-20214 | ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-20215 | ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-20216 | ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-20217 | ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-20243 | ClamAV ALZ Archive Processing Denial of Service Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-32665 | Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass | HIGH | 7.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-38754 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv | HIGH | 7.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-38755 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser | HIGH | 7.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-38969 | ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smugg | HIGH | 7.5 | — | Microsoft | 2026-07-14 |
| CVE-2026-40691 | Packet of death for DNSCrypt over TCP | HIGH | 7.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-41608 | Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport | HIGH | 7.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-43871 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-44690 | Cross-zone wildcard cache poisoning via RRSIG.labels manipulation | HIGH | 7.5 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-46600 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | HIGH | 7.5 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-48145 | Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass | HIGH | 7.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-48586 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression S | HIGH | 7.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-48863 | Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-53375 | drm/amdgpu/vce: Prevent partial address patches | HIGH | 7.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53400 | i2c: core: fix adapter registration race | HIGH | 7.5 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-54332 | GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 1 | HIGH | 7.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-55969 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol: | HIGH | 7.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-55973 | 'dns-error-reporting: yes' leads to stack buffer overflow | HIGH | 7.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-56852 | Infinite loop on invalid input in golang.org/x/text | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-57219 | RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth | HIGH | 7.5 | 80%ile | Microsoft | 2026-07-14 |
| CVE-2026-57220 | RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-ex | HIGH | 7.5 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-57432 | Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack | HIGH | 7.5 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-58043 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Un | HIGH | 7.5 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-58250 | NATS Server: Pre-auth server crash via double INFO in leafnode handshake | HIGH | 7.5 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-59884 | pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs | HIGH | 7.5 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-59885 | pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service | HIGH | 7.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-59886 | pyasn1: Uncontrolled resource consumption when converting decoded REAL values | HIGH | 7.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-59922 | Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough | HIGH | 7.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-59925 | inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs | HIGH | 7.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-59928 | Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions | HIGH | 7.5 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-60081 | DBI::ProfileData versions before 1.651 for Perl do not limit the path index | HIGH | 7.5 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-62309 | CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS | HIGH | 7.5 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-63793 | ntfs: serialize volume label accesses | HIGH | 7.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-63836 | batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd | HIGH | 7.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63872 | esp: fix page frag reference leak on skb_to_sgvec failure | HIGH | 7.5 | — | Microsoft | 2026-07-14 |
| CVE-2026-64383 | smb: client: fix double-free in SMB2_flush() replay | HIGH | 7.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-66033 | libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-66034 | libssh2 Heap Out-of-Bounds Read via publickey subsystem | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-66035 | libssh2 Heap Buffer Overflow via ETM Cipher Negotiation | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-66373 | Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio | HIGH | 7.5 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-67215 | cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion | HIGH | 7.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-8932 | incomplete mTLS config matching in conn reuse | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-9545 | exposing HTTP/3 early data | HIGH | 7.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-9546 | sending old referer | HIGH | 7.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-40378 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-45646 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-47296 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-47302 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-49171 | Windows Speech Runtime Elevation of Privilege Vulnerability | HIGH | 7.5 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-49181 | Windows DHCP Client Elevation of Privilege Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-49787 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-49788 | HTTP/2 Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50304 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50328 | Windows Server Update Service (WSUS) Tampering Vulnerability | HIGH | 7.5 | 68%ile | Microsoft | 2026-07-14 |
| CVE-2026-50330 | Windows Remote Desktop Client Elevation of Privilege Vulnerability | HIGH | 7.5 | 68%ile | Microsoft | 2026-07-14 |
| CVE-2026-50355 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50368 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50379 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50411 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50414 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-50424 | Windows Domain Controller Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50463 | Windows Kernel Information Disclosure Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-50470 | Windows Network Policy Server SNMP Information Disclosure Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-50496 | Windows Network Policy Server SNMP Information Disclosure Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50500 | Windows Netlogon Elevation of Privilege Vulnerability | HIGH | 7.5 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-50505 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability | HIGH | 7.5 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-50506 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50524 | .NET Framework Denial of Service Vulnerability | HIGH | 7.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-50525 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-50527 | .NET Framework Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-50647 | Active Directory Federation Server Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50648 | .NET Framework Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-50651 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-50652 | Azure Active Directory Denial of Service Vulnerability | HIGH | 7.5 | 76%ile | Microsoft | 2026-07-14 |
| CVE-2026-50653 | Azure Active Directory Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50685 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 7.5 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-50695 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50696 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-54119 | Windows Active Directory Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-54983 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-56170 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-56648 | Windows NFS Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-57089 | Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability | HIGH | 7.5 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-57108 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-07-14 |
| CVE-2026-57975 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-57984 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-57986 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-57992 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-58276 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-58290 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-58292 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-58294 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-58299 | Microsoft Edge for Android Remote Code Execution Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-58531 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-58627 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-59117 | Windows Terminal Remote Code Execution Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-66315 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-12064 | proto-default skips SSH verification | HIGH | 7.4 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-64112 | rbd: eliminate a race in lock_dwork draining on unmap | HIGH | 7.4 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-54127 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.4 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-57989 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-57990 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-57991 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-57993 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 7.4 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-65802 | Microsoft Edge for Android Information Disclosure Vulnerability | HIGH | 7.4 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-66321 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.4 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-12080 | Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys | HIGH | 7.3 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-53362 | ipv6: account for fraggap on the paged allocation path | HIGH | 7.3 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-63806 | KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() | HIGH | 7.3 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-49789 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.3 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-49790 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.3 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-50364 | Windows Backup Service Elevation of Privilege Vulnerability | HIGH | 7.3 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50482 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.3 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55021 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-55034 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-55126 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-58640 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.3 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-58298 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 7.2 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-53329 | drm/amd/display: Use krealloc_array() in dal_vector_reserve() | HIGH | 7.1 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-53343 | ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-53354 | arm64: errata: Mitigate TLBI errata on various Arm CPUs | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53356 | drm/i915/gem: Fix phys BO pread/pwrite with offset | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53368 | f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53402 | fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63796 | ocfs2: reject oversized group bitmap descriptors | HIGH | 7.1 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-63801 | tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done | HIGH | 7.1 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-63805 | crypto: nx - fix nx_crypto_ctx_exit argument | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63810 | block: Avoid mounting the bdev pseudo-filesystem in userspace | HIGH | 7.1 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-63826 | fbdev: fix use-after-free in store_modes() | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-63879 | drm/amdgpu: fix amdgpu_hmm_range_get_pages | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63961 | usb: typec: altmodes/displayport: validate count before reading Status Update VDO | HIGH | 7.1 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-63963 | usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers | HIGH | 7.1 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-63978 | net/handshake: Drain pending requests at net namespace exit | HIGH | 7.1 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-64117 | wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb | HIGH | 7.1 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-64133 | ALSA: asihpi: Fix potential OOB array access at reading cache | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64146 | erofs: fix metabuf leak in inode xattr initialization | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64154 | drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64189 | netfilter: ipset: fix race between dump and ip_set_list resize | HIGH | 7.1 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-64210 | net/mlx5e: xsk: Fix unlocked writing to ICOSQ | HIGH | 7.1 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-64212 | wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64213 | hwmon: (lm90) Add lock protection to lm90_alert | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64219 | drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64227 | ACPI: driver: Check ACPI_COMPANION() against NULL during probe | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64245 | fbdev: modedb: fix a possible UAF in fb_find_mode() | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64255 | wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers | HIGH | 7.1 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-64268 | RDMA/siw: bound Read Response placement to the RREAD length | HIGH | 7.1 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-64280 | fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64286 | KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64294 | mm: do file ownership checks with the proper mount idmap | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64303 | spi: fsl-lpspi: terminate the RX channel on TX prepare failure path | HIGH | 7.1 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-64316 | crypto: caam - use print_hex_dump_devel to guard key hex dumps | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64355 | bpf: Reject fragmented frames in devmap | HIGH | 7.1 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-64362 | HID: lg-g15: cancel pending work on remove to fix a use-after-free | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64372 | cpufreq: pcc: fix use-after-free and double free in _OSC evaluation | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64375 | proc: protect ptrace_may_access() with exec_update_lock (FD links) | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64379 | smb: client: mask server-provided mode to 07777 in modefromsid | HIGH | 7.1 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-64384 | smb: client: fix change notify replay double-free | HIGH | 7.1 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64385 | smb: client: fix double-free in SMB2_ioctl() replay | HIGH | 7.1 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64386 | smb: client: fix query_info() replay double-free | HIGH | 7.1 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64403 | Bluetooth: L2CAP: validate option length before reading conf opt value | HIGH | 7.1 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-64405 | Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64411 | netfilter: ebtables: terminate table name before find_table_lock() | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64428 | gpio: sch: use raw_spinlock_t in the irq startup path | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64435 | audit: Fix data races of skb_queue_len() readers on audit_queue | HIGH | 7.1 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-64470 | Bluetooth: btusb: fix use-after-free on marvell probe failure | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64471 | Bluetooth: btusb: fix use-after-free on registration failure | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64496 | iio: event: Fix event FIFO reset race | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64510 | ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64514 | userfaultfd: gate must_wait writability check on pte_present() | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64536 | staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop | HIGH | 7.1 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-64557 | Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() | HIGH | 7.1 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-49165 | Microsoft Windows App Store Information Disclosure Vulnerability | HIGH | 7.1 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-49791 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.1 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-50354 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.1 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50428 | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability | HIGH | 7.1 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-50451 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.1 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-50465 | Windows DNS Client Tampering Vulnerability | HIGH | 7.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50682 | Active Directory Denial of Service Vulnerability | HIGH | 7.1 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-55122 | Microsoft Excel Information Disclosure Vulnerability | HIGH | 7.1 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-55144 | Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability | HIGH | 7.1 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-56171 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | HIGH | 7.1 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-56193 | Microsoft Office Information Disclosure Vulnerability | HIGH | 7.1 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-57101 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.1 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-57977 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 7.1 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-57988 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.1 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-58296 | Microsoft Edge for Android Information Disclosure Vulnerability | HIGH | 7.1 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-58297 | Microsoft Edge for Android Information Disclosure Vulnerability | HIGH | 7.1 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-58529 | Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability | HIGH | 7.1 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-66322 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 7.1 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-53401 | fbdev: omap2: fix use-after-free in omapfb_mmap | HIGH | 7.0 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64377 | cpufreq: qcom-cpufreq-hw: Fix possible double free | HIGH | 7.0 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64530 | net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle | HIGH | 7.0 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-64560 | posix-cpu-timers: Prevent UAF caused by non-leader exec() race | HIGH | 7.0 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-48571 | Windows App Package Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-48572 | Windows App Package Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-49162 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-49183 | Windows Clipboard Server Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-49784 | Microsoft Windows App Store Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-49802 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-49803 | Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-49805 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-49806 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50296 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50297 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50307 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50322 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50323 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50325 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50345 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50348 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-50356 | Microsoft Windows App Store Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50358 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50359 | Microsoft XML Core Services Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50371 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50372 | Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50384 | Windows Clip Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50390 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50392 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50393 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50396 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50397 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50403 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50404 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50406 | Windows Backup Engine Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50410 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50449 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50452 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-50459 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50490 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50491 | Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50503 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50526 | .NET Tampering Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-50658 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50669 | Windows Telephony Server Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50672 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50674 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-54111 | Universal Print Management Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-54129 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-54989 | Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-54996 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-56173 | Windows WebView Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-56183 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-56187 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-57093 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-58526 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-58544 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-58598 | Windows Backup Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-58619 | Windows Sensor Data Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-58629 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-58637 | Windows Client-Side Caching Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-10723 | Incorrect acceptance of NSEC3 records | MEDIUM | 6.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-16615 | Librest: weak random number generation in pkce implementation | MEDIUM | 6.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-57216 | RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-a | MEDIUM | 6.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-58208 | NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled | MEDIUM | 6.8 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-6390 | Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in | MEDIUM | 6.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-49168 | Storage Spaces Direct Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50298 | Windows Spaceport.sys Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50299 | Windows Storage Spaces Direct Remote Code Execution Vulnerability | MEDIUM | 6.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50426 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.8 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-50492 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | MEDIUM | 6.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50668 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-54132 | Windows Kernel Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-58522 | Microsoft Edge for Android Information Disclosure Vulnerability | MEDIUM | 6.8 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-58528 | Windows USB Audio Class Driver Information Disclosure Vulnerability | MEDIUM | 6.8 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-66313 | Microsoft Edge (Chromium-based) Tampering Vulnerability | MEDIUM | 6.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-53397 | nfsd: fix posix_acl leak on SETACL decode failure | MEDIUM | 6.7 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-49804 | Windows USB Video Driver Elevation of Privilege Vulnerability | MEDIUM | 6.6 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-50678 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.6 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-10822 | Key Record using PRIVATEDNS algorithm may lead to unexpected exit | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-14258 | Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling | MEDIUM | 6.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-15714 | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversi | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-16277 | Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() | MEDIUM | 6.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-16461 | Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting | MEDIUM | 6.5 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-47729 | Squid: Memory disclosure in FTP gateway | MEDIUM | 6.5 | 73%ile | Microsoft | 2026-07-14 |
| CVE-2026-50248 | BOGUS configured primary hostname accepted for XFR in auth/rpz zones | MEDIUM | 6.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53345 | KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying | MEDIUM | 6.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-54171 | Excon: redact additional sensitive/risky headers when following redirects | MEDIUM | 6.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-55970 | Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-56434 | NGINX ngx_http_ssi_module vulnerability | MEDIUM | 6.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-57211 | RabbitMQ: UNC SSRF affecting the management UI on Windows | MEDIUM | 6.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-57217 | RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-58251 | NATS Server: Queue Subscribe Authz Bypass | MEDIUM | 6.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-58252 | NATS Server: Subscribe Authz Bypass via Wildcard-Overlap | MEDIUM | 6.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-59818 | etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation | MEDIUM | 6.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-59843 | Libssh: libssh: denial of service via zero advertised channel packet size | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-59844 | Libssh: libssh: denial of service via oversized sftp read length | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-60001 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. | MEDIUM | 6.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-64381 | smb: client: Fix next buffer leak in receive_encrypted_standard() | MEDIUM | 6.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64534 | nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path | MEDIUM | 6.5 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-66337 | Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until() | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-66339 | Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-8458 | wrong reuse for different services | MEDIUM | 6.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-34348 | Windows Event Logging Service Information Disclosure Vulnerability | MEDIUM | 6.5 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-45489 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-47282 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-49159 | Microsoft Graph Information Disclosure Vulnerability | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-49799 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-07-14 |
| CVE-2026-50366 | Windows Active Directory Domain Services Denial of Service Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-07-14 |
| CVE-2026-50376 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-50445 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-50468 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 61%ile | Microsoft | 2026-07-14 |
| CVE-2026-50497 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-50504 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-50659 | .NET Spoofing Vulnerability | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-54108 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 64%ile | Microsoft | 2026-07-14 |
| CVE-2026-54116 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 61%ile | Microsoft | 2026-07-14 |
| CVE-2026-54126 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-55003 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-55051 | Microsoft SharePoint Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-55054 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-56168 | Windows SMB Server Denial of Service Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-07-14 |
| CVE-2026-56185 | Windows Admin Center Information Disclosure Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-56646 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-57976 | Windows Active Directory Domain Services Denial of Service Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-07-14 |
| CVE-2026-57979 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-57982 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 61%ile | Microsoft | 2026-07-14 |
| CVE-2026-57987 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-58279 | Azure CycleCloud Elevation of Privilege Vulnerability | MEDIUM | 6.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-58523 | Microsoft Edge for Android Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-58533 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-58535 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-58539 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-58546 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-66312 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-66314 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | MEDIUM | 6.5 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-66326 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | MEDIUM | 6.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-55000 | Windows USB Print Driver Elevation of Privilege Vulnerability | MEDIUM | 6.4 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-57097 | Microsoft XML Security Feature Bypass Vulnerability | MEDIUM | 6.4 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-58040 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across ident | MEDIUM | 6.3 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-63871 | Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls | MEDIUM | 6.3 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64434 | Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref | MEDIUM | 6.3 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-50374 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | MEDIUM | 6.3 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50375 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | MEDIUM | 6.3 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-55145 | Outlook Copilot Tampering Vulnerability | MEDIUM | 6.3 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-57973 | Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability | MEDIUM | 6.3 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-58543 | Universal Print Management Service Elevation of Privilege Vulnerability | MEDIUM | 6.3 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-49807 | Windows DirectX Information Disclosure Vulnerability | MEDIUM | 6.2 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50294 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 6.2 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50420 | HTTP.sys Information Disclosure Vulnerability | MEDIUM | 6.2 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-55026 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.2 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-57095 | Win32k Elevation of Privilege Vulnerability | MEDIUM | 6.2 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-58300 | Microsoft Edge for Android Information Disclosure Vulnerability | MEDIUM | 6.2 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-66311 | Microsoft Edge (Chromium-based) Tampering Vulnerability | MEDIUM | 6.2 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-59890 | setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+ | MEDIUM | 6.1 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-59926 | Mistune: XSS via unescaped class option in Admonition directive | MEDIUM | 6.1 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-64001 | ALSA: pcm: oss: Fix setup list UAF on proc write error | MEDIUM | 6.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64287 | KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU | MEDIUM | 6.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64450 | tipc: fix out-of-bounds read in broadcast Gap ACK blocks | MEDIUM | 6.1 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-49174 | DNS Client Tampering Vulnerability | MEDIUM | 6.1 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50383 | Windows Print Spooler Information Disclosure Vulnerability | MEDIUM | 6.1 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50453 | Windows USB Audio Class Driver Information Disclosure Vulnerability | MEDIUM | 6.1 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50495 | DNS Client Tampering Vulnerability | MEDIUM | 6.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50661 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.1 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-54988 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.1 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-55898 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.1 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-58291 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | MEDIUM | 6.1 | 61%ile | Microsoft | 2026-07-14 |
| CVE-2026-65804 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.1 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-66325 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-64539 | Bluetooth: eir: Fix stack OOB write when prepending the Flags AD | MEDIUM | 6.0 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-58638 | Windows Boot Loader Security Feature Bypass Vulnerability | MEDIUM | 6.0 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14586 | Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments | MEDIUM | 5.9 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-15712 | Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-terminati | MEDIUM | 5.9 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-15713 | Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak | MEDIUM | 5.9 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-44621 | Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated | MEDIUM | 5.9 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-50046 | Possible heap use-after-free in an error path when a DoT forwarded query is jostled out | MEDIUM | 5.9 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-52863 | Memory corruption could lead to crash and denial of service | MEDIUM | 5.9 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-53357 | Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() | MEDIUM | 5.9 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-53393 | nfsd: reset write verifier on deferred writeback errors | MEDIUM | 5.9 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-55717 | 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash | MEDIUM | 5.9 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-55950 | DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions | MEDIUM | 5.9 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-55990 | Packet of death for a DNSCrypt misconfigured Unbound | MEDIUM | 5.9 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-55991 | Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 | MEDIUM | 5.9 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-56444 | Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual conf | MEDIUM | 5.9 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-59847 | Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification | MEDIUM | 5.9 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-59999 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not | MEDIUM | 5.9 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64535 | nvmet-tcp: Fix potential UAF when ddgst mismatch | MEDIUM | 5.9 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-66053 | Apache Thrift: Python TSSLSocket Hostname Matcher Import | MEDIUM | 5.9 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-67216 | cJSON cJSON_Compare Exponential Complexity Denial of Service | MEDIUM | 5.9 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-8926 | password leak with netrc and user in URL | MEDIUM | 5.9 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50324 | Windows Active Directory Federation Services Denial of Service Vulnerability | MEDIUM | 5.9 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-56649 | Windows Network File System Remote Code Execution Vulnerability | MEDIUM | 5.9 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-64160 | netfs: Fix potential for tearing in ->remote_i_size and ->zero_point | MEDIUM | 5.8 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-64269 | RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg | MEDIUM | 5.7 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-14355 | ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | MEDIUM | 5.6 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-15003 | Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service | MEDIUM | 5.6 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2024-14040 | net: nexthop: Increase weight to u16 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-10536 | HTTP/2 stream-dependency tree UAF | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-12480 | Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-50012 | Squid: Memory corruption in cache_digest reply handling | MEDIUM | 5.5 | 70%ile | Microsoft | 2026-07-14 |
| CVE-2026-53337 | net: bonding: fix NULL pointer dereference in bond_do_ioctl() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-53347 | drm/virtio: Fix driver removal with disabled KMS | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-53349 | netfilter: nf_conntrack: destroy stale expectfn expectations on unregister | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53352 | signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-53353 | hsr: Remove WARN_ONCE() in hsr_addr_is_self(). | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-53355 | net: rds: clear i_sends on setup unwind | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-53377 | drm/msm: always recover the gpu | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53382 | media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53385 | vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53391 | NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-53392 | NFSv4/flexfiles: reject zero filehandle version count | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-53398 | NFSD: Fix SECINFO_NO_NAME decode error cleanup | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-53399 | nfsd: release layout stid on setlease failure | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-63795 | 9p: avoid putting oldfid in p9_client_walk() error path | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-63809 | bpf: use kvfree() for replaced sysctl write buffer | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-63811 | f2fs: read COW data with the original inode during atomic write | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63821 | wifi: rtw88: usb: fix memory leaks on USB write failures | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63825 | gcov: use atomic counter updates to fix concurrent access crashes | MEDIUM | 5.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-63834 | batman-adv: tp_meter: restrict number of unacked list entries | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63954 | hpfs: fix a crash if hpfs_map_dnode_bitmap fails | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63960 | usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-63962 | usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-63964 | usb: typec: ucsi: ccg: reject firmware images without a ':' record header | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-64036 | cgroup/rstat: validate cpu before css_rstat_cpu() access | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64038 | hwmon: (lm90) Stop work before releasing hwmon device | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64060 | netfs: Fix leak of request in netfs_write_begin() error handling | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64077 | netfilter: ebtables: move to two-stage removal scheme | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64097 | drm/amd/display: Validate GPIO pin LUT table size before iterating | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64187 | xfs: fail recovery on a committed log item with no regions | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64188 | net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64190 | net: team: fix NULL pointer dereference in team_xmit during mode change | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64205 | i2c: i801: fix hardware state machine corruption in error path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64206 | Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-64237 | Input: elan_i2c - validate firmware size before use | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64241 | gpio: rockchip: teardown bugs and resource leaks | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64244 | drivers/base/memory: set mem->altmap after successful device registration | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64247 | KVM: x86: hyper-v: Bound the bank index when querying sparse banks | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64248 | MIPS: smp: report dying CPU to RCU in stop_this_cpu() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64250 | LoongArch: Report dying CPU to RCU in stop_this_cpu() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64275 | Input: elan_i2c - prevent division by zero and arithmetic underflow | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64276 | Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64277 | Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64299 | tracing: Prevent out-of-bounds read in glob matching | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64306 | crypto: drbg - Fix returning success on failure in CTR_DRBG | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64317 | isofs: bound Rock Ridge symlink components to the SL record | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64318 | partitions: aix: bound the pp_count scan to the ppe array | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64323 | udf: validate VAT header length against the VAT inode size | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64324 | udf: validate free block extents against the partition length | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64326 | block: skip sync_blockdev() on surprise removal in bdev_mark_dead() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64332 | USB: ulpi: fix memory leak on registration failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64346 | usb: gadget: udc: Fix use-after-free in gadget_match_driver | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64348 | usb: free iso schedules on failed submit | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64350 | usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64351 | net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64352 | bpf: Allow LPM map access from sleepable BPF programs | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64363 | HID: appleir: fix UAF on pending key_up_timer in remove() | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64364 | HID: multitouch: fix out-of-bounds bit access on mt_io_flags | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-64368 | mm/slab: do not limit zeroing to orig_size when only red zoning is enabled | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-64370 | posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64374 | sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-64387 | smb: client: fix query directory replay double-free | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64400 | ksmbd: prevent path traversal bypass by restricting caseless retry | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-64406 | Bluetooth: fix UAF in bt_accept_dequeue() | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-64408 | Bluetooth: bnep: pin L2CAP connection during netdev registration | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-64409 | Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64412 | netfilter: ebtables: module names must be null-terminated | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64413 | netfilter: ebtables: zero chainstack array | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64422 | net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64425 | io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64429 | gpio: eic-sprd: use raw_spinlock_t in the irq startup path | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-64433 | Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64441 | staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-64443 | staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-64444 | staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-64452 | 6lowpan: fix NHC entry use-after-free on error path | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-64462 | PCI: altera: Fix resource leaks on probe failure | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64465 | usb: xhci: Fix sleep in atomic context in xhci_free_streams() | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64474 | vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64482 | ALSA: gus: check snd_ctl_new1() return value | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64487 | ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64507 | x86/bugs: Enable IBPB flush on BPF JIT allocation | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64511 | ACPI: NFIT: core: Fix possible NULL pointer dereference | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64523 | net/handshake: Take a long-lived file reference at submit | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-64525 | xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64533 | fs/ntfs3: validate lcns_follow in log_replay conversion | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-7260 | Stack overflow in phar with circular symlinks | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-33842 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-34328 | Windows Audio Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-34346 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | MEDIUM | 5.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-34349 | Windows Media Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-40422 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-41087 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-45496 | Visual Studio Code Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-48580 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-49177 | Windows TCP/IP Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-49180 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-49801 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50295 | Windows Zero Trust DNS Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50300 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50303 | Windows Key Guard Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50316 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50334 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50339 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50341 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50350 | Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50352 | Windows Cryptographic Services Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50377 | Windows Kernel Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-50381 | Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50389 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50394 | Windows Media Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50401 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50408 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-50409 | Windows Overlay Filter Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50430 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50431 | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50434 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50437 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50442 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50455 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50456 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50473 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50475 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-50483 | Windows Graphics Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50681 | Windows Secure Channel Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50690 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-54997 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-55023 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-55027 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-55028 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-55035 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55042 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-55046 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-55047 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-55050 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-55057 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-55121 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-55124 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-55138 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-55139 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-55142 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-56178 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-56184 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-56192 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-56195 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-57083 | Windows Media Photo Codec Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-57084 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-57085 | Windows Print Spooler Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-58545 | Windows Kernel Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-58547 | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-58614 | Windows Kernel Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-54522 | MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure | MEDIUM | 5.4 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-66338 | Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked() | MEDIUM | 5.4 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-45488 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-56157 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-57978 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-57980 | Microsoft Edge (Chromium-based) Tampering Vulnerability | MEDIUM | 5.4 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-58278 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-58524 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-62828 | Microsoft Edge for Android (Chromium-based) Tampering Vulnerability | MEDIUM | 5.4 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-66316 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-66317 | Microsoft Edge (Chromium-based) Tampering Vulnerability | MEDIUM | 5.4 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-11856 | cross-origin Digest auth state leak | MEDIUM | 5.3 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-15588 | Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering | MEDIUM | 5.3 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-16768 | Gdk-pixbuf: out-of-bounds read in ico parser | MEDIUM | 5.3 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-42505 | Invoking Encrypted Client Hello privacy leak in crypto/tls | MEDIUM | 5.3 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-50045 | 'max-global-quota' reset by DNSSEC validation restarts | MEDIUM | 5.3 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50251 | Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush | MEDIUM | 5.3 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-59845 | Libssh: libssh: denial of service via unchecked proxycommand fork() failure | MEDIUM | 5.3 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-59848 | Libssh: libssh: denial of service via sftp responses with unknown request ids | MEDIUM | 5.3 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-62299 | CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response | MEDIUM | 5.3 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-64082 | riscv: Fix register corruption from uninitialized cregs on error | MEDIUM | 5.3 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-8927 | env-set cross-proxy Digest auth state leak | MEDIUM | 5.3 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-44806 | Windows Secure Channel Denial of Service Vulnerability | MEDIUM | 5.3 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-50415 | Windows Media Information Disclosure Vulnerability | MEDIUM | 5.3 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-50432 | Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability | MEDIUM | 5.3 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | MEDIUM | 5.3 | 98%ile | Microsoft | 2026-07-14 |
| CVE-2026-64478 | ALSA: usb-audio: avoid kobject path lookup in DualSense match | MEDIUM | 5.2 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-47143 | Capstone has a NULL Pointer Dereference with 3DNow! opcodes | MEDIUM | 5.1 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50418 | Windows System Secure Feature Bypass Vulnerability | MEDIUM | 5.1 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-63819 | f2fs: fix to do sanity check on f2fs_get_node_folio_ra() | MEDIUM | 5.0 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-38753 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv | MEDIUM | 4.9 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-16729 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields | MEDIUM | 4.8 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-26081 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise | MEDIUM | 4.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-54887 | DTLS server cookie bypass during startup window due to empty initial cookie secret | MEDIUM | 4.8 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-56416 | Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name | MEDIUM | 4.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-57213 | RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering | MEDIUM | 4.8 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-59998 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th | MEDIUM | 4.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-26145 | Microsoft Azure Synapse Elevation of Privilege Vulnerability | MEDIUM | 4.8 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50684 | Active Directory Federation Server Spoofing Vulnerability | MEDIUM | 4.8 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-64279 | i2c: core: fix adapter deregistration race | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64371 | proc: protect ptrace_may_access() with exec_update_lock (part 1) | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64373 | cpufreq: Fix hotplug-suspend race during reboot | MEDIUM | 4.7 | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-64378 | writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() | MEDIUM | 4.7 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-64542 | ipv6: ndisc: fix NULL deref in accept_untracked_na() | MEDIUM | 4.7 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-49167 | Windows Kernel Elevation of Privilege Vulnerability | MEDIUM | 4.7 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-50310 | Windows Human Interface Device Information Disclosure Vulnerability | MEDIUM | 4.7 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-50312 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | MEDIUM | 4.7 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-50657 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability | MEDIUM | 4.7 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-64547 | net: usb: net1080: validate packet_len before pad-byte access in rx_fixup | MEDIUM | 4.6 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-49794 | Windows USB Audio Class Driver Information Disclosure Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55016 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55019 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55020 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55030 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55135 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-62826 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-53361 | af_unix: Set gc_in_progress to true in unix_gc(). | MEDIUM | 4.5 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-50485 | Windows Hyper-V Denial of Service Vulnerability | MEDIUM | 4.5 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-59831 | GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace | MEDIUM | 4.4 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-63830 | net: skmsg: preserve sg.copy across SG transforms | MEDIUM | 4.4 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-63835 | batman-adv: v: prevent OGM aggregation on disabled hardif | MEDIUM | 4.4 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64388 | smb/client: fix chown/chgrp with SMB3 POSIX Extensions | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64531 | net: openvswitch: reject oversized nested action attrs | MEDIUM | 4.4 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-64544 | crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14647 | onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds | MEDIUM | 4.3 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-58209 | NATS Server: MQTT retained and QoS replay bypass subscribe deny filters | MEDIUM | 4.3 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-59850 | Libssh: libssh: use-after-free via data callbacks on closed channels | MEDIUM | 4.3 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-59930 | Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing c | MEDIUM | 4.3 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-63308 | Helm Files.Lines Denial of Service via Empty Chart Files | MEDIUM | 4.3 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-58597 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-59995 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u | MEDIUM | 4.2 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-15157 | undici vulnerable to CRLF Injection via blob-like body 'type' property | MEDIUM | 4.2 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-59996 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee | MEDIUM | 4.2 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-59997 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important | MEDIUM | 4.2 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-50302 | Windows Cryptographic Services Security Feature Bypass Vulnerability | MEDIUM | 4.2 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55945 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | MEDIUM | 4.2 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-56850 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli | MEDIUM | 4.1 | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-64424 | netpoll: fix a use-after-free on shutdown path | MEDIUM | 4.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-13221 | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 6553 | MEDIUM | 4.0 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-15028 | Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header | LOW | 3.9 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-26080 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro | LOW | 3.7 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-41637 | Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries | LOW | 3.7 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-42955 | Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation re | LOW | 3.7 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-44687 | Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN | LOW | 3.7 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-46582 | A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path | LOW | 3.7 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-54478 | DNS Cookie bypass when combined with proxy-protocol use | LOW | 3.7 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-60000 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au | LOW | 3.7 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-62994 | CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin | LOW | 3.7 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-12547 | Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch | LOW | 3.4 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-41579 | runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations | LOW | 3.3 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-56847 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside | LOW | 3.3 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-58039 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr | LOW | 3.3 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64532 | fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} | LOW | 3.3 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-50416 | Win32k Information Disclosure Vulnerability | LOW | 3.3 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-50419 | Windows Kernel Information Disclosure Vulnerability | LOW | 3.3 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-54787 | sigstore-go fails to check signature timestamps against a signing key's validity period | LOW | 3.1 | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-55708 | Privacy/configuration issue when adding local data in views through 'unbound-control' | LOW | 3.1 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-16517 | Libarchive: libarchive: signed integer overflow in archive_write_zip_header | LOW | 2.9 | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-38752 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial | LOW | 2.9 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-64549 | Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() | LOW | 2.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64512 | ACPI: CPPC: Suppress UBSAN warning caused by field misuse | LOW | 1.9 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64546 | drm/edid: fix OOB read in drm_parse_tiled_block() | LOW | 1.9 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-13346 | pip absolute path traversal during download from malicious package indexes | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14461 | Out-of-bound read in mtr | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-15037 | XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-15788 | WCOW cache mount source selector resolves NTFS junctions outside of cache root | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-16554 | Integer Overflow Leading to Heap Buffer Overflow in cJSON | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-26197 | Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-26199 | Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-40467 | Use after free in gawk | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-40468 | Heap buffer overflow in gawk | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-40553 | Stack-based buffer overflow in gawk | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-42792 | epmd permanent DoS via EMFILE on accept(2) in erts | UNKNOWN | — | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-44943 | remote limited file-write as root via discovery in open-iscsi | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-44944 | iscsiuio control-socket authentication bypass in open-iscsi | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-50243 | 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-50252 | Possible cache poisoning attack by mapping source port population per thread | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-54886 | SSH SFTP server denial of service via extended channel data infinite loop | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-54908 | Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message | UNKNOWN | — | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-55737 | Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-55995 | Double-free in the iSNS attribute decoder in open-iscsi | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-56000 | xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-56288 | NULL Pointer Dereference in GNU patch | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-56289 | Loop with Unreachable Exit Condition in GNU patch | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-56389 | Arbitrary Command Execution in GNU Bison | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-56390 | Arbitrary Output Location Change in GNU Bison | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-56392 | Heap-based Buffer Overflow in GNU coreutils | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-57215 | RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom | UNKNOWN | — | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-58227 | TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-59248 | Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-59250 | Megaco flex scanner buffer overflow via oversized property parm name | UNKNOWN | — | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-59251 | Denial of service via exponential certificate policy tree growth in path validation | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-65624 | Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-6879 | Quadratic Behavior in xml.etree.ElementPath Index Predicates | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-9079 | stale proxy password leak | UNKNOWN | — | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-13028 | Chromium: CVE-2026-13028 Use after free in WebGL | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13030 | Chromium: CVE-2026-13030 Uninitialized Use in GPU | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13032 | Chromium: CVE-2026-13032 Use after free in WebGL | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13037 | Chromium: CVE-2026-13037 Use after free in WebView | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-13282 | Chromium: CVE-2026-13282 Use after free in AdFilter | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-13283 | Chromium: CVE-2026-13282: Use after free in Payments | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13774 | Chromium: CVE-2026-13774 Use after free in Extensions | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13775 | Chromium: CVE-2026-13775 Use after free in GPU | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13776 | Chromium: CVE-2026-13776 Type Confusion in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13777 | Chromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWeb | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13778 | Chromium: CVE-2026-13778 Use after free in WebUSB | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-13779 | Chromium: CVE-2026-13779 Use after free in Chromoting | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-13780 | Chromium: CVE-2026-13780 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13781 | Chromium: CVE-2026-13781 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13782 | Chromium: CVE-2026-13782 Use after free in Browser | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13783 | Chromium: CVE-2026-13783 Use after free in Views | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13784 | Chromium: CVE-2026-13784 Use after free in Views | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13785 | Chromium: CVE-2026-13785 Use after free in Bluetooth | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13786 | Chromium: CVE-2026-13786 Use after free in Ozone | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-13787 | Chromium: CVE-2026-13787 Use after free in Chromoting | UNKNOWN | — | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-13788 | Chromium: CVE-2026-13788 Use after free in Fullscreen | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-13790 | Chromium: CVE-2026-13790 Side-channel information leakage in Scroll | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13791 | Chromium: CVE-2026-13791 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13792 | Chromium: CVE-2026-13792 Use after free in Touchbar | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13793 | Chromium: CVE-2026-13793 Insufficient policy enforcement in SVG | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13794 | Chromium: CVE-2026-13794 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-13795 | Chromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13796 | Chromium: CVE-2026-13796 Integer overflow in Chromecast | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13797 | Chromium: CVE-2026-13797 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13798 | Chromium: CVE-2026-13798 Heap buffer overflow in Chromecast | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-13799 | Chromium: CVE-2026-13799 Use after free in QUIC | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13800 | Chromium: CVE-2026-13800 Inappropriate implementation in Updater | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-13801 | Chromium: CVE-2026-13801 Integer overflow in Chromecast | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13802 | Chromium: CVE-2026-13802 Use after free in Views | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-13803 | Chromium: CVE-2026-13803 Type Confusion in Chrome Tabs | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-13804 | Chromium: CVE-2026-13804 Use after free in Chromecast | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13805 | Chromium: CVE-2026-13805 Use after free in GFX | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13806 | Chromium: CVE-2026-13806 Insufficient validation of untrusted input in Accessibility | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-13807 | Chromium: CVE-2026-13807 Use after free in Import | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13808 | Chromium: CVE-2026-13808 Insufficient data validation in Chrome for iOS | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-13809 | Chromium: CVE-2026-13809 Side-channel information leakage in Safe Browsing | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13810 | Chromium: CVE-2026-13810 Inappropriate implementation in Input | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13811 | Chromium: CVE-2026-13811 Use after free in IME | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13812 | Chromium: CVE-2026-13812 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13813 | Chromium: CVE-2026-13813 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13814 | Chromium: CVE-2026-13814 Use after free in Views | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13815 | Chromium: CVE-2026-13815 Use after free in Blink | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-13816 | Chromium: CVE-2026-13816 Insufficient validation of untrusted input in File Input | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13817 | Chromium: CVE-2026-13817 Insufficient validation of untrusted input in Glic | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13818 | Chromium: CVE-2026-13818 Inappropriate implementation in Passwords | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13819 | Chromium: CVE-2026-13819 Out of bounds read in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-13820 | Chromium: CVE-2026-13820 Out of bounds read in Skia | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13821 | Chromium: CVE-2026-13821 Use after free in Canvas | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13822 | Chromium: CVE-2026-13822 Inappropriate implementation in Extensions | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-13823 | Chromium: CVE-2026-13823 Use after free in Glic | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13824 | Chromium: CVE-2026-13824 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13825 | Chromium: CVE-2026-13825 Uninitialized Use in Dawn | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13826 | Chromium: CVE-2026-13826 Inappropriate implementation in Autofill | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13827 | Chromium: CVE-2026-13827 Use after free in Updater | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-13828 | Chromium: CVE-2026-13828 Inappropriate implementation in Enterprise | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13829 | Chromium: CVE-2026-13829 Insufficient validation of untrusted input in Settings | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-13830 | Chromium: CVE-2026-13830 Use after free in Chromoting | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13831 | Chromium: CVE-2026-13831 Use after free in GPU | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13832 | Chromium: CVE-2026-13832 Use after free in Headless | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13833 | Chromium: CVE-2026-13833 Uninitialized Use in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13834 | Chromium: CVE-2026-13834 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-13835 | Chromium: CVE-2026-13835 Inappropriate implementation in XML | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13836 | Chromium: CVE-2026-13836 Inappropriate implementation in CSS | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13837 | Chromium: CVE-2026-13837 Inappropriate implementation in CSS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13838 | Chromium: CVE-2026-13838 Inappropriate implementation in CSS | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13839 | Chromium: CVE-2026-13839 Inappropriate implementation in CSS | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13840 | Chromium: CVE-2026-13840 Insufficient policy enforcement in Canvas | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13841 | Chromium: CVE-2026-13841 Integer overflow in Skia | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13842 | Chromium: CVE-2026-13842 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13843 | Chromium: CVE-2026-13843 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13844 | Chromium: CVE-2026-13844 Use after free in Updater | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-13845 | Chromium: CVE-2026-13845 Use after free in DOM | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13846 | Chromium: CVE-2026-13846 Use after free in USB | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13847 | Chromium: CVE-2026-13847 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13848 | Chromium: CVE-2026-13848 Use after free in Forms | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13849 | Chromium: CVE-2026-13849 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-13850 | Chromium: CVE-2026-13850 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13851 | Chromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13852 | Chromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13853 | Chromium: CVE-2026-13853 Use after free in Journeys | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13854 | Chromium: CVE-2026-13854 Use after free in Ozone | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13855 | Chromium: CVE-2026-13855 Use after free in Ozone | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13856 | Chromium: CVE-2026-13856 Insufficient validation of untrusted input in Speech | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13857 | Chromium: CVE-2026-13857 Inappropriate implementation in Geometry | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13858 | Chromium: CVE-2026-13858 Out of bounds read in FFmpeg | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13859 | Chromium: CVE-2026-13859 Inappropriate implementation in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13860 | Chromium: CVE-2026-13860 Incorrect security UI in Autofill | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13861 | Chromium: CVE-2026-13861 Use after free in Core | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13862 | CVE-2026-13862 | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-13863 | Chromium: CVE-2026-13863 Insufficient validation of untrusted input in CustomTabs | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-13864 | Chromium: CVE-2026-13864 Insufficient policy enforcement in WebHID | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13865 | Chromium: CVE-2026-13865 Insufficient validation of untrusted input in Enterprise | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13866 | Chromium: CVE-2026-13866 Insufficient validation of untrusted input in Input | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13867 | Chromium: CVE-2026-13867 Inappropriate implementation in Geolocation | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13868 | Chromium: CVE-2026-13868 Inappropriate implementation in Network | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13869 | Chromium: CVE-2026-13869 Use after free in Device | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13870 | Chromium: CVE-2026-13870 Use after free in WebView | UNKNOWN | — | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-13871 | Chromium: CVE-2026-13871 Insufficient data validation in GuestView | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13872 | Chromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13873 | Chromium: CVE-2026-13873 Out of bounds memory access in Layout | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13874 | Chromium: CVE-2026-13874 Inappropriate implementation in DataTransfer | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13875 | Chromium: CVE-2026-13875 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13876 | Chromium: CVE-2026-13876 Inappropriate implementation in Network | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13877 | Chromium: CVE-2026-13877 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13878 | Chromium: CVE-2026-13878 Use after free in Bluetooth | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13879 | Chromium: CVE-2026-13879 Use after free in Bluetooth | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-13880 | Chromium: CVE-2026-13880 Use after free in USB | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13881 | Chromium: CVE-2026-13881 Insufficient data validation in WebAppInstalls | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13882 | Chromium: CVE-2026-13882 Inappropriate implementation in USB | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13883 | Chromium: CVE-2026-13883 Type Confusion in ANGLE | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13884 | Chromium: CVE-2026-13884 Heap buffer overflow in Chromecast | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-13885 | Chromium: CVE-2026-13885 Use after free in Skia | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-13886 | Chromium: CVE-2026-13886 Policy bypass in Isolated Web Apps | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13887 | Chromium: CVE-2026-13887 Insufficient policy enforcement in NFC | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13888 | Chromium: CVE-2026-13888 Use after free in Extensions | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13889 | Chromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthentication | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13890 | Chromium: CVE-2026-13890 Out of bounds read in Chromecast | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13891 | Chromium: CVE-2026-13891 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13892 | Chromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13893 | Chromium: CVE-2026-13893 Insufficient validation of untrusted input in WebUI | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13894 | Chromium: CVE-2026-13894 Insufficient policy enforcement in Network | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13895 | Chromium: CVE-2026-13895 Inappropriate implementation in Autofill | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13896 | Chromium: CVE-2026-13896 Insufficient policy enforcement in Glic | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13897 | Chromium: CVE-2026-13897 Insufficient policy enforcement in Chromecast | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13898 | Chromium: CVE-2026-13898 Use after free in Cast Receiver | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-13899 | Chromium: CVE-2026-13899 Use after free in HTML | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-13900 | Chromium: CVE-2026-13900 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13901 | Chromium: CVE-2026-13901 Insufficient validation of untrusted input in Serial | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13902 | Chromium: CVE-2026-13902 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13903 | Chromium: CVE-2026-13903 Insufficient policy enforcement in Bluetooth | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13904 | Chromium: CVE-2026-13904 Incorrect security UI in Safe Browsing | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13905 | Chromium: CVE-2026-13905 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-13906 | Chromium: CVE-2026-13906 Out of bounds read in Codecs | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13907 | Chromium: CVE-2026-13907 Inappropriate implementation in iOSWeb | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13908 | Chromium: CVE-2026-13908 Insufficient validation of untrusted input in Omnibox | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13909 | Chromium: CVE-2026-13909 Insufficient policy enforcement in DevTools | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13910 | Chromium: CVE-2026-13910 Insufficient policy enforcement in WebXR | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13911 | Chromium: CVE-2026-13911 Insufficient data validation in Spellcheck | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13912 | Chromium: CVE-2026-13912 Incorrect security UI in Safe Browsing | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13913 | Chromium: CVE-2026-13913 Insufficient policy enforcement in Autofill | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13914 | Chromium: CVE-2026-13914 Inappropriate implementation in Passwords | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-13915 | Chromium: CVE-2026-13915 Use after free in Chrome for iOS | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13916 | Chromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13917 | Chromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13918 | Chromium: CVE-2026-13918 Use after free in Chrome for iOS | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13919 | Chromium: CVE-2026-13919 Insufficient data validation in Extensions | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13920 | Chromium: CVE-2026-13920 Insufficient validation of untrusted input in Media | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13921 | Chromium: CVE-2026-13921 Insufficient validation of untrusted input in DeviceBoundSessionCredentials | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13922 | Chromium: CVE-2026-13922 Side-channel information leakage in Paint | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13923 | Chromium: CVE-2026-13923 Uninitialized Use in GPU | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13924 | Chromium: CVE-2026-13924 Insufficient validation of untrusted input in WebView | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13925 | Chromium: CVE-2026-13925 Inappropriate implementation in Downloads | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-13926 | Chromium: CVE-2026-13926 Insufficient validation of untrusted input in Network | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13927 | Chromium: CVE-2026-13927 Insufficient validation of untrusted input in UI | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-13928 | Chromium: CVE-2026-13928 Insufficient validation of untrusted input in Enterprise | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13929 | Chromium: CVE-2026-13929 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-13930 | Chromium: CVE-2026-13930 Insufficient policy enforcement in Actor | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13931 | Chromium: CVE-2026-13931 Inappropriate implementation in Media | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13932 | Chromium: CVE-2026-13932 Inappropriate implementation in Sharing | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13933 | Chromium: CVE-2026-13933 Insufficient policy enforcement in Passwords | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13934 | Chromium: CVE-2026-13934 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13935 | Chromium: CVE-2026-13935 Side-channel information leakage in ComputePressure | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13936 | Chromium: CVE-2026-13936 Inappropriate implementation in Passwords | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13937 | Chromium: CVE-2026-13937 Insufficient policy enforcement in Passwords | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13938 | Chromium: CVE-2026-13938 Integer overflow in Fonts | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13939 | Chromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShare | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13940 | Chromium: CVE-2026-13940 Uninitialized Use in Cast | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-13941 | Chromium: CVE-2026-13941 Inappropriate implementation in SiteSettings | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13942 | Chromium: CVE-2026-13942 Insufficient validation of untrusted input in Video Capture | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-13943 | Chromium: CVE-2026-13943 Uninitialized Use in CSS | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13944 | Chromium: CVE-2026-13944 Inappropriate implementation in DataTransfer | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-13945 | Chromium: CVE-2026-13945 Insufficient policy enforcement in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13946 | Chromium: CVE-2026-13946 Inappropriate implementation in ScriptInjections | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13947 | Chromium: CVE-2026-13947 Uninitialized Use in XR | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13948 | Chromium: CVE-2026-13948 Insufficient policy enforcement in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13949 | Chromium: CVE-2026-13949 Insufficient policy enforcement in Payments | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13950 | Chromium: CVE-2026-13950 Uninitialized Use in GPU | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13951 | Chromium: CVE-2026-13951 Policy bypass in USB | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13952 | Chromium: CVE-2026-13952 Inappropriate implementation in PerformanceAPIs | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13953 | Chromium: CVE-2026-13953 Inappropriate implementation in SplitView | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13954 | Chromium: CVE-2026-13954 Insufficient policy enforcement in XML | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13955 | Chromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabs | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-13956 | Chromium: CVE-2026-13956 Incorrect security UI in PageInfo | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13957 | Chromium: CVE-2026-13957 Incorrect security UI in Extensions | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-13958 | Chromium: CVE-2026-13958 Uninitialized Use in Codecs | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13959 | Chromium: CVE-2026-13959 Insufficient validation of untrusted input in Blink | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-13960 | Chromium: CVE-2026-13960 Inappropriate implementation in Passwords | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13961 | Chromium: CVE-2026-13961 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13962 | Chromium: CVE-2026-13962 Insufficient data validation in PDF | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13963 | Chromium: CVE-2026-13963 Inappropriate implementation in DevTools | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-13964 | Chromium: CVE-2026-13964 Insufficient policy enforcement in WebView | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13965 | Chromium: CVE-2026-13965 Use after free in Oilpan | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-13966 | Chromium: CVE-2026-13966 Inappropriate implementation in History | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13967 | Chromium: CVE-2026-13967 Type Confusion in V8 | UNKNOWN | — | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-13968 | Chromium: CVE-2026-13968 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-13969 | Chromium: CVE-2026-13969 Uninitialized Use in UI | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13970 | Chromium: CVE-2026-13970 Uninitialized Use in Media | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13971 | Chromium: CVE-2026-13971 Uninitialized Use in Skia | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13972 | Chromium: CVE-2026-13972 Inappropriate implementation in Paint | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13973 | Chromium: CVE-2026-13973 Inappropriate implementation in UI | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13974 | Chromium: CVE-2026-13974 Integer overflow in Safe Browsing | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13975 | Chromium: CVE-2026-13975 Out of bounds read in ANGLE | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13976 | Chromium: CVE-2026-13976 Heap buffer overflow in Storage | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-13977 | Chromium: CVE-2026-13977 Inappropriate implementation in HTMLParser | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13978 | Chromium: CVE-2026-13978 Insufficient policy enforcement in PageInfo | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13979 | Chromium: CVE-2026-13979 Inappropriate implementation in Paint | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13980 | Chromium: CVE-2026-13980 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13981 | Chromium: CVE-2026-13981 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13982 | Chromium: CVE-2026-13982 Incorrect security UI in Passwords | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13983 | Chromium: CVE-2026-13983 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13984 | Chromium: CVE-2026-13984 Incorrect security UI in TabStrip | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13985 | Chromium: CVE-2026-13985 Inappropriate implementation in MediaCapture | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13986 | Chromium: CVE-2026-13986 Inappropriate implementation in Media UI | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13987 | Chromium: CVE-2026-13987 Incorrect security UI in Mobile | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13988 | Chromium: CVE-2026-13988 Inappropriate implementation in Paint | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13989 | Chromium: CVE-2026-13989 Insufficient policy enforcement in PageInfo | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13990 | Chromium: CVE-2026-13990 Insufficient validation of untrusted input in DataTransfer | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-13991 | Chromium: CVE-2026-13991 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13992 | Chromium: CVE-2026-13992 Inappropriate implementation in UI | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13993 | Chromium: CVE-2026-13993 Incorrect security UI in WebAppInstalls | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13994 | Chromium: CVE-2026-13994 Inappropriate implementation in Credential Management | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13995 | Chromium: CVE-2026-13995 Insufficient validation of untrusted input in Autofill | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13996 | Chromium: CVE-2026-13996 Incorrect security UI in Permissions | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13997 | Chromium: CVE-2026-13997 Incorrect security UI in Extensions | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13998 | Chromium: CVE-2026-13998 Incorrect security UI in File Input | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13999 | Chromium: CVE-2026-13999 Inappropriate implementation in Extensions | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14000 | Chromium: CVE-2026-14000 Inappropriate implementation in XML | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14001 | Chromium: CVE-2026-14001 Inappropriate implementation in Network | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14002 | Chromium: CVE-2026-14002 Inappropriate implementation in Geolocation | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14003 | Chromium: CVE-2026-14003 Insufficient policy enforcement in Extensions | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14004 | Chromium: CVE-2026-14004 Inappropriate implementation in CSS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14005 | Chromium: CVE-2026-14005 Use after free in Omnibox | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14006 | Chromium: CVE-2026-14006 Use after free in Navigation | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-14007 | Chromium: CVE-2026-14007 Insufficient policy enforcement in PermissionsPolicy | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14008 | Chromium: CVE-2026-14008 Uninitialized Use in WebXR | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14009 | Chromium: CVE-2026-14009 Insufficient data validation in Passwords | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14010 | Chromium: CVE-2026-14010 Uninitialized Use in Codecs | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14011 | Chromium: CVE-2026-14011 Out of bounds read in SurfaceCapture | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14012 | Chromium: CVE-2026-14012 Side-channel information leakage in CSS | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-14013 | Chromium: CVE-2026-14013 Inappropriate implementation in SVG | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14014 | Chromium: CVE-2026-14014 Inappropriate implementation in Paint | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14015 | Chromium: CVE-2026-14015 Inappropriate implementation in WebRTC | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14016 | Chromium: CVE-2026-14016 Insufficient policy enforcement in SVG | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14017 | Chromium: CVE-2026-14017 Inappropriate implementation in Navigation | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14018 | Chromium: CVE-2026-14018 Use after free in Updater | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14019 | Chromium: CVE-2026-14019 Inappropriate implementation in Passwords | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14020 | Chromium: CVE-2026-14020 Insufficient validation of untrusted input in WebXR | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14021 | Chromium: CVE-2026-14021 Insufficient validation of untrusted input in StorageAccessAPI | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14022 | Chromium: CVE-2026-14022 Insufficient validation of untrusted input in Network | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14023 | Chromium: CVE-2026-14023 Insufficient validation of untrusted input in SanitizerAPI | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14024 | Chromium: CVE-2026-14024 Use after free in Ozone | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14025 | Chromium: CVE-2026-14025 Use after free in Views | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14026 | Chromium: CVE-2026-14026 Incorrect security UI in SplitView | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14027 | Chromium: CVE-2026-14027 Use after free in SignIn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14028 | Chromium: CVE-2026-14028 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14030 | Chromium: CVE-2026-14030 Incorrect security UI in SplitView | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14031 | Chromium: CVE-2026-14031 Incorrect security UI in File Input | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14032 | Chromium: CVE-2026-14032 Use after free in Bluetooth | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14033 | Chromium: CVE-2026-14033 Insufficient policy enforcement in Media | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14034 | Chromium: CVE-2026-14034 Inappropriate implementation in WebXR | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-14035 | Chromium: CVE-2026-14035 Insufficient policy enforcement in Bluetooth | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14036 | Chromium: CVE-2026-14036 Insufficient policy enforcement in Bluetooth | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14037 | Chromium: CVE-2026-14037 Insufficient policy enforcement in GPU | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14038 | Chromium: CVE-2026-14038 Insufficient validation of untrusted input in New Tab Page | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14039 | Chromium: CVE-2026-14039 Insufficient policy enforcement in GetUserMedia | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14040 | Chromium: CVE-2026-14040 Use after free in BrowserTag | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14041 | Chromium: CVE-2026-14041 Insufficient policy enforcement in Serial | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14042 | Chromium: CVE-2026-14042 Inappropriate implementation in Isolated Web Apps | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14043 | Chromium: CVE-2026-14043 Use after free in GetUserMedia | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14044 | Chromium: CVE-2026-14044 Use after free in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14045 | Chromium: CVE-2026-14045 Insufficient validation of untrusted input in Network | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14046 | Chromium: CVE-2026-14046 Inappropriate implementation in CustomTabs | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14047 | Chromium: CVE-2026-14047 Insufficient policy enforcement in Extensions | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14048 | Chromium: CVE-2026-14048 Use after free in Chromecast | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-14049 | Chromium: CVE-2026-14049 Inappropriate implementation in GPU | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-14050 | Chromium: CVE-2026-14050 Insufficient policy enforcement in Passwords | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14051 | Chromium: CVE-2026-14051 Uninitialized Use in GamepadAPI | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14052 | Chromium: CVE-2026-14052 Insufficient policy enforcement in FileSystem | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14053 | Chromium: CVE-2026-14053 Insufficient policy enforcement in Extensions | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14054 | Chromium: CVE-2026-14054 Insufficient policy enforcement in Network | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14055 | Chromium: CVE-2026-14055 Insufficient validation of untrusted input in Device Trust | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14056 | Chromium: CVE-2026-14056 Insufficient validation of untrusted input in Media | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14057 | Chromium: CVE-2026-14057 Insufficient policy enforcement in FedCM | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14058 | Chromium: CVE-2026-14058 Policy bypass in Parser | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14059 | Chromium: CVE-2026-14059 Insufficient policy enforcement in Related-Website-Sets | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14060 | Chromium: CVE-2026-14060 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-14061 | Chromium: CVE-2026-14061 Inappropriate implementation in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14062 | Chromium: CVE-2026-14062 Inappropriate implementation in Views | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14063 | Chromium: CVE-2026-14063 Out of bounds memory access in Chromecast | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14064 | Chromium: CVE-2026-14064 Use after free in PageInfo | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-14065 | Chromium: CVE-2026-14065 Insufficient validation of untrusted input in PageInfo | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14066 | Chromium: CVE-2026-14066 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14067 | Chromium: CVE-2026-14067 Use after free in Chrome for iOS | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-14068 | Chromium: CVE-2026-14068 Inappropriate implementation in Omnibox | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14069 | Chromium: CVE-2026-14069 Integer overflow in WebNN | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14070 | Chromium: CVE-2026-14070 Uninitialized Use in WebNN | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14071 | Chromium: CVE-2026-14071 Side-channel information leakage in WebAudio | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14072 | Chromium: CVE-2026-14072 Incorrect security UI in SplitView | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14073 | Chromium: CVE-2026-14073 Insufficient policy enforcement in WebXR | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14074 | Chromium: CVE-2026-14074 Side-channel information leakage in WebAuthentication | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-14075 | Chromium: CVE-2026-14075 Policy bypass in Chrome for iOS | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14076 | Chromium: CVE-2026-14076 Policy bypass in Network | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14077 | Chromium: CVE-2026-14077 Incorrect security UI in Select | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14078 | Chromium: CVE-2026-14078 Policy bypass in WebRTC | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14079 | Chromium: CVE-2026-14079 Policy bypass in Network | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14080 | Chromium: CVE-2026-14080 Insufficient validation of untrusted input in TabSwitcher | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14081 | Chromium: CVE-2026-14081 Insufficient policy enforcement in DevTools | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14082 | Chromium: CVE-2026-14082 Race in Storage | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14083 | Chromium: CVE-2026-14083 Insufficient validation of untrusted input in HTML | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14084 | Chromium: CVE-2026-14084 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14085 | Chromium: CVE-2026-14085 Side-channel information leakage in CSS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14086 | Chromium: CVE-2026-14086 Insufficient policy enforcement in HID | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-14087 | Chromium: CVE-2026-14087 Insufficient validation of untrusted input in WebNN | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-14088 | Chromium: CVE-2026-14088 Uninitialized Use in Canvas | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14089 | Chromium: CVE-2026-14089 Insufficient validation of untrusted input in PopupBlocker | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14090 | Chromium: CVE-2026-14090 Out of bounds read in CameraCapture | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14091 | Chromium: CVE-2026-14091 Use after free in DevTools | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-14092 | Chromium: CVE-2026-14092 Insufficient policy enforcement in Privacy | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14093 | Chromium: CVE-2026-14093 Use after free in Cast | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14094 | Chromium: CVE-2026-14094 Use after free in Installer | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-14095 | Chromium: CVE-2026-14095 Insufficient validation of untrusted input in Browser | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14096 | Chromium: CVE-2026-14096 Object lifecycle issue in Input | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14097 | Chromium: CVE-2026-14097 Inappropriate implementation in WebAppInstalls | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14098 | Chromium: CVE-2026-14098 Inappropriate implementation in CSS | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14099 | Chromium: CVE-2026-14099 Use after free in Chrome for iOS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14100 | Chromium: CVE-2026-14100 Insufficient data validation in NetworkCache | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14101 | Chromium: CVE-2026-14101 Insufficient policy enforcement in Sandbox | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-14102 | Chromium: CVE-2026-14102 Use after free in Passwords | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14103 | Chromium: CVE-2026-14103 Use after free in SSL | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14104 | Chromium: CVE-2026-14104 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-14105 | Chromium: CVE-2026-14105 Insufficient policy enforcement in Speech | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14106 | Chromium: CVE-2026-14106 Insufficient validation of untrusted input in Text | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14107 | Chromium: CVE-2026-14107 Use after free in Scheduling | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-14108 | Chromium: CVE-2026-14108 Use after free in PDFium | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-14109 | Chromium: CVE-2026-14109 Insufficient policy enforcement in Mojo | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14110 | Chromium: CVE-2026-14110 Inappropriate implementation in DarkMode | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14111 | Chromium: CVE-2026-14111 Use after free in WebProtect | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-14112 | Chromium: CVE-2026-14112 Inappropriate implementation in Enterprise | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-14113 | Chromium: CVE-2026-14113 Use after free in Updater | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14114 | Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14115 | Chromium: CVE-2026-14115 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-14116 | Chromium: CVE-2026-14116 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14117 | Chromium: CVE-2026-14117 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14118 | Chromium: CVE-2026-14118 Insufficient data validation in DevTools | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-14119 | Chromium: CVE-2026-14119 Type Confusion in Bluetooth | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-14120 | Chromium: CVE-2026-14120 Inappropriate implementation in DevTools | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14121 | Chromium: CVE-2026-14121 Use after free in Chromoting | UNKNOWN | — | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-14122 | Chromium: CVE-2026-14122 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14123 | Chromium: CVE-2026-14123 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14124 | Chromium: CVE-2026-14124 Inappropriate implementation in CredentialProvider | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-14125 | Chromium: CVE-2026-14125 Uninitialized Use in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14126 | Chromium: CVE-2026-14126 Incorrect security UI in UI | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14127 | Chromium: CVE-2026-14127 Inappropriate implementation in Printing | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14128 | Chromium: CVE-2026-14128 Insufficient data validation in Chrome for iOS | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14129 | Chromium: CVE-2026-14129 Incorrect security UI in PreviewTab | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14130 | Chromium: CVE-2026-14130 Incorrect security UI in Omnibox | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14131 | Chromium: CVE-2026-14131 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14132 | Chromium: CVE-2026-14132 Inappropriate implementation in WebXR | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14133 | Chromium: CVE-2026-14133 Race in History Embeddings | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14134 | Chromium: CVE-2026-14134 Inappropriate implementation in Autofill | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14135 | Chromium: CVE-2026-14135 Insufficient validation of untrusted input in Network | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14136 | Chromium: CVE-2026-14136 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14137 | Chromium: CVE-2026-14137 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14138 | Chromium: CVE-2026-14138 Inappropriate implementation in WebAppInstalls | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14139 | Chromium: CVE-2026-14139 Inappropriate implementation in TabStrip | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14140 | Chromium: CVE-2026-14140 Insufficient validation of untrusted input in Input | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14141 | Chromium: CVE-2026-14141 Incorrect security UI in Document Picture-in-Picture | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14142 | Chromium: CVE-2026-14142 Inappropriate implementation in Extensions | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14143 | Chromium: CVE-2026-14143 Incorrect security UI in Passwords | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14144 | Chromium: CVE-2026-14144 Incorrect security UI in Views | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14145 | Chromium: CVE-2026-14145 Inappropriate implementation in CSS | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14146 | Chromium: CVE-2026-14146 Inappropriate implementation in CSS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14147 | Chromium: CVE-2026-14147 Inappropriate implementation in CSS | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14148 | Chromium: CVE-2026-14148 Type Confusion in CSS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14149 | Chromium: CVE-2026-14149 Use after free in Audio | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-14150 | Chromium: CVE-2026-14150 Insufficient validation of untrusted input in Speech | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14151 | Chromium: CVE-2026-14151 Inappropriate implementation in AI | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14152 | Chromium: CVE-2026-14152 Out of bounds write in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14153 | Chromium: CVE-2026-14153 Inappropriate implementation in Glic | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-14154 | Chromium: CVE-2026-14154 Inappropriate implementation in DevTools | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14155 | Chromium: CVE-2026-14155 Insufficient policy enforcement in StorageAccessAPI | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14156 | Chromium: CVE-2026-14156 Policy bypass in StorageAccessAPI | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14382 | Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14385 | Chromium: CVE-2026-14385 Heap buffer overflow in ANGLE | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-14386 | Chromium: CVE-2026-14386 Out of bounds read in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14388 | Chromium: CVE-2026-14388 Out of bounds read in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14390 | Chromium: CVE-2026-14390 Use after free in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14391 | Chromium: CVE-2026-14391 Integer overflow in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14392 | Chromium: CVE-2026-14392 Out of bounds write in Tint | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14393 | Chromium: CVE-2026-14393 Use after free in V8 | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-14394 | Chromium: CVE-2026-14394 Use after free in V8 | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14395 | Chromium: CVE-2026-14395 Out of bounds write in V8 | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-14396 | Chromium: CVE-2026-14396 Out of bounds read in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14397 | Chromium: CVE-2026-14397 Out of bounds write in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14398 | Chromium: CVE-2026-14398 Use after free in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14399 | Chromium: CVE-2026-14399 Uninitialized Use in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14400 | Chromium: CVE-2026-14400 Out of bounds write in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-14401 | Chromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14402 | Chromium: CVE-2026-14402 Uninitialized Use in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14403 | Chromium: CVE-2026-14403 Use after free in V8 | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-14404 | Chromium: CVE-2026-14404 Inappropriate implementation in PDFium | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-14405 | Chromium: CVE-2026-14405 Uninitialized Use in V8 | UNKNOWN | — | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-14406 | Chromium: CVE-2026-14406 Out of bounds read in V8 | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14407 | Chromium: CVE-2026-14407 Inappropriate implementation in V8 | UNKNOWN | — | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-14408 | Chromium: CVE-2026-14408 Uninitialized Use in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14409 | Chromium: CVE-2026-14409 Inappropriate implementation in V8 | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-14410 | Chromium: CVE-2026-14410 Inappropriate implementation in Skia | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14411 | Chromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14412 | Chromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14413 | Chromium: CVE-2026-14413 Uninitialized Use in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14414 | Chromium: CVE-2026-14414 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-14415 | Chromium: CVE-2026-14415 Inappropriate implementation in V8 | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14416 | Chromium: CVE-2026-14416 Out of bounds read in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14417 | Chromium: CVE-2026-14417 Use after free in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14418 | Chromium: CVE-2026-14418 Uninitialized Use in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14419 | Chromium: CVE-2026-14419 Use after free in Skia | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14420 | Chromium: CVE-2026-14420 Out of bounds read and write in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14421 | Chromium: CVE-2026-14421 Uninitialized Use in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14422 | Chromium: CVE-2026-14422 Out of bounds read and write in Tint | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-14423 | Chromium: CVE-2026-14423 Type Confusion in Tint | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-14424 | Chromium: CVE-2026-14424 Use after free in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14425 | Chromium: CVE-2026-14425 Use after free in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-14426 | Chromium: CVE-2026-14426 Use after free in V8 | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-14427 | Chromium: CVE-2026-14427 Heap buffer overflow in Skia | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14428 | Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14429 | Chromium: CVE-2026-14429 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14430 | Chromium: CVE-2026-14430 Integer overflow in V8 | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-14431 | Chromium: CVE-2026-14431 Type Confusion in V8 | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-14432 | Chromium: CVE-2026-14432 Use after free in V8 | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-15107 | Chromium: CVE-2026-15107 Use after free in IndexedDB | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-15108 | Chromium: CVE-2026-15108 Integer overflow in Extensions API | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-15109 | Chromium: CVE-2026-15109 Uninitialized Use in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15110 | Chromium: CVE-2026-15110 Use after free in Extensions | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-15111 | Chromium: CVE-2026-15111 Use after free in Views | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-15112 | Chromium: CVE-2026-15112 Use after free in Ozone | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15113 | Chromium: CVE-2026-15113 Use after free in Autofill | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15114 | Chromium: CVE-2026-15114 Out of bounds read and write in Codecs | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-15115 | Chromium: CVE-2026-15115 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-15116 | Chromium: CVE-2026-15116 Use after free in Actor | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-15117 | Chromium: CVE-2026-15117 Use after free in Payments | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-15118 | Chromium: CVE-2026-15118 Use after free in Input | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-15119 | Chromium: CVE-2026-15119 Inappropriate implementation in GetUserMedia | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-15120 | Chromium: CVE-2026-15120 Use after free in Core | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-15121 | Chromium: CVE-2026-15121 Use after free in WebRTC | UNKNOWN | — | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-15122 | Chromium: CVE-2026-15122 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-15123 | Chromium: CVE-2026-15123 Insufficient data validation in DOM | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15124 | Chromium: CVE-2026-15124 Insufficient policy enforcement in Passwords | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-15125 | Chromium: CVE-2026-15125 Inappropriate implementation in Forms | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-15126 | Chromium: CVE-2026-15126 Use after free in Forms | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-15127 | Chromium: CVE-2026-15127 Inappropriate implementation in WebGL | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-15128 | Chromium: CVE-2026-15128 Inappropriate implementation in Forms | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-15129 | Chromium: CVE-2026-15129 Use after free in Views | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15130 | Chromium: CVE-2026-15130 Insufficient policy enforcement in Navigation | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-15131 | Chromium: CVE-2026-15131 Insufficient data validation in Navigation | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-15132 | Chromium: CVE-2026-15132 Uninitialized Use in V8 | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-15133 | Chromium: CVE-2026-15133 Use after free in InterestGroups | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-15764 | Chromium: CVE-2026-15764 Use after free in Ozone | UNKNOWN | — | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-15765 | Chromium: CVE-2026-15765 Use after free in Ozone | UNKNOWN | — | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-15766 | Chromium: CVE-2026-15766 Uninitialized Use in Skia | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-15767 | Chromium: CVE-2026-15767 Heap buffer overflow in libyuv | UNKNOWN | — | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-15768 | Chromium: CVE-2026-15768 Insufficient policy enforcement in HTML-in-Canvas | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-15769 | Chromium: CVE-2026-15769 Insufficient validation of untrusted input in Linux Toolkit Theming | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-15770 | Chromium: CVE-2026-15770 Uninitialized Use in V8 | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-15771 | Chromium: CVE-2026-15771 Insufficient validation of untrusted input in Media | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-15772 | Chromium: CVE-2026-15772 Use after free in GPU | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-15773 | Chromium: CVE-2026-15773 Use after free in Core | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-15774 | Chromium: CVE-2026-15774 Use after free in Skia | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-15775 | Chromium: CVE-2026-15775 Insufficient policy enforcement in V8 | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-15776 | Chromium: CVE-2026-15776 Type Confusion in V8 | UNKNOWN | — | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-15777 | Chromium: CVE-2026-15777 Use after free in UI | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-15778 | Chromium: CVE-2026-15778 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-15899 | Chromium: CVE-2026-15899 Use after free in CameraCapture | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-15900 | Chromium: CVE-2026-15900 Use after free in GPU | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-15901 | Chromium: CVE-2026-15901 Use after free in Network | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-15902 | Chromium: CVE-2026-15902 Use after free in Cast | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15903 | Chromium: CVE-2026-15903 Out of bounds read and write in V8 | UNKNOWN | — | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-15904 | Chromium: CVE-2026-15904 Use after free in Ozone | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-15905 | Chromium: CVE-2026-15905 Use after free in Aura | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-16413 | Chromium: CVE-2026-16413 Out of bounds write in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-16414 | Chromium: CVE-2026-16414 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-16415 | Chromium: CVE-2026-16415 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-16416 | Chromium: CVE-2026-16416 Integer overflow in Chromecast | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-16417 | Chromium: CVE-2026-16417 Uninitialized Use in Skia | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-16418 | Chromium: CVE-2026-16418 Stack buffer overflow in V8 | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-16419 | Chromium: CVE-2026-16419 Out of bounds read and write in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-16420 | Chromium: CVE-2026-16420 Type Confusion in WebAudio | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-16421 | Chromium: CVE-2026-16421 Inappropriate implementation in WebAudio | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-16422 | Chromium: CVE-2026-16422 Insufficient validation of untrusted input in Certificate | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-16423 | Chromium: CVE-2026-16423 Use after free in UI | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-16424 | Chromium: CVE-2026-16424 Use after free in GPU | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-16804 | Chromium: CVE-2026-16804 Use after free in Input | UNKNOWN | — | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-16805 | Chromium: CVE-2026-16805 Use after free in Blink | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-16806 | Chromium: CVE-2026-16806 Use after free in WebMCP | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-16807 | Chromium: CVE-2026-16807 Out of bounds write in Codecs | UNKNOWN | — | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-17650 | Chromium: CVE-2026-17650 Use after free in Compositing | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17651 | Chromium: CVE-2026-17651 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-17652 | Chromium: CVE-2026-17652 Use after free in Views | UNKNOWN | — | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-17653 | Chromium: CVE-2026-17653 Use after free in Skia | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17654 | Chromium: CVE-2026-17654 Race in Updater | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17655 | Chromium: CVE-2026-17655 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-17656 | Chromium: CVE-2026-17656 Use after free in Ozone | UNKNOWN | — | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-17657 | Chromium: CVE-2026-17657 Use after free in Navigation | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-17658 | Chromium: CVE-2026-17658 Use after free in V8 | UNKNOWN | — | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-17659 | Chromium: CVE-2026-17659 Inappropriate implementation in SiteIsolation | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-17660 | Chromium: CVE-2026-17660 Insufficient validation of untrusted input in Network | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17661 | Chromium: CVE-2026-17661 Use after free in Loader | UNKNOWN | — | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-17662 | Chromium: CVE-2026-17662 Insufficient policy enforcement in Prefetch | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-17663 | Chromium: CVE-2026-17663 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17664 | Chromium: CVE-2026-17664 Insufficient validation of untrusted input in Loader | UNKNOWN | — | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-17665 | Chromium: CVE-2026-17665 Use after free in V8 | UNKNOWN | — | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-17666 | Chromium: CVE-2026-17666 Cryptographic Flaw in Enterprise | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-17667 | Chromium: CVE-2026-17667 Uninitialized Use in ANGLE | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17668 | Chromium: CVE-2026-17668 Uninitialized Use in ANGLE | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17669 | Chromium: CVE-2026-17669 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17670 | Chromium: CVE-2026-17670 Use after free in Views | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17671 | Chromium: CVE-2026-17671 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17672 | Chromium: CVE-2026-17672 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17673 | Chromium: CVE-2026-17673 Integer overflow in QUIC | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17674 | Chromium: CVE-2026-17674 Inappropriate implementation in HTML | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17675 | Chromium: CVE-2026-17675 Out of bounds write in ANGLE | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17676 | Chromium: CVE-2026-17676 Inappropriate implementation in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17677 | Chromium: CVE-2026-17677 Inappropriate implementation in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17678 | Chromium: CVE-2026-17678 Out of bounds read in ANGLE | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17679 | Chromium: CVE-2026-17679 Insufficient validation of untrusted input in Print Preview | UNKNOWN | — | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-17680 | Chromium: CVE-2026-17680 Heap buffer overflow in Color | UNKNOWN | — | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-17681 | Chromium: CVE-2026-17681 Insufficient validation of untrusted input in Web Authentication | UNKNOWN | — | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-17682 | Chromium: CVE-2026-17682 Integer overflow in ANGLE | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17683 | Chromium: CVE-2026-17683 Inappropriate implementation in ANGLE | UNKNOWN | — | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-17684 | Chromium: CVE-2026-17684 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17685 | Chromium: CVE-2026-17685 Use after free in Autofill | UNKNOWN | — | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-17686 | Chromium: CVE-2026-17686 Insufficient validation of untrusted input in Passwords | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17687 | Chromium: CVE-2026-17687 Type Confusion in ANGLE | UNKNOWN | — | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-17688 | Chromium: CVE-2026-17688 Use after free in Input | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17689 | Chromium: CVE-2026-17689 Uninitialized Use in ANGLE | UNKNOWN | — | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-17690 | Chromium: CVE-2026-17690 Insufficient validation of untrusted input in PDF | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-17691 | Chromium: CVE-2026-17691 Out of bounds write in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17692 | Chromium: CVE-2026-17692 Use after free in DataTransfer | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17693 | Chromium: CVE-2026-17693 Inappropriate implementation in FileSystem | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-17694 | Chromium: CVE-2026-17694 Use after free in DOM | UNKNOWN | — | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-17695 | Chromium: CVE-2026-17695 Inappropriate implementation in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17696 | Chromium: CVE-2026-17696 Side-channel information leakage in Media | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-17697 | Chromium: CVE-2026-17697 Type Confusion in ANGLE | UNKNOWN | — | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-17698 | Chromium: CVE-2026-17698 Insufficient validation of untrusted input in UI | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-17699 | Chromium: CVE-2026-17699 Use after free in Views | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-17700 | Chromium: CVE-2026-17700 Insufficient validation of untrusted input in Actor | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-17701 | Chromium: CVE-2026-17701 Out of bounds read in ANGLE | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17702 | Chromium: CVE-2026-17702 Inappropriate implementation in Skia | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-17703 | Chromium: CVE-2026-17703 Policy bypass in Chrome for iOS | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17704 | Chromium: CVE-2026-17704 Use after free in ANGLE | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17705 | Chromium: CVE-2026-17705 Integer overflow in libxml | UNKNOWN | — | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-17706 | Chromium: CVE-2026-17706 Insufficient validation of untrusted input in Media | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-17707 | Chromium: CVE-2026-17707 Uninitialized Use in Media | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17708 | Chromium: CVE-2026-17708 Use after free in Audio | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17709 | Chromium: CVE-2026-17709 Race in Downloads | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-17710 | Chromium: CVE-2026-17710 Inappropriate implementation in MHTML | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17711 | Chromium: CVE-2026-17711 Race in Downloads | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-17712 | Chromium: CVE-2026-17712 Race in Skia | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-17713 | Chromium: CVE-2026-17713 Insufficient validation of untrusted input in Accessibility | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17714 | Chromium: CVE-2026-17714 Uninitialized Use in ANGLE | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17715 | Chromium: CVE-2026-17715 Inappropriate implementation in Passwords | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-17716 | Chromium: CVE-2026-17716 Use after free in Updater | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17717 | Chromium: CVE-2026-17717 Integer overflow in ANGLE | UNKNOWN | — | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-17718 | Chromium: CVE-2026-17718 Use after free in ANGLE | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17719 | Chromium: CVE-2026-17719 Use after free in Input | UNKNOWN | — | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-17720 | Chromium: CVE-2026-17720 Insufficient policy enforcement in Passwords | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-17721 | Chromium: CVE-2026-17721 Out of bounds write in ANGLE | UNKNOWN | — | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-17722 | Chromium: CVE-2026-17722 Object lifecycle issue in WebView | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-17723 | Chromium: CVE-2026-17723 Use after free in Media | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17724 | Chromium: CVE-2026-17724 Race in Chrome for iOS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17725 | Chromium: CVE-2026-17725 Type Confusion in V8 | UNKNOWN | — | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-17726 | Chromium: CVE-2026-17726 Integer overflow in WebGL | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17727 | Chromium: CVE-2026-17727 Out of bounds write in WebGL | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17728 | Chromium: CVE-2026-17728 Inappropriate implementation in Extensions | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-17729 | Chromium: CVE-2026-17729 Use after free in V8 | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-17730 | Chromium: CVE-2026-17730 Side-channel information leakage in Autofill | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17731 | Chromium: CVE-2026-17731 Inappropriate implementation in Autofill | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17732 | Chromium: CVE-2026-17732 Inappropriate implementation in SVG | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-17733 | Chromium: CVE-2026-17733 Inappropriate implementation in QUIC | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17734 | Chromium: CVE-2026-17734 Inappropriate implementation in Autofill | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-17735 | Chromium: CVE-2026-17735 Insufficient validation of untrusted input in BFCache | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-17736 | Chromium: CVE-2026-17736 Insufficient validation of untrusted input in WebView | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17737 | Chromium: CVE-2026-17737 Use after free in Bluetooth | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17738 | Chromium: CVE-2026-17738 Insufficient validation of untrusted input in Payments | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17739 | Chromium: CVE-2026-17739 Insufficient policy enforcement in Extensions | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17740 | Chromium: CVE-2026-17740 Uninitialized Use in ANGLE | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17741 | Chromium: CVE-2026-17741 Insufficient validation of untrusted input in WebView | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17742 | Chromium: CVE-2026-17742 Insufficient policy enforcement in Payments | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17743 | Chromium: CVE-2026-17743 Insufficient policy enforcement in ControlledFrame | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17744 | Chromium: CVE-2026-17744 Inappropriate implementation in File Input | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17745 | Chromium: CVE-2026-17745 Out of bounds read in Skia | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17746 | Chromium: CVE-2026-17746 Use after free in GPU | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17747 | Chromium: CVE-2026-17747 Insufficient validation of untrusted input in Payments | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-17748 | Chromium: CVE-2026-17748 Inappropriate implementation in Extensions | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17749 | Chromium: CVE-2026-17749 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-17750 | Chromium: CVE-2026-17750 Use after free in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17751 | Chromium: CVE-2026-17751 Inappropriate implementation in AdFilter | UNKNOWN | — | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-17752 | Chromium: CVE-2026-17752 Use after free in Views | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17753 | Chromium: CVE-2026-17753 Inappropriate implementation in Autofill | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17754 | Chromium: CVE-2026-17754 Inappropriate implementation in Blink | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17755 | Chromium: CVE-2026-17755 Incorrect security UI in Extensions | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17756 | Chromium: CVE-2026-17756 Insufficient policy enforcement in Presentation | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-17757 | Chromium: CVE-2026-17757 Uninitialized Use in Skia | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17758 | Chromium: CVE-2026-17758 Heap buffer overflow in Dawn | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-17759 | Chromium: CVE-2026-17759 Uninitialized Use in Codecs | UNKNOWN | — | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-17760 | Chromium: CVE-2026-17760 Side-channel information leakage in NoStatePrefetch | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17761 | Chromium: CVE-2026-17761 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-17762 | Chromium: CVE-2026-17762 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17763 | Chromium: CVE-2026-17763 Inappropriate implementation in GPU | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17764 | Chromium: CVE-2026-17764 Inappropriate implementation in FedCM | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-17765 | Chromium: CVE-2026-17765 Inappropriate implementation in WebProtect | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17766 | Chromium: CVE-2026-17766 Insufficient validation of untrusted input in Clipboard | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-17767 | Chromium: CVE-2026-17767 Insufficient validation of untrusted input in WebView | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17768 | Chromium: CVE-2026-17768 Insufficient validation of untrusted input in WebSockets | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17769 | Chromium: CVE-2026-17769 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17770 | Chromium: CVE-2026-17770 Out of bounds read in Media | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17771 | Chromium: CVE-2026-17771 Uninitialized Use in Skia | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17772 | Chromium: CVE-2026-17772 Out of bounds read in WebGL | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17773 | Chromium: CVE-2026-17773 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17774 | Chromium: CVE-2026-17774 Insufficient validation of untrusted input in Variations | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17775 | Chromium: CVE-2026-17775 Inappropriate implementation in PresentationAPI | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17776 | Chromium: CVE-2026-17776 Policy bypass in Receiver | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17777 | Chromium: CVE-2026-17777 Inappropriate implementation in Autofill | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17778 | Chromium: CVE-2026-17778 Use after free in Extensions | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-17779 | Chromium: CVE-2026-17779 Inappropriate implementation in Site Isolation | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-17780 | Chromium: CVE-2026-17780 Inappropriate implementation in Isolated Web Apps | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-17781 | Chromium: CVE-2026-17781 Inappropriate implementation in Extensions | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17782 | Chromium: CVE-2026-17782 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-17783 | Chromium: CVE-2026-17783 Inappropriate implementation in Loader | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17784 | Chromium: CVE-2026-17784 Use after free in Audio | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17785 | Chromium: CVE-2026-17785 Uninitialized Use in ANGLE | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17786 | Chromium: CVE-2026-17786 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-17787 | Chromium: CVE-2026-17787 Inappropriate implementation in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17788 | Chromium: CVE-2026-17788 Inappropriate implementation in Blink | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17789 | Chromium: CVE-2026-17789 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17790 | Chromium: CVE-2026-17790 Uninitialized Use in ANGLE | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17791 | Chromium: CVE-2026-17791 Insufficient validation of untrusted input in Payments | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17792 | Chromium: CVE-2026-17792 Inappropriate implementation in Credential Management | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17793 | Chromium: CVE-2026-17793 Inappropriate implementation in Messages | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17794 | Chromium: CVE-2026-17794 Insufficient validation of untrusted input in Mobile | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-17795 | Chromium: CVE-2026-17795 Insufficient validation of untrusted input in GetUserMedia | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17796 | Chromium: CVE-2026-17796 Side-channel information leakage in WebXR | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-17797 | Chromium: CVE-2026-17797 Inappropriate implementation in CSS | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-17798 | Chromium: CVE-2026-17798 Inappropriate implementation in Cast | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17799 | Chromium: CVE-2026-17799 Insufficient validation of untrusted input in Safe Browsing | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17800 | Chromium: CVE-2026-17800 Side-channel information leakage in MediaRecording | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-17801 | Chromium: CVE-2026-17801 Out of bounds memory access in ANGLE | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17802 | Chromium: CVE-2026-17802 Side-channel information leakage in GPU | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17803 | Chromium: CVE-2026-17803 Insufficient validation of untrusted input in Save to Drive | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-17804 | Chromium: CVE-2026-17804 Use after free in Media | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17805 | Chromium: CVE-2026-17805 Insufficient policy enforcement in Glic | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17806 | Chromium: CVE-2026-17806 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17807 | Chromium: CVE-2026-17807 Use after free in V8 | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17808 | Chromium: CVE-2026-17808 Uninitialized Use in WebGL | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17809 | Chromium: CVE-2026-17809 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17810 | Chromium: CVE-2026-17810 Uninitialized Use in Dawn | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-17811 | Chromium: CVE-2026-17811 Use after free in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17812 | Chromium: CVE-2026-17812 Inappropriate implementation in DigitalCredentials | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17813 | Chromium: CVE-2026-17813 Insufficient policy enforcement in Chrome for iOS | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17814 | Chromium: CVE-2026-17814 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-17815 | Chromium: CVE-2026-17815 Insufficient policy enforcement in GuestView | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17816 | Chromium: CVE-2026-17816 Inappropriate implementation in Speech | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-17817 | Chromium: CVE-2026-17817 Inappropriate implementation in ReportingAndNEL | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17818 | Chromium: CVE-2026-17818 Inappropriate implementation in Network | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17819 | Chromium: CVE-2026-17819 Inappropriate implementation in WebAppInstalls | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17820 | Chromium: CVE-2026-17820 Insufficient policy enforcement in Autofill | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17821 | Chromium: CVE-2026-17821 Insufficient policy enforcement in Extensions | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-17822 | Chromium: CVE-2026-17822 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17823 | Chromium: CVE-2026-17823 Insufficient policy enforcement in WebXR | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17824 | Chromium: CVE-2026-17824 Insufficient policy enforcement in ServiceWorker | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-17825 | Chromium: CVE-2026-17825 Insufficient policy enforcement in Passwords | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17826 | Chromium: CVE-2026-17826 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-17827 | Chromium: CVE-2026-17827 Inappropriate implementation in CSS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17828 | Chromium: CVE-2026-17828 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17829 | Chromium: CVE-2026-17829 Insufficient policy enforcement in Passwords | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17830 | Chromium: CVE-2026-17830 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17831 | Chromium: CVE-2026-17831 Insufficient validation of untrusted input in Passwords | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17832 | Chromium: CVE-2026-17832 Use after free in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-17833 | Chromium: CVE-2026-17833 Inappropriate implementation in Passwords | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17834 | Chromium: CVE-2026-17834 Inappropriate implementation in Passwords | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-17835 | Chromium: CVE-2026-17835 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17836 | Chromium: CVE-2026-17836 Use after free in V8 | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-17837 | Chromium: CVE-2026-17837 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-17838 | Chromium: CVE-2026-17838 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17839 | Chromium: CVE-2026-17839 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17840 | Chromium: CVE-2026-17840 Incorrect security UI in Passwords | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-17841 | Chromium: CVE-2026-17841 Race in Chrome for iOS | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17842 | Chromium: CVE-2026-17842 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-17843 | Chromium: CVE-2026-17843 Inappropriate implementation in CSS | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17844 | Chromium: CVE-2026-17844 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-17845 | Chromium: CVE-2026-17845 Inappropriate implementation in CSS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-17846 | Chromium: CVE-2026-17846 Inappropriate implementation in Media | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-17847 | Chromium: CVE-2026-17847 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17848 | Chromium: CVE-2026-17848 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-17849 | Chromium: CVE-2026-17849 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17850 | Chromium: CVE-2026-17850 Inappropriate implementation in Permissions | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17851 | Chromium: CVE-2026-17851 Side-channel information leakage in Autofill | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17852 | Chromium: CVE-2026-17852 Inappropriate implementation in Media Router | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17853 | Chromium: CVE-2026-17853 Inappropriate implementation in DevTools | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17854 | Chromium: CVE-2026-17854 Insufficient policy enforcement in WebMCP | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17855 | Chromium: CVE-2026-17855 Race in DevTools | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17856 | Chromium: CVE-2026-17856 Inappropriate implementation in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17857 | Chromium: CVE-2026-17857 Inappropriate implementation in Network | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17858 | Chromium: CVE-2026-17858 Uninitialized Use in WebNN | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17859 | Chromium: CVE-2026-17859 Side-channel information leakage in Favicons | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17860 | Chromium: CVE-2026-17860 Insufficient validation of untrusted input in Mobile | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17861 | Chromium: CVE-2026-17861 Insufficient validation of untrusted input in Updater | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17862 | Chromium: CVE-2026-17862 Use after free in Tracing | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-17863 | Chromium: CVE-2026-17863 Inappropriate implementation in Browser | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17864 | Chromium: CVE-2026-17864 Inappropriate implementation in Updater | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17865 | Chromium: CVE-2026-17865 Inappropriate implementation in Crypto | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17866 | Chromium: CVE-2026-17866 Type Confusion in Tab | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17867 | Chromium: CVE-2026-17867 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-17868 | Chromium: CVE-2026-17868 Insufficient policy enforcement in USB | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17869 | Chromium: CVE-2026-17869 Out of bounds read in WebXR | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17870 | Chromium: CVE-2026-17870 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-17871 | Chromium: CVE-2026-17871 Inappropriate implementation in Passwords | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17872 | Chromium: CVE-2026-17872 Cryptographic Flaw in WebAppInstalls | UNKNOWN | — | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-17873 | Chromium: CVE-2026-17873 Insufficient policy enforcement in Chrome for iOS | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17874 | Chromium: CVE-2026-17874 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17875 | Chromium: CVE-2026-17875 Use after free in PDFium | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-17876 | Chromium: CVE-2026-17876 Inappropriate implementation in Payments | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17877 | Chromium: CVE-2026-17877 Inappropriate implementation in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17878 | Chromium: CVE-2026-17878 Inappropriate implementation in CSS | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17879 | Chromium: CVE-2026-17879 Inappropriate implementation in Autofill | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17880 | Chromium: CVE-2026-17880 Inappropriate implementation in Autofill | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17881 | Chromium: CVE-2026-17881 Use after free in WebXR | UNKNOWN | — | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-17882 | Chromium: CVE-2026-17882 Policy bypass in Extensions | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17883 | Chromium: CVE-2026-17883 Inappropriate implementation in Headless | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17884 | Chromium: CVE-2026-17884 Object lifecycle issue in WebRTC | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17885 | Chromium: CVE-2026-17885 Inappropriate implementation in Paint | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17886 | Chromium: CVE-2026-17886 Use after free in Enterprise | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17887 | Chromium: CVE-2026-17887 Use after free in TabStrip | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-17888 | Chromium: CVE-2026-17888 Insufficient validation of untrusted input in WebUI | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-17889 | Chromium: CVE-2026-17889 Uninitialized Use in WebXR | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17890 | Chromium: CVE-2026-17890 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17891 | Chromium: CVE-2026-17891 Use after free in ANGLE | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-17892 | Chromium: CVE-2026-17892 Inappropriate implementation in WebXR | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17893 | Chromium: CVE-2026-17893 Insufficient validation of untrusted input in Updater | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17894 | Chromium: CVE-2026-17894 Use after free in Views | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17895 | Chromium: CVE-2026-17895 Inappropriate implementation in DataTransfer | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17896 | Chromium: CVE-2026-17896 Use after free in DevTools | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-17897 | Chromium: CVE-2026-17897 Inappropriate implementation in ORB | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17898 | Chromium: CVE-2026-17898 Use after free in DevTools | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-17899 | Chromium: CVE-2026-17899 Insufficient policy enforcement in DevTools | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17900 | Chromium: CVE-2026-17900 Inappropriate implementation in Enterprise | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-17901 | Chromium: CVE-2026-17901 Inappropriate implementation in Sharing | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-17902 | Chromium: CVE-2026-17902 Inappropriate implementation in Editing | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17903 | Chromium: CVE-2026-17903 Insufficient policy enforcement in Chromecast | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-17904 | Chromium: CVE-2026-17904 Insufficient policy enforcement in NFC | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17905 | Chromium: CVE-2026-17905 Inappropriate implementation in SurfaceCapture | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17906 | Chromium: CVE-2026-17906 Insufficient validation of untrusted input in Bluetooth | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-17907 | Chromium: CVE-2026-17907 Side-channel information leakage in Network | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17908 | Chromium: CVE-2026-17908 Insufficient validation of untrusted input in Printing | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-17909 | Chromium: CVE-2026-17909 Insufficient validation of untrusted input in Isolated Web Apps | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17910 | Chromium: CVE-2026-17910 Insufficient policy enforcement in NFC | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17911 | Chromium: CVE-2026-17911 Insufficient policy enforcement in SVG | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17912 | Chromium: CVE-2026-17912 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17913 | Chromium: CVE-2026-17913 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-17914 | Chromium: CVE-2026-17914 Side-channel information leakage in Skia | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17915 | Chromium: CVE-2026-17915 Inappropriate implementation in WebView | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-17916 | Chromium: CVE-2026-17916 Insufficient policy enforcement in Settings | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17917 | Chromium: CVE-2026-17917 Policy bypass in Chrome for iOS | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17918 | Chromium: CVE-2026-17918 Use after free in Sync | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-17919 | Chromium: CVE-2026-17919 Insufficient policy enforcement in Enterprise | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-17920 | Chromium: CVE-2026-17920 Use after free in V8 | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17921 | Chromium: CVE-2026-17921 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17922 | Chromium: CVE-2026-17922 Inappropriate implementation in Enterprise | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-17923 | Chromium: CVE-2026-17923 Policy bypass in Enterprise | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-17924 | Chromium: CVE-2026-17924 Use after free in DNS | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17925 | Chromium: CVE-2026-17925 Inappropriate implementation in Cast | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-17926 | Chromium: CVE-2026-17926 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17927 | Chromium: CVE-2026-17927 Insufficient policy enforcement in DevTools | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-17928 | Chromium: CVE-2026-17928 Inappropriate implementation in DataTransfer | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-17929 | Chromium: CVE-2026-17929 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-17930 | Chromium: CVE-2026-17930 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17931 | Chromium: CVE-2026-17931 Inappropriate implementation in DevTools | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17932 | Chromium: CVE-2026-17932 Use after free in DataTransfer | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17933 | Chromium: CVE-2026-17933 Inappropriate implementation in DOMStorage | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17934 | Chromium: CVE-2026-17934 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-17935 | Chromium: CVE-2026-17935 Heap buffer overflow in Codecs | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-17936 | Chromium: CVE-2026-17936 Inappropriate implementation in DevTools | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-17937 | Chromium: CVE-2026-17937 Inappropriate implementation in DevTools | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-17938 | Chromium: CVE-2026-17938 Inappropriate implementation in FullScreen | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17939 | Chromium: CVE-2026-17939 Inappropriate implementation in Passwords | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17940 | Chromium: CVE-2026-17940 Insufficient validation of untrusted input in Picture-in-Picture | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17941 | Chromium: CVE-2026-17941 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17942 | Chromium: CVE-2026-17942 Side-channel information leakage in SVG | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-17943 | Chromium: CVE-2026-17943 Inappropriate implementation in Parser | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-17944 | Chromium: CVE-2026-17944 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17945 | Chromium: CVE-2026-17945 Inappropriate implementation in Navigation | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17946 | Chromium: CVE-2026-17946 Uninitialized Use in Dawn | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-17947 | Chromium: CVE-2026-17947 Use after free in WebSockets | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17948 | Chromium: CVE-2026-17948 Type Confusion in V8 | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-17949 | Chromium: CVE-2026-17949 Uninitialized Use in GPU | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17950 | Chromium: CVE-2026-17950 Policy bypass in Safebrowsing | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-17951 | Chromium: CVE-2026-17951 Heap buffer overflow in WebRTC | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-17952 | Chromium: CVE-2026-17952 Inappropriate implementation in V8 | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17953 | Chromium: CVE-2026-17953 Insufficient policy enforcement in WebView | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17954 | Chromium: CVE-2026-17954 Policy bypass in MHTML | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-17955 | Chromium: CVE-2026-17955 Insufficient validation of untrusted input in Payments | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17956 | Chromium: CVE-2026-17956 Inappropriate implementation in Scheduling | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-17957 | Chromium: CVE-2026-17957 Inappropriate implementation in CORS | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-17958 | Chromium: CVE-2026-17958 Inappropriate implementation in Views | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17959 | Chromium: CVE-2026-17959 Inappropriate implementation in Network | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17960 | Chromium: CVE-2026-17960 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-17961 | Chromium: CVE-2026-17961 Inappropriate implementation in Session | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17962 | Chromium: CVE-2026-17962 Inappropriate implementation in Blink | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17963 | Chromium: CVE-2026-17963 Inappropriate implementation in SVG | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17964 | Chromium: CVE-2026-17964 Incorrect security UI in UI | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17965 | Chromium: CVE-2026-17965 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17966 | Chromium: CVE-2026-17966 Inappropriate implementation in Views | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17967 | Chromium: CVE-2026-17967 Use after free in Chrome for iOS | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-17968 | Chromium: CVE-2026-17968 Uninitialized Use in WebXR | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-17969 | Chromium: CVE-2026-17969 Inappropriate implementation in Passwords | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-17970 | Chromium: CVE-2026-17970 Insufficient validation of untrusted input in Passwords | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-17971 | Chromium: CVE-2026-17971 Inappropriate implementation in Frame | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-17972 | Chromium: CVE-2026-17972 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17973 | Chromium: CVE-2026-17973 Inappropriate implementation in Views | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17974 | Chromium: CVE-2026-17974 Insufficient policy enforcement in DevTools | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17975 | Chromium: CVE-2026-17975 Inappropriate implementation in IME | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17976 | Chromium: CVE-2026-17976 Policy bypass in Extensions | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-17977 | Chromium: CVE-2026-17977 Policy bypass in CSS | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-17978 | Chromium: CVE-2026-17978 Side-channel information leakage in WebCodecs | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17979 | Chromium: CVE-2026-17979 Race in V8 | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-17980 | Chromium: CVE-2026-17980 Inappropriate implementation in UI | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-17981 | Chromium: CVE-2026-17981 Inappropriate implementation in Blink | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-17982 | Chromium: CVE-2026-17982 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-17983 | Chromium: CVE-2026-17983 Incorrect security UI in Global Media Controls | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-17984 | Chromium: CVE-2026-17984 Inappropriate implementation in Browser | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-17985 | Chromium: CVE-2026-17985 Insufficient policy enforcement in Speech | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17986 | Chromium: CVE-2026-17986 Insufficient policy enforcement in Bluetooth | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-17987 | Chromium: CVE-2026-17987 Insufficient validation of untrusted input in Notifications | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-17988 | Chromium: CVE-2026-17988 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-17989 | Chromium: CVE-2026-17989 Type Confusion in V8 | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-17990 | Chromium: CVE-2026-17990 Insufficient validation of untrusted input in WebAuthn | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-17991 | Chromium: CVE-2026-17991 Insufficient validation of untrusted input in AI | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-17992 | Chromium: CVE-2026-17992 Uninitialized Use in Skia | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-17993 | Chromium: CVE-2026-17993 Race in Updater | UNKNOWN | — | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-17994 | Chromium: CVE-2026-17994 Inappropriate implementation in Media | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-17995 | Chromium: CVE-2026-17995 Out of bounds read in Dawn | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-17996 | Chromium: CVE-2026-17996 Inappropriate implementation in Browser | UNKNOWN | — | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-17997 | Chromium: CVE-2026-17997 Inappropriate implementation in Passwords | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-17998 | Chromium: CVE-2026-17998 Incorrect security UI in Extensions | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-17999 | Chromium: CVE-2026-17999 Incorrect security UI in PictureInPicture | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-18000 | Chromium: CVE-2026-18000 Insufficient policy enforcement in USB | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-18001 | Chromium: CVE-2026-18001 Inappropriate implementation in WebGL | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-18002 | Chromium: CVE-2026-18002 Insufficient validation of untrusted input in Google Lens | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-18003 | Chromium: CVE-2026-18003 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-18004 | Chromium: CVE-2026-18004 Insufficient policy enforcement in Speech | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-18005 | Chromium: CVE-2026-18005 Inappropriate implementation in WebXR | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-18006 | Chromium: CVE-2026-18006 Inappropriate implementation in Google Lens | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-18007 | Chromium: CVE-2026-18007 Inappropriate implementation in Input | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-18008 | Chromium: CVE-2026-18008 Inappropriate implementation in Settings | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-18009 | Chromium: CVE-2026-18009 Insufficient validation of untrusted input in Passwords | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-18010 | Chromium: CVE-2026-18010 Inappropriate implementation in Passwords | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-18011 | Chromium: CVE-2026-18011 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-18012 | Chromium: CVE-2026-18012 Use after free in PDFium | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-18013 | Chromium: CVE-2026-18013 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-18014 | Chromium: CVE-2026-18014 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-18015 | Chromium: CVE-2026-18015 Inappropriate implementation in Tint | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-18016 | Chromium: CVE-2026-18016 Insufficient policy enforcement in Chrome for iOS | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-18017 | Chromium: CVE-2026-18017 Use after free in Dawn | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-18018 | Chromium: CVE-2026-18018 Inappropriate implementation in Updater | UNKNOWN | — | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-18019 | Chromium: CVE-2026-18019 Side-channel information leakage in Media | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-48561 | Microsoft Edge Copilot Remote Code Execution Vulnerability | UNKNOWN | — | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-56160 | Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability | UNKNOWN | — | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-58643 | Windows Admin Center Spoofing Vulnerability | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-45480 | Azure Active Directory Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 58%ile | Microsoft | 2026-06-09 |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-47647 | Dynamics 365 Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-48584 | Microsoft Azure Synapse Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 58%ile | Microsoft | 2026-06-09 |
| CVE-2026-52919 | batman-adv: fix tp_meter counter underflow during shutdown | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52922 | batman-adv: dat: handle forward allocation error | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-52931 | batman-adv: tp_meter: avoid use of uninit sender vars | CRITICAL | 9.8 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-52934 | batman-adv: tvlv: reject oversized TVLV packets | CRITICAL | 9.8 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-52947 | net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52989 | nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers | CRITICAL | 9.8 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-52991 | sched/psi: fix race between file release and pressure write | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52993 | tipc: fix double-free in tipc_buf_append() | CRITICAL | 9.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-53000 | netfilter: nat: use kfree_rcu to release ops | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53002 | netfilter: conntrack: remove sprintf usage | CRITICAL | 9.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-53009 | ice: fix double-free of tx_buf skb | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53010 | ksmbd: fix use-after-free in smb2_open during durable reconnect | CRITICAL | 9.8 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-53017 | f2fs: fix data loss caused by incorrect use of nat_entry flag | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53018 | f2fs: avoid reading already updated pages during GC | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53025 | greybus: raw: fix use-after-free on cdev close | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53036 | bpf, arm64: Fix off-by-one in check_imm signed range check | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53053 | iommu/amd: Fix clone_alias() to use the original device's devid | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53062 | dm cache policy smq: fix missing locks in invalidating cache blocks | CRITICAL | 9.8 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53075 | ppp: require CAP_NET_ADMIN in target netns for unattached ioctls | CRITICAL | 9.8 | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-53077 | net/rds: Restrict use of RDS/IB to the initial network namespace | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53086 | net: bcmgenet: fix racing timeout handler | CRITICAL | 9.8 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-54906 | concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption | CRITICAL | 9.8 | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability | CRITICAL | 9.8 | 79%ile | Microsoft | 2026-06-09 |
| CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability | CRITICAL | 9.8 | 64%ile | Microsoft | 2026-06-09 |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability | CRITICAL | 9.8 | 97%ile | Microsoft | 2026-06-09 |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98%ile | Microsoft | 2026-06-09 |
| CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability | CRITICAL | 9.8 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-54130 | M365 Copilot Information Disclosure Vulnerability | CRITICAL | 9.8 | 64%ile | Microsoft | 2026-06-09 |
| CVE-2026-53043 | ocfs2/dlm: validate qr_numregions in dlm_match_regions() | CRITICAL | 9.8 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-53049 | gfs2: add some missing log locking | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-53045 | memory: tegra124-emc: Fix dll_change check | CRITICAL | 9.8 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-52913 | batman-adv: v: stop OGMv2 on disabled interface | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53052 | ASoC: qcom: qdsp6: topology: check widget type before accessing data | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53130 | fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52944 | ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53309 | ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison | CRITICAL | 9.8 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-7531 | Use-after-free in PQC hybrid key-share handling | CRITICAL | 9.8 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-48582 | Microsoft Exchange Online Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 51%ile | Microsoft | 2026-06-09 |
| CVE-2026-44631 | Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow | CRITICAL | 9.4 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2025-10263 | ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] | CRITICAL | 9.3 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-47646 | Dynamics 365 Customer Voice Spoofing Vulnerability | CRITICAL | 9.3 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-12087 | Socket versions before 2.041 for Perl have an out-of-bounds heap read | CRITICAL | 9.1 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-53176 | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN | CRITICAL | 9.1 | 53%ile | Microsoft | 2026-06-09 |
| CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability | CRITICAL | 9.1 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-48579 | Microsoft Exchange Online Information Disclosure Vulnerability | CRITICAL | 9.1 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-34182 | CMS AuthEnvelopedData Processing May Accept Forged Messages | CRITICAL | 9.1 | 48%ile | Microsoft | 2026-06-09 |
| CVE-2026-6094 | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData | CRITICAL | 9.1 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-45447 | Heap Use-After-Free in the PKCS7_verify() Function | HIGH | 8.8 | 89%ile | Microsoft | 2026-06-09 |
| CVE-2026-48715 | radvdump's Route Information Option Parser has a Stack Buffer Overflow | HIGH | 8.8 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-56115 | Bootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass | HIGH | 8.8 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-6893 | Dracut: dracut: root code execution via dhcp options command injection | HIGH | 8.8 | 69%ile | Microsoft | 2026-06-09 |
| CVE-2026-9698 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer | HIGH | 8.8 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-32208 | Microsoft Entra ID Spoofing Vulnerability | HIGH | 8.8 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability | HIGH | 8.8 | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 68%ile | Microsoft | 2026-06-09 |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 98%ile | Microsoft | 2026-06-09 |
| CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-06-09 |
| CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.8 | 65%ile | Microsoft | 2026-06-09 |
| CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 60%ile | Microsoft | 2026-06-09 |
| CVE-2026-47645 | Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-10879 | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders | HIGH | 8.6 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-29167 | Apache HTTP Server: mod_ldap per-dir use-after-free | HIGH | 8.6 | 51%ile | Microsoft | 2026-06-09 |
| CVE-2026-13325 | Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated vi | HIGH | 8.5 | — | Microsoft | 2026-06-09 |
| CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability | HIGH | 8.4 | 56%ile | Microsoft | 2026-06-09 |
| CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | HIGH | 8.4 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability | HIGH | 8.4 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability | HIGH | 8.4 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability | HIGH | 8.4 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.4 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.4 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability | HIGH | 8.4 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-52911 | ksmbd: scope conn->binding slowpath to bound sessions only | HIGH | 8.4 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-50521 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-49759 | Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash | HIGH | 8.2 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-57235 | Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` | HIGH | 8.2 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-57236 | Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception | HIGH | 8.2 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability | HIGH | 8.2 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability | HIGH | 8.2 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.2 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-42055 | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability | HIGH | 8.1 | 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-46331 | net/sched: fix pedit partial COW leading to page cache corruption | HIGH | 8.1 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-55200 | libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c | HIGH | 8.1 | 90%ile | Microsoft | 2026-06-09 |
| CVE-2026-7383 | Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion | HIGH | 8.1 | 55%ile | Microsoft | 2026-06-09 |
| CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability | HIGH | 8.1 | 68%ile | Microsoft | 2026-06-09 |
| CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability | HIGH | 8.1 | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability | HIGH | 8.1 | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution | HIGH | 8.1 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability | HIGH | 8.1 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability | HIGH | 8.1 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability | HIGH | 8.1 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.1 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-56123 | socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser | HIGH | 8.1 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-11816 | Path Traversal in keras-team/keras | HIGH | 8.1 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability | HIGH | 8.0 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.0 | 50%ile | Microsoft | 2026-06-09 |
| CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11332 | Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution | HIGH | 7.8 | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11822 | SQLite before 3.53.2 Memory Corruption in FTS5 Extension | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11824 | SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-12505 | Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-43958 | Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service | HIGH | 7.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-46243 | smb: client: reject userspace cifs.spnego descriptions | HIGH | 7.8 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-46274 | io-wq: check that the predecessor is hashed in io_wq_remove_pending() | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-46324 | netfilter: nf_tables: use list_del_rcu for netlink hooks | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-50256 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfo | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-50258 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shif | HIGH | 7.8 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-50259 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths in | HIGH | 7.8 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-50261 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-52908 | RDMA: During rereg_mr ensure that REREG_ACCESS is compatible | HIGH | 7.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52909 | ip6_vti: set netns_immutable on the fallback device. | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52910 | bpf: Free reuseport cBPF prog after RCU grace period. | HIGH | 7.8 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-52912 | netfilter: nf_queue: hold bridge skb->dev while queued | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-52923 | ipc: limit next_id allocation to the valid ID range | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-52926 | batman-adv: clear current gateway during teardown | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52943 | net: skbuff: fix missing zerocopy reference in pskb_carve helpers | HIGH | 7.8 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-52972 | crypto: af_alg - Cap AEAD AD length to 0x80000000 | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53005 | af_unix: Drop all SCM attributes for SOCKMAP. | HIGH | 7.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53068 | drm/komeda: fix integer overflow in AFBC framebuffer size check | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53097 | wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() | HIGH | 7.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53143 | drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-53198 | ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL | HIGH | 7.8 | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-53246 | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing | HIGH | 7.8 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-53262 | l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-55693 | Vim: Out-of-bounds Write in Spell File Word Count | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-55895 | Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-57455 | Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57456 | Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 80%ile | Microsoft | 2026-06-09 |
| CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 80%ile | Microsoft | 2026-06-09 |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability | HIGH | 7.8 | 82%ile | Microsoft | 2026-06-09 |
| CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability | HIGH | 7.8 | 89%ile | Microsoft | 2026-06-09 |
| CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-50511 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-50512 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-50656 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 96%ile | Microsoft | 2026-06-09 |
| CVE-2026-8863 | UEFI Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46301 | spi: topcliff-pch: fix use-after-free on unbind | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53159 | misc: fastrpc: fix DMA address corruption due to find_vma misuse | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-53194 | USB: serial: kl5kusb105: fix bulk-out buffer overflow | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53039 | ocfs2: validate group add input before caching | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53247 | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown | HIGH | 7.8 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-53196 | USB: serial: io_ti: fix heap overflow in get_manuf_info() | HIGH | 7.8 | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-53215 | net: mvpp2: refill RX buffers before XDP or skb use | HIGH | 7.8 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-53160 | misc: fastrpc: fix use-after-free race in fastrpc_map_create | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-52935 | xfrm: espintcp: do not reuse an in-progress partial send | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-32174 | Azure Bot Service Elevation of Privilege Vulnerability | HIGH | 7.7 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-45497 | Microsoft M365 Copilot Remote Code Execution Vulnerability | HIGH | 7.7 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-11625 | Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes | HIGH | 7.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-14164 | Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack() | HIGH | 7.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-27145 | Inefficient candidate hostname parsing in crypto/x509 | HIGH | 7.5 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-34180 | Heap Buffer Over-read in ASN.1 Content Parsing | HIGH | 7.5 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-34183 | Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler | HIGH | 7.5 | 63%ile | Microsoft | 2026-06-09 |
| CVE-2026-34355 | Apache HTTP Server: mod_proxy_html buffer overflow | HIGH | 7.5 | 66%ile | Microsoft | 2026-06-09 |
| CVE-2026-34356 | Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow | HIGH | 7.5 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-42504 | Quadratic complexity in WordDecoder.DecodeHeader in mime | HIGH | 7.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-42535 | Apache HTTP Server: mod_dav_fs protected directory access | HIGH | 7.5 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-42536 | Apache HTTP Server: mod_xml2enc heap overflow | HIGH | 7.5 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-45445 | AES-OCB IV Ignored on EVP_Cipher() Path | HIGH | 7.5 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | 98%ile | Microsoft | 2026-06-09 |
| CVE-2026-50031 | ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Manag | HIGH | 7.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-52955 | libceph: Fix potential out-of-bounds access in crush_decode() | HIGH | 7.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-52956 | libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() | HIGH | 7.5 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-52957 | libceph: Fix potential null-ptr-deref in decode_choose_args() | HIGH | 7.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-52986 | netfilter: nf_conntrack_sip: don't use simple_strtoul | HIGH | 7.5 | 48%ile | Microsoft | 2026-06-09 |
| CVE-2026-53284 | btrfs: only release the dirty pages io tree after successful writes | HIGH | 7.5 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-55203 | HAProxy - Integer Overflow in FCGI Demux Record Length Field | HIGH | 7.5 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-55204 | HAProxy - NULL Pointer Dereference in hpack_dht_insert Function | HIGH | 7.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-57434 | Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes | HIGH | 7.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-57435 | Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=` | HIGH | 7.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-57585 | MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error | HIGH | 7.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-58016 | Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" | HIGH | 7.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-8829 | HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities | HIGH | 7.5 | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-9076 | Out-of-Bounds Read in CMS Password-Based Decryption | HIGH | 7.5 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-9675 | undici WebSocket client vulnerable to denial of service via cumulative fragment bypass | HIGH | 7.5 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability | HIGH | 7.5 | 50%ile | Microsoft | 2026-06-09 |
| CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2026-06-09 |
| CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH | 7.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 84%ile | Microsoft | 2026-06-09 |
| CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2026-06-09 |
| CVE-2026-47633 | Microsoft Cost Management Information Disclosure Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 99%ile | Microsoft | 2026-06-09 |
| CVE-2026-42765 | NULL Dereference in Certificate Verification with OCSP Checking | HIGH | 7.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-46669 | `openvm-pairing` pairing check missing proper subfield check on scaling factor | HIGH | 7.5 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-42764 | NULL Pointer Dereference in QUIC Server Initial Packet Handling | HIGH | 7.5 | 66%ile | Microsoft | 2026-06-09 |
| CVE-2026-48779 | ws: Memory exhaustion DoS from tiny fragments and data chunks | HIGH | 7.5 | 55%ile | Microsoft | 2026-06-09 |
| CVE-2026-7532 | iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined | HIGH | 7.5 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-55960 | Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation | HIGH | 7.5 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-55961 | wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer | HIGH | 7.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-6331 | HMAC zero-length tag forgery in EVP_DigestVerifyFinal | HIGH | 7.5 | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-6731 | X.509 name constraint bypass via Subject CN treated as a DNS name | HIGH | 7.5 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-55958 | Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage | HIGH | 7.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-6325 | Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list | HIGH | 7.5 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-10512 | X25519 x86_64 assembly final reduction leaves non-canonical field element | HIGH | 7.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-8720 | HMAC-BLAKE2 final discards message when key length exceeds block size | HIGH | 7.5 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-10097 | ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery | HIGH | 7.5 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11310 | X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring | HIGH | 7.5 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-37460 | Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all | HIGH | 7.5 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-12143 | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection) | HIGH | 7.5 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-57231 | Podman: Malformed Image can trick podman run into leaking host environment variables into the container | HIGH | 7.5 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11703 | Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption | HIGH | 7.5 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-55967 | AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse | HIGH | 7.5 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11999 | X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert() | HIGH | 7.5 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-7511 | PKCS7_verify signer confusion allows forged signatures to be accepted | HIGH | 7.5 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-12340 | Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation | HIGH | 7.5 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-3195 | Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730) | HIGH | 7.4 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-50292 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properti | HIGH | 7.4 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-9697 | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | HIGH | 7.4 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-34181 | PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys | HIGH | 7.4 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11463 | USCiLab Cereal Shared Pointer type confusion | HIGH | 7.3 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-12912 | Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image | HIGH | 7.3 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-44185 | Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` | HIGH | 7.3 | 53%ile | Microsoft | 2026-06-09 |
| CVE-2026-48913 | Apache HTTP Server: mod_http2 memory corruption when file handles exhausted | HIGH | 7.3 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-58014 | Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" | HIGH | 7.3 | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 51%ile | Microsoft | 2026-06-09 |
| CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-46320 | tap: free page on error paths in tap_get_user_xdp() | HIGH | 7.1 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-46330 | Revert "net/smc: Introduce TCP ULP support" | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-49839 | jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow | HIGH | 7.1 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-52917 | sctp: diag: reject stale associations in dump_one path | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52918 | Bluetooth: serialize accept_q access | HIGH | 7.1 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-52942 | netfilter: nf_log: validate MAC header was set before dumping it | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52953 | iommu/vt-d: Fix oops due to out of scope access | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52961 | ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size | HIGH | 7.1 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-52969 | KVM: Reject wrapped offset in kvm_reset_dirty_gfn() | HIGH | 7.1 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-53023 | fs/ntfs3: terminate the cached volume label after UTF-8 conversion | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53024 | greybus: raw: fix use-after-free if write is called after disconnect | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53027 | fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53063 | dm cache: fix write hang in passthrough mode | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53064 | dm cache: fix null-deref with concurrent writes in passthrough mode | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53091 | net: pull headers in qdisc_pkt_len_segs_init() | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53136 | drm/amd/display: Clamp VBIOS HDMI retimer register count to array size | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53137 | drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size | HIGH | 7.1 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-53178 | staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction | HIGH | 7.1 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-53179 | staging: rtl8723bs: fix buffer over-read in rtw_update_protection | HIGH | 7.1 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-53186 | RDMA/srp: bound SRP_RSP sense copy by the received length | HIGH | 7.1 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-53212 | netfilter: nft_tunnel: fix use-after-free on object destroy | HIGH | 7.1 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-53230 | net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53253 | Bluetooth: bnep: reject short frames before parsing | HIGH | 7.1 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-53265 | dm cache policy smq: check allocation under invalidate lock | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53268 | netfilter: conntrack_irc: fix possible out-of-bounds read | HIGH | 7.1 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-53270 | ipvs: clear the svc scheduler ptr early on edit | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53689 | CVE-2026-53689 | HIGH | 7.1 | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-54369 | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions | HIGH | 7.1 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-54371 | attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr | HIGH | 7.1 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability | HIGH | 7.1 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution | HIGH | 7.1 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.1 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-46285 | mtd: docg3: fix use-after-free in docg3_release() | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52996 | ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53041 | ocfs2: fix listxattr handling when the buffer is full | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53217 | net: mvpp2: sync RX data at the hardware packet offset | HIGH | 7.1 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-57918 | libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d | HIGH | 7.1 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-46293 | clk: microchip: mpfs-ccc: fix out of bounds access during output registration | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53195 | USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() | HIGH | 7.1 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53098 | wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52992 | fs/adfs: validate nzones in adfs_validate_bblk() | HIGH | 7.1 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53016 | crypto: ccp - copy IV using skcipher ivsize | HIGH | 7.1 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53306 | tty: hvc_iucv: fix off-by-one in number of supported devices | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53303 | f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-46244 | netfilter: nft_inner: Fix IPv6 inner_thoff desync | HIGH | 7.0 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-46275 | Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-46306 | flow_dissector: do not dissect PPPoE PFC frames | HIGH | 7.0 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-46319 | net/sched: act_ct: Only release RCU read lock after ct_ft | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52920 | netfilter: xt_policy: fix strict mode inbound policy matching | HIGH | 7.0 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-52924 | sctp: purge outqueue on stale COOKIE-ECHO handling | HIGH | 7.0 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-52933 | io_uring/poll: fix signed comparison in io_poll_get_ownership() | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52998 | netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check | HIGH | 7.0 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-53006 | ipv6: fix possible UAF in icmpv6_rcv() | HIGH | 7.0 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-53011 | net/sched: taprio: fix use-after-free in advance_sched() on schedule switch | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53034 | bpf, sockmap: Fix af_unix null-ptr-deref in proto update | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53059 | dm log: fix out-of-bounds write due to region_count overflow | HIGH | 7.0 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53071 | Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp | HIGH | 7.0 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-53072 | Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER | HIGH | 7.0 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-53073 | Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53078 | bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53131 | netfilter: require Ethernet MAC header before using eth_hdr() | HIGH | 7.0 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-53132 | vsock/virtio: fix potential unbounded skb queue | HIGH | 7.0 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53133 | RDMA/umem: Fix truncation for block sizes >= 4G | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53148 | thunderbolt: Clamp XDomain response data copy to allocation size | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53150 | thunderbolt: Reject zero-length property entries in validator | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53167 | fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53168 | fuse: reject fuse_notify() pagecache ops on directories | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53182 | wifi: nl80211: reject oversized EMA RNR lists | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53192 | ALSA: timer: Fix UAF at snd_timer_user_params() | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53208 | Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53209 | Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53218 | netfilter: nft_exthdr: fix register tracking for F_PRESENT flag | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53228 | ipv6: sit: reload inner IPv6 header after GSO offloads | HIGH | 7.0 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-53236 | tcp: restrict SO_ATTACH_FILTER to priv users | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53239 | xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53242 | ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53249 | ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53254 | Bluetooth: RFCOMM: validate skb length in MCC handlers | HIGH | 7.0 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-53264 | net/sched: act_api: use RCU with deferred freeing for action lifecycle | HIGH | 7.0 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-53267 | netfilter: nft_ct: bail out on template ct in get eval | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53275 | ipv6: mcast: Fix use-after-free when processing MLD queries | HIGH | 7.0 | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-58050 | libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation | HIGH | 7.0 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.0 | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-53161 | misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context | HIGH | 7.0 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-56132 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array | MEDIUM | 6.9 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-56403 | libexpat before 2.8.2 has an integer overflow in storeAtts. | MEDIUM | 6.9 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-56404 | libexpat before 2.8.2 has an integer overflow in addBinding. | MEDIUM | 6.9 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-56405 | libexpat before 2.8.2 has an integer overflow in getAttributeId. | MEDIUM | 6.9 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-56406 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse | MEDIUM | 6.9 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-56407 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. | MEDIUM | 6.9 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-56410 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. | MEDIUM | 6.9 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-56411 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. | MEDIUM | 6.9 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-53266 | netfilter: bridge: make ebt_snat ARP rewrite writable | MEDIUM | 6.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-13595 | Util-linux: util-linux: heap use-after-free in libblkid nested partition probing | MEDIUM | 6.8 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability | MEDIUM | 6.8 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 92%ile | Microsoft | 2026-06-09 |
| CVE-2026-48914 | Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling | MEDIUM | 6.7 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-42014 | Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin | MEDIUM | 6.6 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-46323 | net: gro: don't merge zcopy skbs | MEDIUM | 6.6 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-50257 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() | MEDIUM | 6.6 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-50260 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() | MEDIUM | 6.6 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-57438 | Nokogiri: Possible Use-After-Free in XInclude Processing | MEDIUM | 6.6 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2025-15661 | libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-06-09 |
| CVE-2026-13208 | Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request | MEDIUM | 6.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-43951 | Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-44186 | Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-46433 | lldpd: Heap OOB Read in VLAN Decapsulation memmove | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-48855 | SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-48856 | httpc leaks Authorization header to cross-origin redirect targets | MEDIUM | 6.5 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-48858 | ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks | MEDIUM | 6.5 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-48860 | Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist | MEDIUM | 6.5 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-53111 | bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap | MEDIUM | 6.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53146 | thunderbolt: Limit XDomain response copy to actual frame size | MEDIUM | 6.5 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-56116 | dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling | MEDIUM | 6.5 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. | MEDIUM | 6.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57453 | Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction | MEDIUM | 6.5 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-58010 | Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() | MEDIUM | 6.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-58011 | Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-58012 | Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() | MEDIUM | 6.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-58013 | Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" | MEDIUM | 6.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-58051 | libssh2 - Free of Uninitialized Pointer in publickey List Cleanup | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-58058 | Nmap - Integer Underflow in IPv6 Extension Header Parsing | MEDIUM | 6.5 | 71%ile | Microsoft | 2026-06-09 |
| CVE-2026-9539 | libslirp TCP URG OOB Read Information Leak | MEDIUM | 6.5 | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability | MEDIUM | 6.5 | 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-42895 | Microsoft Copilot Tampering Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability | MEDIUM | 6.5 | 58%ile | Microsoft | 2026-06-09 |
| CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-06-09 |
| CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability | MEDIUM | 6.5 | 75%ile | Microsoft | 2026-06-09 |
| CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-06-09 |
| CVE-2026-47287 | Visual Studio Code Tampering Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-06-09 |
| CVE-2026-47644 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-06-09 |
| CVE-2026-47655 | Microsoft Graph Information Disclosure Vulnerability | MEDIUM | 6.5 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability | MEDIUM | 6.5 | 95%ile | Microsoft | 2026-06-09 |
| CVE-2026-50519 | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-06-09 |
| CVE-2026-6291 | Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption | MEDIUM | 6.5 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-6329 | PKCS#12 MAC verification uses attacker-controlled comparison length | MEDIUM | 6.5 | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-6330 | ML-KEM ARM64 NEON ciphertext comparison only compares half of the input | MEDIUM | 6.5 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-55962 | TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify | MEDIUM | 6.5 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-6091 | Partial-chain verification accepts untrusted intermediate as trust anchor | MEDIUM | 6.5 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-13318 | Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip | MEDIUM | 6.4 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-52968 | KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic | MEDIUM | 6.4 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53074 | bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb | MEDIUM | 6.4 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53094 | bpf: Fix stale offload->prog pointer after constant blinding | MEDIUM | 6.4 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-13201 | Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and n | MEDIUM | 6.3 | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-13757 | P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing | MEDIUM | 6.2 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-45491 | .NET Tampering Vulnerability | MEDIUM | 6.2 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-29170 | Apache HTTP Server: mod_proxy_ftp XSS | MEDIUM | 6.1 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-44889 | WebOb: Location header normalization during redirect leads to open redirect | MEDIUM | 6.1 | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-46322 | tun: free page on build_skb failure in tun_xdp_one() | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-46325 | RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE | MEDIUM | 6.1 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-53021 | scsi: target: core: Fix integer overflow in UNMAP bounds check | MEDIUM | 6.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57454 | Vim: Out-of-bounds Read with Text Properties | MEDIUM | 6.1 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 6.1 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-12725 | Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies | MEDIUM | 5.9 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-42766 | Possible NULL Dereference in Password-Based CMS Decryption | MEDIUM | 5.9 | 63%ile | Microsoft | 2026-06-09 |
| CVE-2026-42767 | NULL Pointer Dereference in CRMF EncryptedValue Decryption | MEDIUM | 5.9 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-52946 | fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling | MEDIUM | 5.9 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-55199 | libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler | MEDIUM | 5.9 | 59%ile | Microsoft | 2026-06-09 |
| CVE-2026-58015 | Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive | MEDIUM | 5.9 | 50%ile | Microsoft | 2026-06-09 |
| CVE-2026-54411 | Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-passwor | MEDIUM | 5.9 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2025-71315 | drm/vkms: Convert to DRM's vblank timer | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-3196 | Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-4367 | Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-44119 | Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-46254 | AppArmor: Allow apparmor to handle unaligned dfa tables | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46273 | ibmveth: Disable GSO for packets with small MSS | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-46280 | lib: test_hmm: evict device pages on file close to avoid use-after-free | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-46282 | iio: frequency: admv1013: fix NULL pointer dereference on str | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46287 | net: txgbe: fix RTNL assertion warning when remove module | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46289 | lib/scatterlist: fix length calculations in extract_kvec_to_sg | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-46291 | crypto: caam - guard HMAC key hex dumps in hash_digest_key | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46292 | pmdomain: core: Fix detach procedure for virtual devices in genpd | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46296 | spi: s3c64xx: fix NULL-deref on driver unbind | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46299 | hfsplus: fix held lock freed on hfsplus_fill_super() | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-46302 | selinux: allow multiple opens of /sys/fs/selinux/policy | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-46303 | isofs: validate Rock Ridge CE continuation extent against volume size | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-46304 | nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-46307 | wifi: ath5k: do not access array OOB | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-46312 | media: videobuf2: Set vma_flags in vb2_dma_sg_mmap | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46314 | drm/v3d: Reject empty multisync extension to prevent infinite loop | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46321 | tun: free page on short-frame rejection in tun_xdp_one() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-47770 | jq: stack overflow in deep structural equality | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-49760 | Stack Buffer Overflow in ei_s_print_term at Very Large Integer | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-50262 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-50263 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-52915 | netfilter: ip6t_hbh: reject oversized option lists | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52916 | batman-adv: frag: disallow unicast fragment in fragment | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52921 | netfilter: ipset: stop hash:* range iteration at end | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52925 | vrf: Fix a potential NPD when removing a port from a VRF | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52927 | netfilter: ebtables: fix OOB read in compat_mtw_from_user | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52928 | af_unix: Reject SIOCATMARK on non-stream sockets | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52929 | sctp: stream: fully roll back denied add-stream state | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-52930 | ipc/shm: serialize orphan cleanup with shm_nattch updates | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52936 | crypto: jitterentropy - replace long-held spinlock with mutex | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52937 | tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52941 | net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52948 | i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52954 | libceph: handle rbtree insertion error in decode_choose_args() | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-52958 | libceph: Fix potential out-of-bounds access in osdmap_decode() | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-52960 | ceph: put folios not suitable for writeback | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-52962 | ceph: fix a buffer leak in __ceph_setxattr() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-52963 | ALSA: usb-audio: Bound MIDI endpoint descriptor scans | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52967 | smb/client: fix possible infinite loop and oob read in symlink_data() | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-52970 | netfilter: nft_ct: fix missing expect put in obj eval | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52974 | net: tls: fix strparser anchor skb leak on offload RX setup failure | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-52975 | bonding: 3ad: implement proper RCU rules for port->aggregator | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-52977 | futex: Prevent lockup in requeue-PI during signal/ timeout wakeup | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52981 | neigh: let neigh_xmit take skb ownership | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-52982 | net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-52984 | net/sched: netem: fix queue limit check to include reordered packets | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52985 | netdevsim: zero initialize struct iphdr in dummy sk_buff | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52988 | netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52999 | netfilter: nfnetlink_osf: fix out-of-bounds read on option matching | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-53003 | pppoe: drop PFC frames | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-53012 | nexthop: fix IPv6 route referencing IPv4 nexthop | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53013 | macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53015 | erofs: unify lcn as u64 for 32-bit platforms | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53022 | platform/x86: dell-wmi-sysman: bound enumeration string aggregation | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53032 | bpf: Fix NULL deref in map_kptr_match_type for scalar regs | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53035 | bpf, sockmap: Fix af_unix iter deadlock | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53037 | HID: usbhid: fix deadlock in hid_post_reset() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53047 | efi/capsule-loader: fix incorrect sizeof in phys array reallocation | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53050 | quota: Fix race of dquot_scan_active() with quota deactivation | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53056 | drm/msm/dpu: fix mismatch between power and frequency | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53058 | drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53060 | dm cache metadata: fix memory leak on metadata abort retry | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53061 | dm cache: fix dirty mapping checking in passthrough mode switching | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53066 | drm/sun4i: backend: fix error pointer dereference | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53070 | sctp: disable BH before calling udp_tunnel_xmit_skb() | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-53076 | bpf: Fix OOB in pcpu_init_value | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53080 | net/sched: cls_fw: fix NULL dereference of "old" filters before change() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53082 | net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53088 | net: bcmgenet: fix off-by-one in bcmgenet_put_txcb | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-53093 | wifi: brcmfmac: Fix error pointer dereference | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53096 | bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53102 | wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53106 | bpf: Do not allow deleting local storage in NMI | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53107 | wifi: libertas: don't kill URBs in interrupt context | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53108 | powerpc/64s: Fix unmap race with PMD migration entries | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-53109 | powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53110 | s390/bpf: Zero-extend bpf prog return values and kfunc arguments | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53113 | wifi: ath11k: fix memory leaks in beacon template setup | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53115 | bus: fsl-mc: use generic driver_override infrastructure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53118 | vdpa: use generic driver_override infrastructure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53120 | PCI: use generic driver_override infrastructure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53122 | btrfs: fix deadlock between reflink and transaction commit when using flushoncommit | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53126 | blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53128 | drbd: Balance RCU calls in drbd_adm_dump_devices() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53129 | fs/mbcache: cancel shrink work before destroying the cache | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53135 | drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-53138 | drm/amd/display: Bound VBIOS record-chain walk loops | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53139 | drm/v3d: Skip CSD when it has zeroed workgroups | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53147 | thunderbolt: Validate XDomain request packet size before type cast | MEDIUM | 5.5 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-53149 | thunderbolt: Bound root directory content to block size | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53151 | rxrpc: Fix the ACK parser to extract the SACK table for parsing | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-53154 | mm/hugetlb: restore reservation on error in hugetlb folio copy paths | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-53156 | nvmem: core: fix use-after-free bugs in error paths | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-53157 | net: phonet: free phonet_device after RCU grace period | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53163 | locking/rtmutex: Skip remove_waiter() when waiter is not enqueued | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53166 | futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock | MEDIUM | 5.5 | — | Microsoft | 2026-06-09 |
| CVE-2026-53177 | bnxt_en: Fix NULL pointer dereference | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53181 | vsock/vmci: fix sk_ack_backlog leak on failed handshake | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53183 | mptcp: allow subflow rcv wnd to shrink | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-53184 | udp: clear skb->dev before running a sockmap verdict | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-53190 | drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-53199 | hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-53207 | mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53213 | drm/vc4: fix krealloc() memory leak | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53214 | ipv6: Fix a potential NPD in cleanup_prefix_route() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-53219 | netfilter: x_tables: avoid leaking percpu counter pointers | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53220 | netfilter: revalidate bridge ports | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53221 | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-53223 | net: guard timestamp cmsgs to real error queue skbs | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53225 | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-53226 | gpio: rockchip: fix generic IRQ chip leak on remove | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53227 | net: openvswitch: fix possible kfree_skb of ERR_PTR | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53229 | net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-53232 | net: phy: clean the sfp upstream if phy probing fails | MEDIUM | 5.5 | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-53237 | gpio: mvebu: fix NULL pointer dereference in suspend/resume | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-53245 | net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53252 | Bluetooth: fix memory leak in error path of hci_alloc_dev() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53255 | Bluetooth: MGMT: validate advertising TLV before type checks | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53258 | wifi: fix leak if split 6 GHz scanning fails | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-53263 | 6lowpan: fix off-by-one in multicast context address compression | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-53269 | netfilter: synproxy: add mutex to guard hook reference counting | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53274 | net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-53287 | audit: fix incorrect inheritable capability in CAPSET records | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53289 | ice: fix NULL pointer dereference in ice_reset_all_vfs() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53291 | ALSA: hda/conexant: Fix missing error check for jack detection | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53292 | net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53293 | drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53295 | mailbox: add sanity check for channel array | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53297 | net: mana: Guard mana_remove against double invocation | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53304 | scsi: sg: Resolve soft lockup issue when opening /dev/sgX | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53313 | drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53314 | padata: Put CPU offline callback in ONLINE section to allow failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53317 | wifi: mt76: mt7921: Place upper limit on station AID | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53325 | agp/amd64: Fix broken error propagation in agp_amd64_probe() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-54679 | jq: potential integer overflow in jvp_string_append | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-54905 | concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-55892 | Vim: Out-of-bounds Write in Spell File Prefix Dump | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57452 | Vim: Out-of-bounds Read with libsodium-encrypted Files | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-42915 | Microsoft Windows VMSwitch Denial of Service Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-44821 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45647 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-53065 | ASoC: sti: use managed regmap_field allocations | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53158 | misc: fastrpc: Fix NULL pointer dereference in rpmsg callback | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53046 | ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-53048 | gfs2: prevent NULL pointer dereference during unmount | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52964 | ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53320 | nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53296 | mailbox: mailbox-test: free channels on probe error | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53294 | mailbox: mailbox-test: don't free the reused channel | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53279 | drm/gma500/oaktrail_lvds: fix hang on init failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53655 | node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation di | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability | MEDIUM | 5.4 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 59%ile | Microsoft | 2026-06-09 |
| CVE-2026-40930 | LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body | MEDIUM | 5.4 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-58055 | nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length | MEDIUM | 5.4 | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-12969 | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-42507 | Arbitrary inputs are included in errors without any escaping in net/textproto | MEDIUM | 5.3 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-42769 | Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-44967 | opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response | MEDIUM | 5.3 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-57436 | Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-57437 | Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-57451 | Vim: Out-of-bounds Read in Text Property Count | MEDIUM | 5.3 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability | MEDIUM | 5.3 | 55%ile | Microsoft | 2026-06-09 |
| CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 5.3 | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-6450 | CRL critical extension bypass in ParseCRL_Extensions | MEDIUM | 5.3 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-55964 | Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption) | MEDIUM | 5.3 | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-6678 | Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info | MEDIUM | 5.3 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10592 | Wildcard DNS SAN bypasses CA name-constraint checks | MEDIUM | 5.3 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-10098 | OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status | MEDIUM | 5.3 | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-50265 | Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292 | MEDIUM | 5.3 | — | Microsoft | 2026-06-09 |
| CVE-2026-6092 | Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured | MEDIUM | 5.3 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10275 | OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow | MEDIUM | 5.0 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-55655 | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client ve | MEDIUM | 5.0 | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability | MEDIUM | 5.0 | 97%ile | Microsoft | 2026-06-09 |
| CVE-2026-35188 | Double-free When Checking OCSP Stapled Response | MEDIUM | 5.0 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-50219 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars | MEDIUM | 4.9 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-56131 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a | MEDIUM | 4.9 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-56412 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking | MEDIUM | 4.9 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45446 | Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes | MEDIUM | 4.8 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-48142 | NGINX ngx_http_charset_module vulnerability | MEDIUM | 4.8 | 51%ile | Microsoft | 2026-06-09 |
| CVE-2026-46245 | drm/amd/display: Fix dc_link NULL handling in HPD init | MEDIUM | 4.7 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53112 | wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 4.7 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-11623 | tmux image.c image_free use after free | MEDIUM | 4.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2025-71313 | PCI: endpoint: Add missing NULL check for alloc_workqueue() | MEDIUM | 4.4 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-46250 | MIPS: Work around LLVM bug when gp is used as global register variable | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53238 | netlabel: validate unlabeled address and mask attribute lengths | MEDIUM | 4.3 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-55653 | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validati | MEDIUM | 4.3 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability | MEDIUM | 4.3 | 48%ile | Microsoft | 2026-06-09 |
| CVE-2026-6412 | Continued acceptance of SHA-1/MD5 digests in certificate processing | MEDIUM | 4.3 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-13218 | Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher | MEDIUM | 4.2 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11526 | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments | MEDIUM | 4.2 | 70%ile | Microsoft | 2026-06-09 |
| CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability | LOW | 3.9 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-46272 | coresight: tmc-etr: Fix race condition between sysfs and perf mode | LOW | 3.9 | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-13322 | Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service | LOW | 3.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-11525 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching | LOW | 3.7 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-42768 | Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() | LOW | 3.7 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-42770 | FFC-DH Peer Validation Uses Attacker-Supplied q | LOW | 3.7 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-5419 | Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal | LOW | 3.7 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-46252 | regulator: core: fix locking in regulator_resolve_supply() error path | LOW | 3.4 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability | LOW | 3.3 | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability | LOW | 3.3 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability | LOW | 3.3 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-45485 | Microsoft Office Information Disclosure Vulnerability | LOW | 3.3 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-10722 | cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow | LOW | 3.3 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-49356 | Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core | LOW | 3.2 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-57062 | CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM becaus | LOW | 2.9 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-57234 | Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247 | LOW | 2.6 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-53089 | bpf: Fix use-after-free in offloaded map/prog info fill | LOW | 2.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-0864 | Configuration Injection via Carriage Return (\r) in write() method | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-10846 | Insufficient verification that responses belong to a query | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11972 | tarfile opened in streaming mode mishandles EOF | UNKNOWN | — | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-12003 | CPython >3.11 Insecure Input Validation resulting in privilege escalation | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-3276 | Potential DoS via quadratic complexity in unicodedata.normalize() | UNKNOWN | — | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-41991 | Predictable Temporary File in GNU gzip | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-41992 | Global Buffer Overflow in GNU gzip | UNKNOWN | — | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-4360 | Tarfile.extract() doesn't fully respect filter parameter | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-43966 | HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-43973 | gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion | UNKNOWN | — | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-47162 | Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-47167 | Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-47240 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | UNKNOWN | — | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-47242 | Net::IMAP: Command Injection via ID command argument | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-49762 | Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-49851 | Mistune: Potential DoS via quadratic-time parsing in parse_link_text | UNKNOWN | — | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-52858 | Vim: Arbitrary Code Execution via Python Omni-Completion | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-52859 | Vim: Out-of-bounds Read in Terminal Screen Snapshot | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-52860 | Vim: Arbitrary Code Execution via Python Omni-Completion | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-7774 | tarfile.data_filter path traversal bypass allows writing outside the extraction directory | UNKNOWN | — | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-8643 | pip can extract console_scripts and gui_scripts outside installation directory | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-9669 | bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow | UNKNOWN | — | 51%ile | Microsoft | 2026-06-09 |
| CVE-2026-10881 | Chromium: CVE-2026-10881 Out of bounds read and write in ANGLE | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10882 | Chromium: CVE-2026-10882 Use after free in Network | UNKNOWN | — | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-10883 | Chromium: CVE-2026-10883 Out of bounds write in ANGLE | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10884 | Chromium: CVE-2026-10884 Use after free in Chromecast | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10886 | Chromium: CVE-2026-10886 Use after free in FileSystem | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-10887 | Chromium: CVE-2026-10887 Use after free in Chromoting | UNKNOWN | — | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-10888 | Chromium: CVE-2026-10888 Use after free in Cast Streaming | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-10889 | Chromium: CVE-2026-10889 Out of bounds read in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10890 | Chromium: CVE-2026-10890 Use after free in Cast | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-10891 | Chromium: CVE-2026-10891 Use after free in GFX | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10892 | Chromium: CVE-2026-10892 Out of bounds write in GPU | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10893 | Chromium: CVE-2026-10893 Use after free in Chromoting | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10894 | Chromium: CVE-2026-10894 Use after free in Printing | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10895 | Chromium: CVE-2026-10895 Use after free in Ozone | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10897 | Chromium: CVE-2026-10897 Out of bounds write in GPU | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10898 | Chromium: CVE-2026-10898 Stack buffer overflow in GPU | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10899 | Chromium: CVE-2026-10899 Use after free in Ozone | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10900 | Chromium: CVE-2026-10900 Use after free in Passwords | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10901 | Chromium: CVE-2026-10901 Use after free in Passwords | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-10902 | Chromium: CVE-2026-10902 Use after free in Ozone | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10903 | Chromium: CVE-2026-10903 Use after free in WebRTC | UNKNOWN | — | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-10904 | Chromium: CVE-2026-10904 Inappropriate implementation in V8 | UNKNOWN | — | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-10905 | Chromium: CVE-2026-10905 Use after free in Network | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10906 | Chromium: CVE-2026-10906 Use after free in WebAuthentication | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10907 | Chromium: CVE-2026-10907 Out of bounds write in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10908 | Chromium: CVE-2026-10908 Use after free in FullScreen | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10909 | Chromium: CVE-2026-10909 Use after free in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10910 | Chromium: CVE-2026-10910 Type Confusion in V8 | UNKNOWN | — | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-10911 | Chromium: CVE-2026-10911 Insufficient validation of untrusted input in Media | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10912 | Chromium: CVE-2026-10912 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10913 | Chromium: CVE-2026-10913 Use after free in ANGLE | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10914 | Chromium: CVE-2026-10914 Use after free in ANGLE | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10916 | Chromium: CVE-2026-10916 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-10917 | Chromium: CVE-2026-10917 Insufficient validation of untrusted input in Media | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10918 | Chromium: CVE-2026-10918 Use after free in Viz | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10919 | Chromium: CVE-2026-10919 Use after free in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10920 | Chromium: CVE-2026-10920 Insufficient validation of untrusted input in WebShare | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10921 | Chromium: CVE-2026-10921 Integer overflow in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10922 | Chromium: CVE-2026-10922 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10923 | Chromium: CVE-2026-10923 Use after free in WebAppInstalls | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10924 | Chromium: CVE-2026-10924 Integer overflow in Chromecast | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10925 | Chromium: CVE-2026-10925 Out of bounds write in Skia | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10926 | Chromium: CVE-2026-10926 Use after free in Cast | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-10927 | Chromium: CVE-2026-10927 Out of bounds read in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10928 | Chromium: CVE-2026-10928 Script injection in Headless | UNKNOWN | — | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-10929 | Chromium: CVE-2026-10929 Heap buffer overflow in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10930 | Chromium: CVE-2026-10930 Out of bounds read in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10931 | Chromium: CVE-2026-10931 Use after free in FileSystem | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10932 | Chromium: CVE-2026-10932 Use after free in UI | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10933 | Chromium: CVE-2026-10933 Use after free in Audio | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-10934 | Chromium: CVE-2026-10934 Use after free in Autofill | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-10935 | Chromium: CVE-2026-10935 Inappropriate implementation in V8 | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10936 | Chromium: CVE-2026-10936 Type Confusion in V8 | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10937 | Chromium: CVE-2026-10937 Inappropriate implementation in Passwords | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-10938 | Chromium: CVE-2026-10938 Insufficient validation of untrusted input in Input | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10939 | Chromium: CVE-2026-10939 Use after free in WebRTC | UNKNOWN | — | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-10940 | Chromium: CVE-2026-10940 Race in Codecs | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-10941 | Chromium: CVE-2026-10941 Out of bounds memory access in Skia | UNKNOWN | — | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-10942 | Chromium: CVE-2026-10942 Insufficient validation of untrusted input in UI | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-10943 | Chromium: CVE-2026-10943 Use after free in WebRTC | UNKNOWN | — | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-10945 | Chromium: CVE-2026-10945 Use after free in PDF | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10946 | Chromium: CVE-2026-10946 Heap buffer overflow in Media | UNKNOWN | — | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-10947 | Chromium: CVE-2026-10947 Use after free in WebRTC | UNKNOWN | — | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-10948 | Chromium: CVE-2026-10948 Use after free in WebRTC | UNKNOWN | — | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-10949 | Chromium: CVE-2026-10949 Heap buffer overflow in Video | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10953 | Chromium: CVE-2026-10953 Use after free in Core | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10954 | Chromium: CVE-2026-10954 Use after free in Actor | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10955 | Chromium: CVE-2026-10955 Type Confusion in ANGLE | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10956 | Chromium: CVE-2026-10956 Use after free in MimeHandlerView | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10957 | Chromium: CVE-2026-10957 Use after free in Glic | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10959 | Chromium: CVE-2026-10959 Use after free in Input | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10960 | Chromium: CVE-2026-10960 Uninitialized Use in Codecs | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-10962 | Chromium: CVE-2026-10962 Type Confusion in Media | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10963 | Chromium: CVE-2026-10963 Integer overflow in V8 | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10964 | Chromium: CVE-2026-10964 Integer overflow in V8 | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10965 | Chromium: CVE-2026-10965 Integer overflow in DevTools | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10966 | Chromium: CVE-2026-10966 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10967 | Chromium: CVE-2026-10967 Use after free in SurfaceCapture | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-10968 | Chromium: CVE-2026-10968 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10969 | Chromium: CVE-2026-10969 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10970 | Chromium: CVE-2026-10970 Insufficient validation of untrusted input in InterestGroups | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10971 | Chromium: CVE-2026-10971 Insufficient validation of untrusted input in Printing | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10972 | Chromium: CVE-2026-10972 Use after free in Ozone | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10973 | Chromium: CVE-2026-10973 Uninitialized Use in Dawn | UNKNOWN | — | 61%ile | Microsoft | 2026-06-09 |
| CVE-2026-10974 | Chromium: CVE-2026-10974 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10975 | Chromium: CVE-2026-10975 Use after free in WebRTC | UNKNOWN | — | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-10976 | Chromium: CVE-2026-10976 Uninitialized Use in Dawn | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10977 | Chromium: CVE-2026-10977 Uninitialized Use in Skia | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10978 | Chromium: CVE-2026-10978 Use after free in Chromoting | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10979 | Chromium: CVE-2026-10979 Out of bounds read in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10980 | Chromium: CVE-2026-10980 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10981 | Chromium: CVE-2026-10981 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10982 | Chromium: CVE-2026-10982 Use after free in WebXR | UNKNOWN | — | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-10983 | Chromium: CVE-2026-10983 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10984 | Chromium: CVE-2026-10984 Inappropriate implementation in Accessibility | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-10985 | Chromium: CVE-2026-10985 Out of bounds read in Skia | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10986 | Chromium: CVE-2026-10986 Integer overflow in Media | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10987 | Chromium: CVE-2026-10987 Integer overflow in V8 | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10988 | Chromium: CVE-2026-10988 Use after free in Views | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10989 | Chromium: CVE-2026-10989 Inappropriate implementation in V8 | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10990 | Chromium: CVE-2026-10990 Use after free in Glic | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10991 | Chromium: CVE-2026-10991 Use after free in V8 | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10992 | Chromium: CVE-2026-10992 Insufficient data validation in Animation | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10993 | Chromium: CVE-2026-10993 Heap buffer overflow in Skia | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10994 | Chromium: CVE-2026-10994 Uninitialized Use in ANGLE | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10995 | Chromium: CVE-2026-10995 Heap buffer overflow in TabStrip | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10996 | Chromium: CVE-2026-10996 Inappropriate implementation in Workers | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-10997 | Chromium: CVE-2026-10997 Insufficient policy enforcement in Extensions | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-10998 | Chromium: CVE-2026-10998 Out of bounds read in Media | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-10999 | Chromium: CVE-2026-10999 Out of bounds memory access in ANGLE | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-11000 | Chromium: CVE-2026-11000 Use after free in Fonts | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-11001 | Chromium: CVE-2026-11001 Incorrect security UI in Payments | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11002 | Chromium: CVE-2026-11002 Use after free in Autofill | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11003 | Chromium: CVE-2026-11003 Use after free in WebRTC | UNKNOWN | — | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-11004 | Chromium: CVE-2026-11004 Out of bounds read in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11005 | Chromium: CVE-2026-11005 Out of bounds read in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11006 | Chromium: CVE-2026-11006 Out of bounds read in Dawn | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11007 | Chromium: CVE-2026-11007 Insufficient validation of untrusted input in WebView | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11008 | Chromium: CVE-2026-11008 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11009 | Chromium: CVE-2026-11009 Use after free in USB | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-11010 | Chromium: CVE-2026-11010 Use after free in WebShare | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11011 | Chromium: CVE-2026-11011 Insufficient policy enforcement in Password Manager | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11012 | Chromium: CVE-2026-11012 Use after free in Serial | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11013 | Chromium: CVE-2026-11013 Insufficient validation of untrusted input in Network | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11014 | Chromium: CVE-2026-11014 Insufficient policy enforcement in Extensions | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11015 | Chromium: CVE-2026-11015 Out of bounds read in WebGPU | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-11016 | Chromium: CVE-2026-11016 Insufficient validation of untrusted input in Network | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11017 | Chromium: CVE-2026-11017 Inappropriate implementation in Link Preview | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11018 | Chromium: CVE-2026-11018 Insufficient policy enforcement in Actor | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11019 | Chromium: CVE-2026-11019 Inappropriate implementation in Payments | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11020 | Chromium: CVE-2026-11020 Inappropriate implementation in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11021 | Chromium: CVE-2026-11021 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-11022 | Chromium: CVE-2026-11022 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11023 | Chromium: CVE-2026-11023 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11024 | Chromium: CVE-2026-11024 Stack buffer overflow in Skia | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11025 | Chromium: CVE-2026-11025 Insufficient policy enforcement in Navigation | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11026 | Chromium: CVE-2026-11026 Insufficient policy enforcement in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11027 | Chromium: CVE-2026-11027 Insufficient validation of untrusted input in Glic | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11028 | Chromium: CVE-2026-11028 Use after free in Media | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-11029 | Chromium: CVE-2026-11029 Insufficient validation of untrusted input in Drag and Drop | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11030 | Chromium: CVE-2026-11030 Use after free in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11031 | Chromium: CVE-2026-11031 Insufficient validation of untrusted input in Password Manager | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11032 | Chromium: CVE-2026-11032 Insufficient data validation in Password Manager | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11033 | Chromium: CVE-2026-11033 Uninitialized Use in WebML | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11034 | Chromium: CVE-2026-11034 Insufficient validation of untrusted input in Tab Group Sync | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11035 | Chromium: CVE-2026-11035 Insufficient validation of untrusted input in Custom Tabs | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11036 | Chromium: CVE-2026-11036 Inappropriate implementation in DOM | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11037 | Chromium: CVE-2026-11037 Out of bounds write in Codecs | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11038 | Chromium: CVE-2026-11038 Insufficient validation of untrusted input in Subresource Integrity | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11039 | Chromium: CVE-2026-11039 Uninitialized Use in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11040 | Chromium: CVE-2026-11040 Use after free in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11041 | Chromium: CVE-2026-11041 Insufficient validation of untrusted input in Media | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11042 | Chromium: CVE-2026-11042 Use after free in Views | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11043 | Chromium: CVE-2026-11043 Out of bounds write in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11044 | Chromium: CVE-2026-11044 Integer overflow in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11045 | Chromium: CVE-2026-11045 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11046 | Chromium: CVE-2026-11046 Insufficient validation of untrusted input in Media | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-11047 | Chromium: CVE-2026-11047 Insufficient validation of untrusted input in Base | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11048 | Chromium: CVE-2026-11048 Inappropriate implementation in Extensions | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11049 | Chromium: CVE-2026-11049 Use after free in Password Manager | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11050 | Chromium: CVE-2026-11050 Use after free in V8 | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11051 | Chromium: CVE-2026-11051 Out of bounds read in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11052 | Chromium: CVE-2026-11052 Type Confusion in GPU | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11053 | Chromium: CVE-2026-11053 VULNERABILITY in WebRTC | UNKNOWN | — | — | Microsoft | 2026-06-09 |
| CVE-2026-11054 | Chromium: CVE-2026-11054 Use after free in WebRTC | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11055 | Chromium: CVE-2026-11055 Use after free in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11056 | Chromium: CVE-2026-11056 Insufficient validation of untrusted input in SiteIsolation | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11057 | Chromium: CVE-2026-11057 Uninitialized Use in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11058 | Chromium: CVE-2026-11058 Integer overflow in CredentialProvider | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11059 | Chromium: CVE-2026-11059 Use after free in Blink | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11060 | Chromium: CVE-2026-11060 Use after free in Media | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11061 | Chromium: CVE-2026-11061 Out of bounds read in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11062 | Chromium: CVE-2026-11062 Insufficient policy enforcement in Extensions | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-11063 | Chromium: CVE-2026-11063 Insufficient validation of untrusted input in WebNN | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11064 | Chromium: CVE-2026-11064 Uninitialized Use in GPU | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11065 | Chromium: CVE-2026-11065 Use after free in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-11066 | Chromium: CVE-2026-11066 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11067 | Chromium: CVE-2026-11067 Uninitialized Use in Dawn | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11068 | Chromium: CVE-2026-11068 Use after free in WebSockets | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11069 | Chromium: CVE-2026-11069 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11070 | Chromium: CVE-2026-11070 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11071 | Chromium: CVE-2026-11071 Use after free in Base | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11072 | Chromium: CVE-2026-11072 Use after free in WebView | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11073 | Chromium: CVE-2026-11073 Use after free in WebGL | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11074 | Chromium: CVE-2026-11074 Use after free in WebRTC | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11075 | Chromium: CVE-2026-11075 Out of bounds read in V8 | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11076 | Chromium: CVE-2026-11076 Type Confusion in CSS | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11077 | Chromium: CVE-2026-11077 Out of bounds read in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11078 | Chromium: CVE-2026-11078 Insufficient validation of untrusted input in FileSystem | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11079 | Chromium: CVE-2026-11079 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11080 | Chromium: CVE-2026-11080 Use after free in WebView | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11081 | Chromium: CVE-2026-11081 Policy bypass in Canvas | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11082 | Chromium: CVE-2026-11082 Use after free in GPU | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11083 | Chromium: CVE-2026-11083 Inappropriate implementation in Password Manager | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11084 | Chromium: CVE-2026-11084 Inappropriate implementation in Password Manager | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11085 | Chromium: CVE-2026-11085 Integer overflow in GPU | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11086 | Chromium: CVE-2026-11086 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11087 | Chromium: CVE-2026-11087 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11088 | Chromium: CVE-2026-11088 Integer overflow in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-11089 | Chromium: CVE-2026-11089 Uninitialized Use in Media | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11090 | Chromium: CVE-2026-11090 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11091 | Chromium: CVE-2026-11091 Inappropriate implementation in Dawn | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11092 | Chromium: CVE-2026-11092 Insufficient policy enforcement in DevTools | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11093 | Chromium: CVE-2026-11093 Insufficient validation of untrusted input in Printing | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11094 | Chromium: CVE-2026-11094 Use after free in Codecs | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11095 | Chromium: CVE-2026-11095 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11096 | Chromium: CVE-2026-11096 Out of bounds read in WebRTC | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11097 | Chromium: CVE-2026-11097 Inappropriate implementation in WebView | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11098 | Chromium: CVE-2026-11098 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11099 | Chromium: CVE-2026-11099 Vulnerability in Skia | UNKNOWN | — | — | Microsoft | 2026-06-09 |
| CVE-2026-11100 | Chromium: CVE-2026-11100 Use after free in File Input | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11101 | Chromium: CVE-2026-11101 Uninitialized Use in Dawn | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11102 | Chromium: CVE-2026-11102 Inappropriate implementation in Isolated Web Apps | UNKNOWN | — | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-11103 | Chromium: CVE-2026-11103 Inappropriate implementation in Installer | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11104 | Chromium: CVE-2026-11104 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11105 | Chromium: CVE-2026-11105 Insufficient validation of untrusted input in WebUI | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11106 | Chromium: CVE-2026-11106 Inappropriate implementation in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11107 | Chromium: CVE-2026-11107 Inappropriate implementation in Downloads | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11108 | Chromium: CVE-2026-11108 Inappropriate implementation in NFC | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11109 | Chromium: CVE-2026-11109 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11110 | Chromium: CVE-2026-11110 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11111 | Chromium: CVE-2026-11111 Out of bounds read in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11112 | Chromium: CVE-2026-11112 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11113 | Chromium: CVE-2026-11113 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11114 | Chromium: CVE-2026-11114 Use after free in Device Trust | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11115 | Chromium: CVE-2026-11115 Use after free in Updater | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11116 | Chromium: CVE-2026-11116 Use after free in Chromoting | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-11117 | Chromium: CVE-2026-11117 Use after free in Views | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11118 | Chromium: CVE-2026-11118 Use after free in WebRTC | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-11119 | Chromium: CVE-2026-11119 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11120 | Chromium: CVE-2026-11120 Insufficient validation of untrusted input in Enterprise Reporting | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11121 | Chromium: CVE-2026-11121 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11122 | Chromium: CVE-2026-11122 Inappropriate implementation in Keyboard | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11123 | Chromium: CVE-2026-11123 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11124 | Chromium: CVE-2026-11124 Heap buffer overflow in Skia | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11125 | Chromium: CVE-2026-11125 Use after free in Compositing | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11126 | Chromium: CVE-2026-11126 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11127 | Chromium: CVE-2026-11127 Inappropriate implementation in WebAPKs | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11128 | Chromium: CVE-2026-11128 Insufficient validation of untrusted input in Web Share | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11129 | Chromium: CVE-2026-11129 Inappropriate implementation in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11130 | Chromium: CVE-2026-11130 Use after free in Media | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11131 | Chromium: CVE-2026-11131 Use after free in Autofill | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11132 | Chromium: CVE-2026-11132 Policy bypass in Paint | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11133 | Chromium: CVE-2026-11133 Insufficient policy enforcement in Paint | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11134 | Chromium: CVE-2026-11134 Insufficient data validation in Media | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11135 | Chromium: CVE-2026-11135 Insufficient policy enforcement in Autofill | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11136 | Chromium: CVE-2026-11136 Use after free in Canvas | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11137 | Chromium: CVE-2026-11137 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11138 | Chromium: CVE-2026-11138 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11139 | Chromium: CVE-2026-11139 Policy bypass in Paint | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11140 | Chromium: CVE-2026-11140 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11141 | Chromium: CVE-2026-11141 Uninitialized Use in Audio | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11142 | Chromium: CVE-2026-11142 Policy bypass in Paint | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11143 | Chromium: CVE-2026-11143 Heap buffer overflow in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11144 | Chromium: CVE-2026-11144 Use after free in Media | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11145 | Chromium: CVE-2026-11145 Race in Geolocation | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11146 | Chromium: CVE-2026-11146 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11147 | Chromium: CVE-2026-11147 Use after free in WebML | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11148 | Chromium: CVE-2026-11148 Inappropriate implementation in Payments | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11149 | Chromium: CVE-2026-11149 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11150 | Chromium: CVE-2026-11150 Inappropriate implementation in XML | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11151 | Chromium: CVE-2026-11151 Insufficient validation of untrusted input in Password Manager | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11152 | Chromium: CVE-2026-11152 Object lifecycle issue in Dawn | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11153 | Chromium: CVE-2026-11153 Side-channel information leakage in Forms | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11154 | Chromium: CVE-2026-11154 Use after free in Dawn | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11155 | Chromium: CVE-2026-11155 Insufficient policy enforcement in CSS | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11156 | Chromium: CVE-2026-11156 Inappropriate implementation in CSS | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11157 | Chromium: CVE-2026-11157 Script injection in Accessibility | UNKNOWN | — | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-11158 | Chromium: CVE-2026-11158 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11159 | Chromium: CVE-2026-11159 Uninitialized Use in Skia | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11160 | Chromium: CVE-2026-11160 Out of bounds read in Input | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11161 | Chromium: CVE-2026-11161 Insufficient data validation in DataTransfer | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11162 | Chromium: CVE-2026-11162 Insufficient policy enforcement in CSS | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11163 | Chromium: CVE-2026-11163 Use after free in Messages | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11164 | Chromium: CVE-2026-11164 Use after free in Blink | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11166 | Chromium: CVE-2026-11166 Inappropriate implementation in SVG | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11167 | Chromium: CVE-2026-11167 Inappropriate implementation in WebView | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11168 | Chromium: CVE-2026-11168 Insufficient policy enforcement in Extensions | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11169 | Chromium: CVE-2026-11169 Inappropriate implementation in XML | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11170 | Chromium: CVE-2026-11170 Inappropriate implementation in Chromoting | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11171 | Chromium: CVE-2026-11171 Integer overflow in Blink | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11172 | Chromium: CVE-2026-11172 Incorrect security UI in Contact Picker | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11173 | Chromium: CVE-2026-11173 Out of bounds write in V8 | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11174 | Chromium: CVE-2026-11174 Insufficient policy enforcement in Site Isolation | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11175 | Chromium: CVE-2026-11175 Incorrect security UI in Messages | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11176 | Chromium: CVE-2026-11176 Inappropriate implementation in Media | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11177 | Chromium: CVE-2026-11177 Use after free in Omnibox | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11178 | Chromium: CVE-2026-11178 Policy bypass in WebView | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11179 | Chromium: CVE-2026-11179 Inappropriate implementation in ORB | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11180 | Chromium: CVE-2026-11180 Policy bypass in SVG | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11181 | Chromium: CVE-2026-11181 Inappropriate implementation in Media Session | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11182 | Chromium: CVE-2026-11182 Inappropriate implementation in SVG | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11184 | Chromium: CVE-2026-11184 Insufficient policy enforcement in Actor | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11185 | Chromium: CVE-2026-11185 Use after free in V8 | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11186 | Chromium: CVE-2026-11186 Inappropriate implementation in CSS | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11187 | Chromium: CVE-2026-11187 Insufficient policy enforcement in Glic | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11188 | Chromium: CVE-2026-11188 Use after free in USB | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11189 | Chromium: CVE-2026-11189 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11190 | Chromium: CVE-2026-11190 Insufficient policy enforcement in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11191 | Chromium: CVE-2026-11191 Out of bounds memory access in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11192 | Chromium: CVE-2026-11192 Insufficient validation of untrusted input in Password Manager | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11193 | Chromium: CVE-2026-11193 Insufficient policy enforcement in Password Manager | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11194 | Chromium: CVE-2026-11194 Inappropriate implementation in Network | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11195 | Chromium: CVE-2026-11195 Inappropriate implementation in MHTML | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11196 | Chromium: CVE-2026-11196 Type Confusion in XML | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11197 | Chromium: CVE-2026-11197 Insufficient policy enforcement in Workers | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11198 | Chromium: CVE-2026-11198 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11199 | Chromium: CVE-2026-11199 Insufficient validation of untrusted input in WebRTC | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11200 | Chromium: CVE-2026-11200 Inappropriate implementation in WebRTC | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11201 | Chromium: CVE-2026-11201 Use after free in ServiceWorker | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11203 | Chromium: CVE-2026-11203 Policy bypass in GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11206 | Chromium: CVE-2026-11206 Policy bypass in ServiceWorker | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11207 | Chromium: CVE-2026-11207 Insufficient validation of untrusted input in Autofill | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11208 | Chromium: CVE-2026-11208 Use after free in Codecs | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11209 | Chromium: CVE-2026-11209 Insufficient policy enforcement in Passwords | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11210 | Chromium: CVE-2026-11210 Insufficient policy enforcement in Safe Browsing | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11211 | Chromium: CVE-2026-11211 Integer overflow in V8 | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11212 | Chromium: CVE-2026-11212 Insufficient policy enforcement in DevTools | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11213 | Chromium: CVE-2026-11213 Insufficient validation of untrusted input in Reading Mode | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11215 | Chromium: CVE-2026-11215 Inappropriate implementation in Cronet | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11216 | Chromium: CVE-2026-11216 Incorrect security UI in File Input | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11217 | Chromium: CVE-2026-11217 Insufficient policy enforcement in Fenced Frames | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11218 | Chromium: CVE-2026-11218 Inappropriate implementation in PlatformIntegration | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11219 | Chromium: CVE-2026-11219 Insufficient data validation in Navigation | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11220 | Chromium: CVE-2026-11220 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11221 | Chromium: CVE-2026-11221 Insufficient validation of untrusted input in PointerLock | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11222 | Chromium: CVE-2026-11222 Incorrect security UI in Tab Strip | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11223 | Chromium: CVE-2026-11223 Insufficient validation of untrusted input in Network | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11224 | Chromium: CVE-2026-11224 Use after free in Chromoting | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11225 | Chromium: CVE-2026-11225 Incorrect security UI in WebUI | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11226 | Chromium: CVE-2026-11226 Insufficient policy enforcement in PreviewTab | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11227 | Chromium: CVE-2026-11227 Incorrect security UI in Tab Hover Cards | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11228 | Chromium: CVE-2026-11228 Incorrect security UI in File Input | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11229 | Chromium: CVE-2026-11229 Insufficient policy enforcement in Enterprise | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11230 | Chromium: CVE-2026-11230 Use after free in Extensions | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11231 | Chromium: CVE-2026-11231 Inappropriate implementation in Safe Browsing | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11232 | Chromium: CVE-2026-11232 Inappropriate implementation in TabGroups | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11233 | Chromium: CVE-2026-11233 Insufficient validation of untrusted input in FoldableAPIs | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11234 | Chromium: CVE-2026-11234 Insufficient policy enforcement in FoldableAPIs | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11235 | Chromium: CVE-2026-11235 Insufficient validation of untrusted input in Compositing | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11236 | Chromium: CVE-2026-11236 Insufficient policy enforcement in Web Bluetooth | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11237 | Chromium: CVE-2026-11237 Insufficient validation of untrusted input in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11238 | Chromium: CVE-2026-11238 Inappropriate implementation in DevTools | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11239 | Chromium: CVE-2026-11239 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11240 | Chromium: CVE-2026-11240 Insufficient validation of untrusted input in Loader | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11241 | Chromium: CVE-2026-11241 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-11242 | Chromium: CVE-2026-11242 Insufficient validation of untrusted input in Plugins | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11243 | Chromium: CVE-2026-11243 Incorrect security UI in Downloads | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11244 | Chromium: CVE-2026-11244 Insufficient validation of untrusted input in WebAuthentication | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11245 | Chromium: CVE-2026-11245 Inappropriate implementation in Payments | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11246 | Chromium: CVE-2026-11246 Insufficient validation of untrusted input in IndexedDB | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11247 | Chromium: CVE-2026-11247 Insufficient policy enforcement in CustomTabs | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11248 | Chromium: CVE-2026-11248 Policy bypass in Google Lens | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11249 | Chromium: CVE-2026-11249 Use after free in Network | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11250 | Chromium: CVE-2026-11250 Inappropriate implementation in DevTools | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11251 | Chromium: CVE-2026-11251 Insufficient validation of untrusted input in Password Manager | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11252 | Chromium: CVE-2026-11252 Policy bypass in Content Settings | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11253 | Chromium: CVE-2026-11253 Race in Permissions | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11254 | Chromium: CVE-2026-11254 Inappropriate implementation in Permissions | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11255 | Chromium: CVE-2026-11255 Insufficient validation of untrusted input in Storage Access API | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11256 | Chromium: CVE-2026-11256 Out of bounds read in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11257 | Chromium: CVE-2026-11257 Inappropriate implementation in Browser | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11258 | Chromium: CVE-2026-11258 Inappropriate implementation in File System Access | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11259 | Chromium: CVE-2026-11259 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11260 | Chromium: CVE-2026-11260 Policy bypass in Permissions | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11261 | Chromium: CVE-2026-11261 Insufficient validation of untrusted input in PDF | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11262 | Chromium: CVE-2026-11262 Use after free in TabStrip | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11263 | Chromium: CVE-2026-11263 Insufficient policy enforcement in WebAuthentication | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11264 | Chromium: CVE-2026-11264 Policy bypass in Content Security Policy | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11265 | Chromium: CVE-2026-11265 Insufficient data validation in Autofill | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11266 | Chromium: CVE-2026-11266 Policy bypass in SafeBrowsing | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11267 | Chromium: CVE-2026-11267 Insufficient policy enforcement in Extensions | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11268 | Chromium: CVE-2026-11268 Uninitialized Use in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11269 | Chromium: CVE-2026-11269 Inappropriate implementation in Extensions | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11270 | Chromium: CVE-2026-11270 Inappropriate implementation in UI | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11271 | Chromium: CVE-2026-11271 Incorrect security UI in Passwords | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11273 | Chromium: CVE-2026-11273 Insufficient validation of untrusted input in Omnibox | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11275 | Chromium: CVE-2026-11275 Insufficient policy enforcement in Page Info | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11276 | Chromium: CVE-2026-11276 Inappropriate implementation in Cast | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11278 | Chromium: CVE-2026-11278 Inappropriate implementation in CustomTabs | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11279 | Chromium: CVE-2026-11279 Out of bounds read in DevTools | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-11281 | Chromium: CVE-2026-11281 Integer overflow in Chromoting | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11282 | Chromium: CVE-2026-11282 Policy bypass in Sandbox | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11283 | Chromium: CVE-2026-11283 Policy bypass in Shortcuts | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11284 | Chromium: CVE-2026-11284 Side-channel information leakage in PerformanceAPIs | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11286 | Chromium: CVE-2026-11286 Insufficient validation of untrusted input in Wallet | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11287 | Chromium: CVE-2026-11287 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11288 | Chromium: CVE-2026-11288 Policy bypass in CSS | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11289 | Chromium: CVE-2026-11289 Side-channel information leakage in Paint | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11290 | Chromium: CVE-2026-11290 Integer overflow in WebView | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11291 | Chromium: CVE-2026-11291 Policy bypass in Android Autofill | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11292 | Chromium: CVE-2026-11292 Policy bypass in Blink | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11293 | Chromium: CVE-2026-11293 Use after free in Input | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11294 | Chromium: CVE-2026-11294 Inappropriate implementation in Passwords | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11295 | Chromium: CVE-2026-11295 Inappropriate implementation in WebView | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11296 | Chromium: CVE-2026-11296 Inappropriate implementation in ImageCapture | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11297 | Chromium: CVE-2026-11297 Insufficient validation of untrusted input in Reader Mode | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11299 | Chromium: CVE-2026-11299 Out of bounds read in Fonts | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11300 | Chromium: CVE-2026-11300 Inappropriate implementation in Permissions | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11301 | Chromium: CVE-2026-11301 Out of bounds read in LiveCaption | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11303 | Chromium: CVE-2026-11303 Use after free in PDFium | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11304 | Chromium: CVE-2026-11304 Use after free in PDFium | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11305 | Chromium: CVE-2026-11305 Use after free in PDFium | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11306 | Chromium: CVE-2026-11306 Use after free in PDFium | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11307 | Chromium: CVE-2026-11307 Use after free in PDFium | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11308 | Chromium: CVE-2026-11308 Inappropriate implementation in Extensions | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11309 | Chromium: CVE-2026-11309 Insufficient policy enforcement in History | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-11628 | Chromium: CVE-2026-11628 Use after free in Ozone | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11629 | Chromium: CVE-2026-11629 Use after free in Ozone | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11630 | Chromium: CVE-2026-11630 Use after free in File Input | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11631 | Chromium: CVE-2026-11631 Use after free in Aura | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11632 | Chromium: CVE-2026-11632 Use after free in TabStrip | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11633 | Chromium: CVE-2026-11633 Use after free in Bluetooth | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11634 | Chromium: CVE-2026-11634 Use after free in Gamepad | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11635 | Chromium: CVE-2026-11635 Use after free in Bluetooth | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11636 | Chromium: CVE-2026-11636 Use after free in Autofill | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11637 | Chromium: CVE-2026-11637 Use after free in Views | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11638 | Chromium: CVE-2026-11638 Use after free in Printing | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11639 | Chromium: CVE-2026-11639 Use after free in Compositing | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11640 | Chromium: CVE-2026-11640 Integer overflow in libyuv | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11641 | Chromium: CVE-2026-11641 Use after free in Bluetooth | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11642 | Chromium: CVE-2026-11642 Use after free in Web Apps | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11643 | Chromium: CVE-2026-11643 Use after free in Proxy | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11644 | Chromium: CVE-2026-11644 Use after free in Views | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11645 | Chromium: CVE-2026-11645 Out of bounds memory access in V8 | UNKNOWN | — | 82%ile | Microsoft | 2026-06-09 |
| CVE-2026-11646 | Chromium: CVE-2026-11646 Use after free in ViewTransitions | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11647 | Chromium: CVE-2026-11647 Use after free in Printing | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11648 | Chromium: CVE-2026-11648 Use after free in FullScreen | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11649 | Chromium: CVE-2026-11649 Use after free in V8 | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-11650 | Chromium: CVE-2026-11650 Use after free in V8 | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-11651 | Chromium: CVE-2026-11651 Use after free in Network | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-11652 | Chromium: CVE-2026-11652 Use after free in Extensions | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11653 | Chromium: CVE-2026-11653 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11654 | Chromium: CVE-2026-11654 Use after free in CameraCapture | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11655 | Chromium: CVE-2026-11655 Integer overflow in Media | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11656 | Chromium: CVE-2026-11656 Use after free in ServiceWorker | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11657 | Chromium: CVE-2026-11657 Use after free in Payments | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11658 | Chromium: CVE-2026-11658 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11659 | Chromium: CVE-2026-11659 Insufficient validation of untrusted input in UI | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11660 | Chromium: CVE-2026-11660 Insufficient validation of untrusted input in New Tab Page | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11661 | Chromium: CVE-2026-11661 Use after free in Views | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11662 | Chromium: CVE-2026-11662 Type Confusion in Bindings | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-11663 | Chromium: CVE-2026-11663 Use after free in Skia | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11664 | Chromium: CVE-2026-11664 Use after free in Payments | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11665 | Chromium: CVE-2026-11665 Out of bounds read in Dawn | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11666 | Chromium: CVE-2026-11666 Insufficient validation of untrusted input in Input | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11667 | Chromium: CVE-2026-11667 Out of bounds read in WebRTC | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11668 | Chromium: CVE-2026-11668 Uninitialized Use in Codecs | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11669 | Chromium: CVE-2026-11669 Integer overflow in Media | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11670 | Chromium: CVE-2026-11670 Use after free in PDF | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11671 | Chromium: CVE-2026-11671 Use after free in Navigation | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11672 | Chromium: CVE-2026-11672 Out of bounds write in GPU | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11673 | Chromium: CVE-2026-11673 Use after free in InterestGroups | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11674 | Chromium: CVE-2026-11674 Use after free in Guest View | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11675 | Chromium: CVE-2026-11675 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11676 | Chromium: CVE-2026-11676 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11677 | Chromium: CVE-2026-11677 Race in Network | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11678 | Chromium: CVE-2026-11678 Integer overflow in libyuv | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11679 | Chromium: CVE-2026-11679 Use after free in Codecs | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11680 | Chromium: CVE-2026-11680 Use after free in Media | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11681 | Chromium: CVE-2026-11681 Use after free in Ozone | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11682 | Chromium: CVE-2026-11682 Insufficient validation of untrusted input in Views | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11683 | Chromium: CVE-2026-11683 Use after free in WebCodecs | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11684 | Chromium: CVE-2026-11684 Insufficient policy enforcement in Network | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11685 | Chromium: CVE-2026-11685 Insufficient data validation in MediaCapture | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11686 | Chromium: CVE-2026-11686 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11687 | Chromium: CVE-2026-11687 Use after free in Dawn | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11688 | Chromium: CVE-2026-11688 Object lifecycle issue in SVG | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11689 | Chromium: CVE-2026-11689 Insufficient validation of untrusted input in Passwords | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11690 | Chromium: CVE-2026-11690 Out of bounds read and write in Media | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11691 | Chromium: CVE-2026-11691 Insufficient validation of untrusted input in New Tab Page | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11692 | Chromium: CVE-2026-11692 Use after free in Read Anything | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11693 | Chromium: CVE-2026-11693 Inappropriate implementation in Plugins | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11694 | Chromium: CVE-2026-11694 Use after free in ServiceWorker | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11695 | Chromium: CVE-2026-11695 Inappropriate implementation in Passwords | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11696 | Chromium: CVE-2026-11696 Uninitialized Use in Video | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11697 | Chromium: CVE-2026-11697 Insufficient validation of untrusted input in UI | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11698 | Chromium: CVE-2026-11698 Use after free in Bluetooth | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11699 | Chromium: CVE-2026-11699 Use after free in Bluetooth | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11700 | Chromium: CVE-2026-11700 Use after free in Tracing | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11701 | Chromium: CVE-2026-11701 Insufficient validation of untrusted input in Guest View | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-12007 | Chromium: CVE-2026-12007 Use after free Core | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-12008 | Chromium: CVE-2026-12008 Use after free DigitalCredentials | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-12009 | Chromium: CVE-2026-12009 Insufficient validation of untrusted input Accessibility | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-12010 | Chromium: CVE-2026-12010 Heap buffer overflow GPU | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-12011 | Chromium: CVE-2026-12011 Use after free WebMIDI | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-12012 | Chromium: CVE-2026-12012 Use after free Network | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-12013 | Chromium: CVE-2026-12013 Use after free Media | UNKNOWN | — | — | Microsoft | 2026-06-09 |
| CVE-2026-12014 | Chromium: CVE-2026-12014 Use after free Cast | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-12015 | Chromium: CVE-2026-12015 Use after free Autofill | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-12016 | Chromium: CVE-2026-12016 Insufficient validation of untrusted input DevTools | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-12017 | Chromium: CVE-2026-12017 Insufficient validation of untrusted input Extensions | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-12018 | Chromium: CVE-2026-12018 Inappropriate implementation Mojo | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-12019 | Chromium: CVE-2026-12019 Out of bounds write Codecs | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-12028 | Chromium: CVE-2026-12028 Use after free GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-12030 | Chromium: CVE-2026-12031 Inappropriate implementation Views | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-12032 | Chromium: CVE-2026-12032 Inappropriate implementation Passwords | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-12437 | Chromium: CVE-2026-12437 Use after free in WebShare | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-12438 | Chromium: CVE-2026-12438 Inappropriate implementation in WebView | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-12439 | Chromium: CVE-2026-12439 Use after free in Digital Credentials | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-12440 | Chromium: CVE-2026-12440 Use after free in DigitalCredentials | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-12441 | Chromium: CVE-2026-12441 Use after free in File Input | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-12442 | Chromium: CVE-2026-12442 Use after free in Passwords | UNKNOWN | — | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-12443 | Chromium: CVE-2026-12443 Use after free in Web Authentication | UNKNOWN | — | 48%ile | Microsoft | 2026-06-09 |
| CVE-2026-12444 | Chromium: CVE-2026-12444 Out of bounds read in Chromoting | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12445 | Chromium: CVE-2026-12445 Use after free in Extensions | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-12446 | Chromium: CVE-2026-12446 Insufficient data validation in Passwords | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-12447 | Chromium: CVE-2026-12447 Heap buffer overflow in WebRTC | UNKNOWN | — | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-12448 | Chromium: CVE-2026-12448 Inappropriate implementation in WebView | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-12449 | Chromium: CVE-2026-12449 Use after free in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-12451 | Chromium: CVE-2026-12451 Use after free in DigitalCredentials | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-12452 | Chromium: CVE-2026-12452 Use after free in Downloads | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-12453 | Chromium: CVE-2026-12453 Insufficient validation of untrusted input in Input | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-12454 | Chromium: CVE-2026-12454 Race in Safe Browsing | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12455 | Chromium: CVE-2026-12455 Use after free in Tab Strip | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-12456 | Chromium: CVE-2026-12456 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12457 | Chromium: CVE-2026-12457 Insufficient data validation in Extensions | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-12458 | Chromium: CVE-2026-12458 Incorrect security UI in Passwords | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-12459 | Chromium: CVE-2026-12459 Inappropriate implementation in Serial | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-12460 | Chromium: CVE-2026-12460 Insufficient policy enforcement in File System Access | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-12461 | Chromium: CVE-2026-12461 Out of bounds read in WebRTC | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-12462 | Chromium: CVE-2026-12462 Use after free in Media | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-12463 | Chromium: CVE-2026-12463 Inappropriate implementation in Views | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-12464 | Chromium: CVE-2026-12464 Use after free in Browser | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-12465 | Chromium: CVE-2026-12465 Insufficient validation of untrusted input in Metrics | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-12466 | Chromium: CVE-2026-12466 Heap buffer overflow in WebRTC | UNKNOWN | — | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-12467 | Chromium: CVE-2026-12467 Use after free in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-12468 | Chromium: CVE-2026-12468 Inappropriate implementation in Updater | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12469 | Chromium: CVE-2026-12469 Uninitialized Use in GPU | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-13021 | Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentials | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-13022 | Chromium: CVE-2026-13022 Inappropriate implementation in Autofill | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-13023 | Chromium: CVE-2026-13023 Uninitialized Use in GPU | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-13024 | Chromium: CVE-2026-13024 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-13025 | Chromium: CVE-2026-13025 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-13026 | Chromium: CVE-2026-13026 Use after free in Digital Credentials | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-13027 | Chromium: CVE-2026-13027 Use after free in FileSystem | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-13029 | Chromium: CVE-2026-13029 Use after free in Web Authentication | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-13031 | Chromium: CVE-2026-13031 Use after free in Blink | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-13033 | Chromium: CVE-2026-13033 Out of bounds read in Blink>InterestGroups | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-13034 | Chromium: CVE-2026-13034 Inappropriate implementation in Passwords | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-13035 | Chromium: CVE-2026-13035 Use after free in Bluetooth | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-13036 | Chromium: CVE-2026-13036 Use after free in Blink | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-13038 | Chromium: CVE-2026-13038 Use after free in Autofill | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-46643 | Snappy: Binary path is never shell-escaped due to an inverted is_executable check | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-48854 | Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-46683 | Snappy: SSRF and local file read via the xsl-style-sheet option | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-44705 | tmp: Path Traversal via unsanitized prefix/postfix enables directory escape | UNKNOWN | — | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-47241 | Net::IMAP: Denial of Service via incomplete raw argument validation | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11979 | Stack-Based Buffer Overflow in libxml2 | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-23652 | Microsoft Power Pages Remote Code Execution Vulnerability | CRITICAL | 10.0 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution Vulnerability | CRITICAL | 10.0 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-41104 | Microsoft Planetary Computer Pro Information Disclosure Vulnerability | CRITICAL | 10.0 | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-42826 | Azure DevOps Information Disclosure Vulnerability | CRITICAL | 10.0 | 56%ile | Microsoft | 2026-05-12 |
| CVE-2026-42901 | Microsoft Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-47280 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-7374 | Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability | CRITICAL | 9.9 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-33109 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 9.9 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-40411 | Azure Virtual Network Gateway Remote Code Execution Vulnerability | CRITICAL | 9.9 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-42823 | Azure Logic Apps Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-42898 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | CRITICAL | 9.9 | 67%ile | Microsoft | 2026-05-12 |
| CVE-2025-71305 | drm/display/dp_mst: Add protection against 0 vcpi | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-31705 | ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-31718 | ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger | CRITICAL | 9.8 | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-33278 | Possible arbitrary code execution during DNSSEC validation | CRITICAL | 9.8 | 68%ile | Microsoft | 2026-05-12 |
| CVE-2026-45899 | ext4: drop extent cache when splitting extent fails | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-41089 | Windows Netlogon Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-41096 | Windows DNS Client Remote Code Execution Vulnerability | CRITICAL | 9.8 | 79%ile | Microsoft | 2026-05-12 |
| CVE-2026-33823 | Microsoft Team Events Portal Information Disclosure Vulnerability | CRITICAL | 9.6 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-35428 | Azure Cloud Shell Spoofing Vulnerability | CRITICAL | 9.6 | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-41615 | Microsoft Authenticator Information Disclosure Vulnerability | CRITICAL | 9.6 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-43870 | Apache Thrift: Node.js web_server.js multi-vulnerability | CRITICAL | 9.4 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-40379 | Azure Entra ID Spoofing Vulnerability | CRITICAL | 9.3 | 58%ile | Microsoft | 2026-05-12 |
| CVE-2026-40402 | Windows Hyper-V Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-41090 | Microsoft Copilot Tampering Vulnerability | CRITICAL | 9.3 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-39832 | Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent | CRITICAL | 9.1 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-39833 | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent | CRITICAL | 9.1 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-39834 | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-42496 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dire | CRITICAL | 9.1 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-42508 | Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts | CRITICAL | 9.1 | 94%ile | Microsoft | 2026-05-12 |
| CVE-2026-8450 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() | CRITICAL | 9.1 | 71%ile | Microsoft | 2026-05-12 |
| CVE-2026-33117 | Azure SDK for Java Security Feature Bypass Vulnerability | CRITICAL | 9.1 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-33843 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-41103 | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 92%ile | Microsoft | 2026-05-12 |
| CVE-2026-42833 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | CRITICAL | 9.1 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-33844 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 9.0 | 61%ile | Microsoft | 2026-05-12 |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | HIGH | 8.8 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-31706 | ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() | HIGH | 8.8 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-31709 | smb: client: validate the whole DACL before rewriting it in cifsacl | HIGH | 8.8 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-31717 | ksmbd: validate owner of durable handle on reconnect | HIGH | 8.8 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-43048 | HID: core: Mitigate potential OOB by removing bogus memset() | HIGH | 8.8 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-43249 | 9p/xen: protect xen_9pfs_front_free against concurrent calls | HIGH | 8.8 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-6473 | PostgreSQL server undersizes allocations, via integer wraparound | HIGH | 8.8 | 62%ile | Microsoft | 2026-05-12 |
| CVE-2026-6475 | PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice | HIGH | 8.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-6477 | PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory | HIGH | 8.8 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-6637 | PostgreSQL refint allows stack buffer overflow and SQL injection | HIGH | 8.8 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-32207 | Azure Machine Learning Notebook Spoofing Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-33110 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 80%ile | Microsoft | 2026-05-12 |
| CVE-2026-33112 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 98%ile | Microsoft | 2026-05-12 |
| CVE-2026-34329 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.8 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-35430 | Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability | HIGH | 8.8 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-35436 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 8.8 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-35439 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 80%ile | Microsoft | 2026-05-12 |
| CVE-2026-40357 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 76%ile | Microsoft | 2026-05-12 |
| CVE-2026-40365 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 60%ile | Microsoft | 2026-05-12 |
| CVE-2026-40370 | SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-40403 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 8.8 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-40420 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 8.8 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-41086 | Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability | HIGH | 8.8 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-41094 | Microsoft Data Formulator Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-05-12 |
| CVE-2026-41109 | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-41613 | Visual Studio Code Elevation of Privilege Vulnerability | HIGH | 8.8 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-45495 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 61%ile | Microsoft | 2026-05-12 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-43490 | ksmbd: validate inherited ACE SID length | HIGH | 8.8 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-35435 | Azure AI Foundry Elevation of Privilege Vulnerability | HIGH | 8.6 | 66%ile | Microsoft | 2026-05-12 |
| CVE-2026-40358 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-40361 | Microsoft Outlook and Word Remote Code Execution Vulnerability | HIGH | 8.4 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-40363 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-40364 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 91%ile | Microsoft | 2026-05-12 |
| CVE-2026-40366 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-40367 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-43493 | crypto: pcrypt - Fix handling of MAY_BACKLOG requests | HIGH | 8.4 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-4892 | CVE-2026-4892 | HIGH | 8.4 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-31712 | ksmbd: require minimum ACE size in smb_check_perm_dacl() | HIGH | 8.3 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-35438 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 8.3 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-42013 | Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name | HIGH | 8.2 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-5260 | Gnutls: gnutls: information disclosure via heap overread in rsa key exchange | HIGH | 8.2 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-33833 | Azure Machine Learning Notebook Spoofing Vulnerability | HIGH | 8.2 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-34327 | Microsoft Partner Center Spoofing Vulnerability | HIGH | 8.2 | 49%ile | Microsoft | 2026-05-12 |
| CVE-2026-31708 | smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path | HIGH | 8.1 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-31771 | Bluetooth: hci_event: move wake reason storage into validated event handlers | HIGH | 8.1 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-43618 | Rsync < 3.4.3 Integer Overflow Information Disclosure | HIGH | 8.1 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-47783 | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a | HIGH | 8.1 | 68%ile | Microsoft | 2026-05-12 |
| CVE-2026-47784 | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because me | HIGH | 8.1 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-6665 | PgBouncer buffer overflow in SCRAM | HIGH | 8.1 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-8711 | NGINX JavaScript vulnerability | HIGH | 8.1 | 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 96%ile | Microsoft | 2026-05-12 |
| CVE-2026-40415 | Windows TCP/IP Remote Code Execution Vulnerability | HIGH | 8.1 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-41105 | Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability | HIGH | 8.1 | 56%ile | Microsoft | 2026-05-12 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.1 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-45584 | Microsoft Defender Remote Code Execution Vulnerability | HIGH | 8.1 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-34332 | Windows Kernel-Mode Driver Remote Code Execution Vulnerability | HIGH | 8.0 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-40368 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.0 | 80%ile | Microsoft | 2026-05-12 |
| CVE-2026-47294 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.0 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-31694 | fuse: reject oversized dirents in page cache | HIGH | 7.8 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-31700 | net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() | HIGH | 7.8 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-31722 | usb: gadget: f_rndis: Fix net_device lifecycle with device_move | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31723 | usb: gadget: f_subset: Fix net_device lifecycle with device_move | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31724 | usb: gadget: f_eem: Fix net_device lifecycle with device_move | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31725 | usb: gadget: f_ecm: Fix net_device lifecycle with device_move | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-40034 | gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule | HIGH | 7.8 | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-41054 | Missing exit out of permission check in haveged could lead to root exploit | HIGH | 7.8 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-43009 | bpf: Fix incorrect pruning due to atomic fetch precision tracking | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43019 | Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43033 | crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43059 | Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43125 | dlm: validate length in dlm_search_rsb_tree | HIGH | 7.8 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-43258 | alpha: fix user-space corruption during memory compaction | HIGH | 7.8 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43284 | xfrm: esp: avoid in-place decrypt on shared skb frags | HIGH | 7.8 | 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-43298 | drm/amdgpu: Skip vcn poison irq release on VF | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43321 | bpf: Properly mark live registers for indirect jumps | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43353 | i3c: mipi-i3c-hci: Fix race in DMA ring dequeue | HIGH | 7.8 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43497 | fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43499 | rtmutex: Use waiter::task instead of current in remove_waiter() | HIGH | 7.8 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-43500 | rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present | HIGH | 7.8 | 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-45958 | drm/exynos: vidi: fix to avoid directly dereferencing user pointer | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46150 | fanotify: fix false positive on permission events | HIGH | 7.8 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46242 | eventpoll: fix ep_remove struct eventpoll / struct file UAF | HIGH | 7.8 | 87%ile | Microsoft | 2026-05-12 |
| CVE-2026-46300 | net: skbuff: preserve shared-frag marker during coalescing | HIGH | 7.8 | 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-32204 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-33834 | Windows Event Logging Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-33835 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 81%ile | Microsoft | 2026-05-12 |
| CVE-2026-33837 | Windows TCP/IP Local Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-05-12 |
| CVE-2026-33838 | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-33840 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 80%ile | Microsoft | 2026-05-12 |
| CVE-2026-33841 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-34330 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-34333 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-34334 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-34336 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-34337 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-34338 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-34343 | Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-34344 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-34351 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.8 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-35415 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-35417 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-35418 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-35420 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-35421 | Windows GDI Remote Code Execution Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-40359 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-40360 | Microsoft Excel Information Disclosure Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-40362 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-40369 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 91%ile | Microsoft | 2026-05-12 |
| CVE-2026-40377 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-40381 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-40382 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-40397 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-40398 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 83%ile | Microsoft | 2026-05-12 |
| CVE-2026-40399 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-40407 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-40408 | Windows WAN ARP Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-40417 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-40418 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-40419 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-41088 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-41095 | Data Deduplication Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-41611 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-42831 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-42834 | Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-42896 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-31721 | usb: gadget: f_hid: move list and spinlock inits from bind to alloc | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-31702 | f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-48864 | Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data | HIGH | 7.8 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-46191 | fbcon: Avoid OOB font access if console rotation fails | HIGH | 7.7 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-9804 | Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read | HIGH | 7.7 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-26147 | Azure Stack HCI Information Disclosure Vulnerability | HIGH | 7.7 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-33821 | Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability | HIGH | 7.7 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-42832 | Microsoft Office Spoofing Vulnerability | HIGH | 7.7 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-29169 | Apache HTTP Server: mod_dav_lock indirect lock crash | HIGH | 7.5 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-3039 | BIND 9 server memory exhaustion during GSS-API TKEY negotiation | HIGH | 7.5 | 63%ile | Microsoft | 2026-05-12 |
| CVE-2026-31711 | smb: server: fix active_num_conn leak on transport allocation failure | HIGH | 7.5 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-33811 | Crash when handling long CNAME response in net | HIGH | 7.5 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-33814 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | HIGH | 7.5 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-33846 | Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly | HIGH | 7.5 | 68%ile | Microsoft | 2026-05-12 |
| CVE-2026-34059 | Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data() | HIGH | 7.5 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-37457 | An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of F | HIGH | 7.5 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-37459 | An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v | HIGH | 7.5 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-39820 | Quadratic string concatentation in consumeComment in net/mail | HIGH | 7.5 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | HIGH | 7.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-39836 | Panic in Dial and LookupPort when handling NUL byte on Windows in net | HIGH | 7.5 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-41292 | Long list of incoming EDNS options degrades performance | HIGH | 7.5 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-42009 | Gnutls: gnutls: denial of service via dtls packet reordering vulnerability | HIGH | 7.5 | 70%ile | Microsoft | 2026-05-12 |
| CVE-2026-42151 | Prometheus Azure AD remote write OAuth client secret exposed via config API | HIGH | 7.5 | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-42154 | Prometheus: remote read endpoint allows denial of service via crafted snappy payload | HIGH | 7.5 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-42304 | Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains | HIGH | 7.5 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-42497 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directo | HIGH | 7.5 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-42499 | Quadratic string concatenation in consumePhrase in net/mail | HIGH | 7.5 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-42501 | Malicious module proxy can bypass checksum database in cmd/go | HIGH | 7.5 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-42944 | Heap overflow with multiple NSID, COOKIE, PADDING EDNS options | HIGH | 7.5 | 56%ile | Microsoft | 2026-05-12 |
| CVE-2026-42959 | Crash during DNSSEC validation of malicious content | HIGH | 7.5 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-44673 | libyang: lyb_read_string() integer overflow → heap buffer overflow | HIGH | 7.5 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-45850 | ipvs: skip ipv6 extension headers for csum checks | HIGH | 7.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46009 | PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown | HIGH | 7.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46054 | selinux: fix overlayfs mmap() and mprotect() access checks | HIGH | 7.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | HIGH | 7.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-4890 | CVE-2026-4890 | HIGH | 7.5 | 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-48959 | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward | HIGH | 7.5 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-5946 | Invalid handling of CLASS != IN | HIGH | 7.5 | 78%ile | Microsoft | 2026-05-12 |
| CVE-2026-5947 | SIG(0) validation during query flood may lead to undefined behavior | HIGH | 7.5 | 71%ile | Microsoft | 2026-05-12 |
| CVE-2026-6276 | stale custom cookie host causes cookie leak | HIGH | 7.5 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-6479 | PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion | HIGH | 7.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-6664 | PgBouncer integer overflow in PgBouncer network packet parsing | HIGH | 7.5 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-8177 | XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing trunc | HIGH | 7.5 | 49%ile | Microsoft | 2026-05-12 |
| CVE-2026-23663 | Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability | HIGH | 7.5 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-26129 | M365 Copilot Information Disclosure Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-05-12 |
| CVE-2026-26164 | M365 Copilot Information Disclosure Vulnerability | HIGH | 7.5 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-32161 | Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability | HIGH | 7.5 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-33111 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-05-12 |
| CVE-2026-35424 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-05-12 |
| CVE-2026-40405 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-05-12 |
| CVE-2026-40406 | Windows TCP/IP Information Disclosure Vulnerability | HIGH | 7.5 | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-42899 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 84%ile | Microsoft | 2026-05-12 |
| CVE-2026-31704 | ksmbd: use check_add_overflow() to prevent u16 DACL size overflow | HIGH | 7.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-5773 | wrong reuse of SMB connection | HIGH | 7.5 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-9538 | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar heade | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-3593 | Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation | HIGH | 7.4 | 74%ile | Microsoft | 2026-05-12 |
| CVE-2026-48526 | PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed | HIGH | 7.4 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-40413 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.4 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-40414 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.4 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-41107 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-42893 | Microsoft Outlook for iOS Tampering Vulnerability | HIGH | 7.4 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-42011 | Gnutls: gnutls: security bypass due to incorrect name constraint handling | HIGH | 7.4 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-2291 | CVE-2026-2291 | HIGH | 7.3 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-29168 | Apache HTTP Server: mod_md unrestricted OCSP response | HIGH | 7.3 | 49%ile | Microsoft | 2026-05-12 |
| CVE-2026-45894 | iommu/vt-d: Clear Present bit before tearing down PASID entry | HIGH | 7.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45932 | bpf: Fix tcx/netkit detach permissions when prog fd isn't given | HIGH | 7.3 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45993 | LoongArch: Add spectre boundry for syscall dispatch table | HIGH | 7.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46006 | drm/nouveau: fix u32 overflow in pushbuf reloc bounds check | HIGH | 7.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46033 | crypto: authencesn - reject short ahash digests during instance creation | HIGH | 7.3 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46130 | dm-verity-fec: fix reading parity bytes split across blocks (take 3) | HIGH | 7.3 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46145 | RDMA/mana: Validate rx_hash_key_len | HIGH | 7.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-48962 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled ou | HIGH | 7.3 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-5172 | CVE-2026-5172 | HIGH | 7.3 | 85%ile | Microsoft | 2026-05-12 |
| CVE-2026-7598 | libssh2 userauth.c userauth_password integer overflow | HIGH | 7.3 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-32177 | .NET Elevation of Privilege Vulnerability | HIGH | 7.3 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-35433 | .NET Elevation of Privilege Vulnerability | HIGH | 7.3 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-43869 | Apache Thrift: TSSLTransportFactory.java hostname verification | HIGH | 7.3 | 49%ile | Microsoft | 2026-05-12 |
| CVE-2025-71289 | fs/ntfs3: handle attr_set_size() errors when truncating files | HIGH | 7.1 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-31697 | crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-31698 | crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-31699 | crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-31707 | ksmbd: validate response sizes in ipc_validate_msg() | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-42010 | Gnutls: gnutls: authentication bypass via nul character in username | HIGH | 7.1 | 63%ile | Microsoft | 2026-05-12 |
| CVE-2026-42012 | Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans | HIGH | 7.1 | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-43042 | mpls: add seqcount to protect the platform_label{,s} pair | HIGH | 7.1 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43088 | net: af_key: zero aligned sockaddr tail in PF_KEY exports | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43109 | x86: shadow stacks: proper error handling for mmap lock | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43116 | netfilter: ctnetlink: ensure safe access to master conntrack | HIGH | 7.1 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43153 | xfs: remove xfs_attr_leaf_hasname | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43195 | drm/amdgpu: validate user queue size constraints | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43219 | net: cpsw_new: Fix potential unregister of netdev that has not been registered yet | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43245 | ntfs: ->d_compare() must not block | HIGH | 7.1 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-43248 | vhost: move vdpa group bound check to vhost_vdpa | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43250 | usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43274 | mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43318 | drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45839 | bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45861 | gfs2: Fix slab-use-after-free in qd_put | HIGH | 7.1 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-45912 | ext4: don't cache extent during splitting extent | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45956 | drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45991 | udf: fix partition descriptor append bookkeeping | HIGH | 7.1 | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-46047 | net: qrtr: ns: Fix use-after-free in driver remove() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46056 | Bluetooth: hci_event: fix potential UAF in SSP passkey handlers | HIGH | 7.1 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-46062 | ntfs3: fix integer overflow in run_unpack() volume boundary check | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46069 | wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46072 | ntfs3: add buffer boundary checks to run_unpack() | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46080 | ocfs2: split transactions in dio completion to avoid credit exhaustion | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46084 | RDMA/mana_ib: Disable RX steering on RSS QP destroy | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46091 | media: rc: igorplugusb: heed coherency rules | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46094 | ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46099 | net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels | HIGH | 7.1 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-46112 | RDMA/hns: Fix unlocked call to hns_roce_qp_remove() | HIGH | 7.1 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46122 | wifi: b43: enforce bounds check on firmware key index in b43_rx() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46146 | ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46174 | x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46177 | ipmi: Add limits to event and receive message requests | HIGH | 7.1 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-46193 | xfrm: ah: account for ESN high bits in async callbacks | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46197 | drm/amdkfd: validate SVM ioctl nattr against buffer size | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46204 | drm/amdgpu/vcn4: Prevent OOB reads when parsing IB | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46225 | spi: rspi: fix controller deregistration | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46226 | spi: fsl: fix controller deregistration | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46227 | sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL | HIGH | 7.1 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46229 | drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46230 | drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46231 | batman-adv: bla: put backbone reference on failed claim hash insert | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46233 | batman-adv: bla: only purge non-released claims | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-40401 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.1 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-41101 | Microsoft Word for Android Spoofing Vulnerability | HIGH | 7.1 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-41102 | Microsoft PowerPoint for Android Spoofing Vulnerability | HIGH | 7.1 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-43058 | media: vidtv: fix pass-by-value structs causing MSAN warnings | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43228 | hfs: Replace BUG_ON with error handling for CNID count checks | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-29518 | Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write | HIGH | 7.0 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-31729 | usb: typec: ucsi: validate connector number in ucsi_notify_common() | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-31777 | ALSA: ctxfi: Check the error for index mapping | HIGH | 7.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43037 | ip6_tunnel: clear skb2->cb[] in ip4ip6_err() | HIGH | 7.0 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-43049 | HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43052 | wifi: mac80211: check tdls flag in ieee80211_tdls_oper | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43083 | net: ioam6: fix OOB and missing lock | HIGH | 7.0 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-43101 | ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() | HIGH | 7.0 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-43198 | tcp: fix potential race in tcp_v6_syn_recv_sock() | HIGH | 7.0 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-43199 | net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query | HIGH | 7.0 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-43213 | wifi: rtw89: pci: validate sequence number of TX release report | HIGH | 7.0 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-43303 | mm/page_alloc: clear page->private in free_pages_prepare() | HIGH | 7.0 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-43306 | bpf: crypto: Use the correct destructor kfunc type | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43501 | ipv6: rpl: reserve mac_len headroom when recompressed SRH grows | HIGH | 7.0 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-43503 | net: skbuff: propagate shared-frag marker through frag-transfer helpers | HIGH | 7.0 | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-45840 | openvswitch: cap upcall PID array size and pre-size vport replies | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45859 | netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation | HIGH | 7.0 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-45892 | ext4: drop extent cache after doing PARTIAL_VALID1 zeroout | HIGH | 7.0 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-45934 | btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45940 | net: stmmac: fix oops when split header is enabled | HIGH | 7.0 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-45942 | ext4: fix e4b bitmap inconsistency reports | HIGH | 7.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-45998 | rxrpc: Fix potential UAF after skb_unshare() failure | HIGH | 7.0 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46017 | mm: fix deferred split queue races during migration | HIGH | 7.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46032 | KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46043 | RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv | HIGH | 7.0 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-46052 | ceph: only d_add() negative dentries when they are unhashed | HIGH | 7.0 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-46053 | net: rds: fix MR cleanup on copy error | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46076 | KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46086 | net: bridge: use a stable FDB dst snapshot in RCU readers | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46090 | ALSA: aloop: Fix peer runtime UAF during format-change stop | HIGH | 7.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46114 | RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads | HIGH | 7.0 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46119 | libceph: Fix slab-out-of-bounds access in auth message processing | HIGH | 7.0 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-33839 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-34331 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-34340 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-34341 | Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-34342 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-34345 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-34347 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-35416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 75%ile | Microsoft | 2026-05-12 |
| CVE-2026-40410 | Windows SMB Client Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-42825 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-43176 | wifi: rtw89: pci: validate release report content before using for RTL8922DE | HIGH | 7.0 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-43267 | wifi: rtw89: fix potential zero beacon interval in beacon tracking | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46121 | mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45585 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 70%ile | Microsoft | 2026-05-12 |
| CVE-2026-21530 | Windows Rich Text Edit Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-32170 | Windows Rich Text Edit Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-41097 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 72%ile | Microsoft | 2026-05-12 |
| CVE-2026-45130 | Vim: Heap Buffer Overflow in spell file loading | MEDIUM | 6.6 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-45930 | net: mctp: ensure our nlmsg responses are initialised | MEDIUM | 6.6 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46209 | drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() | MEDIUM | 6.6 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46220 | drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission | MEDIUM | 6.6 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-24072 | Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-25680 | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | MEDIUM | 6.5 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-33523 | Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line | MEDIUM | 6.5 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-37458 | Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat | MEDIUM | 6.5 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh | MEDIUM | 6.5 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-40460 | NGINX ngx_quic_module vulnerability | MEDIUM | 6.5 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-41401 | libyang - Heap Use-After-Free Write in XML Metadata Parsing | MEDIUM | 6.5 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-42946 | NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-43620 | Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files() | MEDIUM | 6.5 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-44283 | etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks | MEDIUM | 6.5 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-5545 | wrong reuse of HTTP Negotiate connection | MEDIUM | 6.5 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-6478 | PostgreSQL discloses MD5-hashed passwords via covert timing channel | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-9149 | Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-9150 | Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums | MEDIUM | 6.5 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-34350 | Windows Storport Miniport Driver Denial of Service Vulnerability | MEDIUM | 6.5 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-35422 | Windows TCP/IP Driver Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-40374 | Microsoft Power Automate Desktop Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-42827 | M365 Copilot Information Disclosure Vulnerability | MEDIUM | 6.5 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-42830 | Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-42891 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 6.5 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-43495 | net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler | MEDIUM | 6.5 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-39828 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh | MEDIUM | 6.3 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-43619 | Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls | MEDIUM | 6.3 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-41610 | Visual Studio Code Security Feature Bypass Vulnerability | MEDIUM | 6.3 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-43894 | jq: Wild stack write via signed-integer overflow in decNumber D2U() macro | MEDIUM | 6.2 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-43896 | jq: Stack Overflow in Recursive Object Merge | MEDIUM | 6.2 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-40380 | Windows Volume Manager Extension Driver Remote Code Execution Vulnerability | MEDIUM | 6.2 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-41614 | M365 Copilot for Desktop Spoofing Vulnerability | MEDIUM | 6.2 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-23679 | libusb < 1.0.30 NULL Pointer Dereference in parse_interface() | MEDIUM | 6.2 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-25681 | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-27136 | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-39823 | Bypass of meta content URL escaping causes XSS in html/template | MEDIUM | 6.1 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-39826 | Escaper bypass leads to XSS in html/template | MEDIUM | 6.1 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-42502 | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-42506 | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-44708 | Mistune Math Plugin XSS Escape Bypass | MEDIUM | 6.1 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-44897 | Mistune Heading ID Attribute Injection XSS | MEDIUM | 6.1 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-44898 | Mistune TOC Anchor Injection XSS | MEDIUM | 6.1 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-45989 | of: unittest: fix use-after-free in testdrv_probe() | MEDIUM | 6.1 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46116 | xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46149 | scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() | MEDIUM | 6.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46160 | btrfs: fix missing last_unlink_trans update when removing a directory | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46199 | drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46218 | drm/amdgpu: Add bounds checking to ib_{get,set}_value | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-34956 | Openvswitch: open vswitch: denial of service via malformed ftp epasv command | MEDIUM | 5.9 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-39817 | Invoking "go tool pack" does not sanitize output paths in cmd/go | MEDIUM | 5.9 | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-44608 | Use after free and crash under special conditions in RPZ code | MEDIUM | 5.9 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-4873 | connection reuse ignores TLS requirement | MEDIUM | 5.9 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-6253 | proxy credentials leak over redirect-to proxy | MEDIUM | 5.9 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-6666 | PgBouncer crash in kill_pool_logins_server_error | MEDIUM | 5.9 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-8376 | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed strin | MEDIUM | 5.7 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2025-15649 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-71272 | most: core: fix resource leak in most_register_interface error paths | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-71273 | wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2025-71285 | net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-71290 | misc: ti_fpc202: fix a potential memory leak in probe function | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2025-71293 | drm/amdgpu/ras: Move ras data alloc before bad page check | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-71294 | drm/amdgpu: fix NULL pointer issue buffer funcs | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-71299 | spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31696 | rxrpc: Fix missing validation of ticket length in non-XDR key preparsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-31715 | f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31767 | drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-41256 | jq: Embedded NUL truncates top-level jq programs loaded with -f | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-43010 | bpf: Reject sleepable kprobe_multi programs at attach time | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43029 | mptcp: fix soft lockup in mptcp_recvmsg() | MEDIUM | 5.5 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-43036 | net: use skb_header_pointer() for TCPv4 GSO frag_off check | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43053 | xfs: close crash window in attr dabtree inactivation | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-05-12 |
| CVE-2026-43107 | xfrm: account XFRMA_IF_ID in aevent size calculation | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43115 | srcu: Use irq_work to start GP in tiny SRCU | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43118 | btrfs: fix zero size inode with non-zero size after log replay | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43119 | Bluetooth: hci_sync: annotate data-races around hdev->req_status | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43126 | ALSA: mixer: oss: Add card disconnect checkpoints | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43127 | ntfs3: fix circular locking dependency in run_unpack_ex | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43129 | ima: verify the previous kernel's IMA buffer lies in addressable RAM | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43131 | drm/amd/pm: Fix null pointer dereference issue | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43137 | ASoC: SOF: Intel: hda: Fix NULL pointer dereference | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43161 | iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43165 | hwmon: (nct7363) Fix a resource leak in nct7363_present_pwm_fanin | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43172 | wifi: iwlwifi: fix 22000 series SMEM parsing | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-43185 | ksmbd: fix signededness bug in smb_direct_prepare_negotiation() | MEDIUM | 5.5 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-43191 | drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43197 | netconsole: avoid OOB reads, msg is not nul-terminated | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-43201 | APEI/GHES: ARM processor Error: don't go past allocated memory | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43204 | ASoC: qcom: q6asm: drop DSP responses for closed data streams | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43216 | net: Drop the lock in skb_may_tx_timestamp() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43220 | iommu/amd: serialize sequence allocation under concurrent TLB invalidations | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43234 | team: avoid NETDEV_CHANGEMTU event when unregistering slave | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43237 | drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43243 | drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43244 | kcm: fix zero-frag skb in frag_list on partial sendmsg error | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43292 | mm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43294 | drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43299 | btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43300 | drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43305 | drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-05-12 |
| CVE-2026-43308 | btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43309 | md raid: fix hang when stopping arrays with metadata through dm-raid | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43310 | media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43311 | soc/tegra: pmc: Fix unsafe generic_handle_irq() call | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43319 | spi: spidev: fix lock inversion between spi_lock and buf_lock | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43331 | x86/kexec: Disable KCOV instrumentation after load_segments() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43338 | btrfs: reserve enough transaction items for qgroup ioctls | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43344 | perf/x86/intel/uncore: Fix die ID init and look up bugs | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43352 | i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43414 | scsi: qla2xxx: Completely fix fcport double free | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-43456 | bonding: fix type confusion in bond_setup_by_slave() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-43464 | net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-43465 | net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-43491 | net: qrtr: ns: Limit the maximum server registration per node | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43492 | lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-43494 | net/rds: reset op_nents when zerocopy page pin fails | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-43496 | net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43502 | net/rds: handle zerocopy send cleanup before the message is queued | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45834 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45835 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45836 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45838 | bpf: fix end-of-list detection in cgroup_storage_get_next_key() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45841 | netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45842 | slip: reject VJ receive packets on instances with no rstate array | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45843 | slip: bound decode() reads against the compressed packet length | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-45844 | netfilter: arp_tables: fix IEEE1394 ARP payload parsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45845 | net/sched: taprio: fix NULL pointer dereference in class dump | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45846 | bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45855 | ata: libata-scsi: avoid Non-NCQ command starvation | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-45858 | ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-45877 | HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-45897 | netfilter: nft_counter: serialize reset with spinlock | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-45901 | netfilter: nf_tables: revert commit_mutex usage in reset path | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-45917 | ipvs: do not keep dest_dst if dev is going down | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45943 | erofs: fix inline data read failure for ztailpacking pclusters | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45944 | iommu/vt-d: Clear Present bit before tearing down context entry | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45949 | hwrng: core - use RCU and work_struct to fix race condition | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-05-12 |
| CVE-2026-45961 | gfs2: fix memory leaks in gfs2_fill_super error path | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45963 | ASoC: nau8821: Cancel delayed work on component remove | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45973 | RDMA/mlx5: Fix UMR hang in LAG error state unload | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-45987 | KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45988 | rxrpc: Fix re-decryption of RESPONSE packets | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-45994 | ibmasm: fix OOB reads in command_file_write due to missing size checks | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45996 | spi: imx: fix use-after-free on unbind | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45997 | scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45999 | erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46000 | rxrpc: Fix conn-level packet handling to unshare RESPONSE packets | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46002 | ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46003 | net: qrtr: ns: Limit the total number of nodes | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46005 | xfs: fix a resource leak in xfs_alloc_buftarg() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46012 | rxrpc: Fix memory leaks in rxkad_verify_response() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46014 | KVM: SVM: Add missing save/restore handling of LBR MSRs | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46015 | tcp: call sk_data_ready() after listener migration | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46016 | remoteproc: xlnx: Only access buffer information if IPI is buffered | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46018 | ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-46019 | crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46022 | misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46024 | libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-46026 | net: qrtr: ns: Limit the maximum number of lookups | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46027 | net/smc: avoid early lgr access in smc_clc_wait_msg | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-46031 | net: ks8851: Reinstate disabling of BHs around IRQ handler | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-46037 | ipv4: icmp: validate reply type before using icmp_pointers | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-46038 | net: qrtr: ns: Free the node during ctrl_cmd_bye() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46040 | inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46046 | ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46048 | ALSA: caiaq: fix usb_dev refcount leak on probe failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46049 | ALSA: ctxfi: Add fallback to default RSR for S/PDIF | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46050 | md/raid10: fix deadlock with check operation and nowait requests | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46051 | md/raid5: fix soft lockup in retry_aligned_read() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46058 | media: amphion: Fix race between m2m job_abort and device_run | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46059 | KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46063 | x86/shstk: Prevent deadlock during shstk sigreturn | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46064 | ibmasm: fix heap over-read in ibmasm_send_i2o_message() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46065 | fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46066 | ceph: fix num_ops off-by-one when crypto allocation fails | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46068 | crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46070 | md/raid5: validate payload size before accessing journal metadata | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46071 | KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46075 | crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46077 | crypto: atmel-tdes - fix DMA sync direction | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46078 | erofs: fix the out-of-bounds nameoff handling for trailing dirents | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46079 | rbd: fix null-ptr-deref when device_add_disk() fails | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46082 | KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46083 | spi: fix resource leaks on device setup failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46085 | rxrpc: Fix rxkad crypto unalignment handling | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-46088 | ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46089 | zram: do not forget to endio for partial discard requests | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46092 | wifi: rtw88: check for PCI upstream bridge existence | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46098 | net: caif: clear client service pointer on teardown | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46101 | netfilter: reject zero shift in nft_bitwise | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46102 | net: strparser: fix skb_head leak in strp_abort_strp() | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-46103 | can: ucan: fix devres lifetime | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46106 | eventfs: Hold eventfs_mutex and SRCU when remount walks events | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46107 | dm-thin: fix metadata refcount underflow | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46108 | ipmi:si: Return state to normal if message allocation fails | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46109 | usb: ulpi: fix memory leak on ulpi_register() error paths | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46111 | Bluetooth: hci_conn: fix potential UAF in create_big_sync | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46113 | KVM: x86: Fix shadow paging use-after-free due to unexpected GFN | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-46115 | block: add pgmap check to biovec_phys_mergeable | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-46120 | ip6_gre: Use cached t->net in ip6erspan_changelink(). | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46124 | isofs: validate block number from NFS file handle in isofs_export_iget | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-46125 | wifi: mac80211: remove station if connection prep fails | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-46127 | RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46128 | ipmi: Check event message buffer response for bad data | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46129 | btrfs: fix double free in create_space_info() error path | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46131 | KVM: x86: check for nEPT/nNPT in slow flush hypercalls | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46132 | net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46133 | RDMA/rxe: Reject unknown opcodes before ICRC processing | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-46135 | nvmet-tcp: fix race between ICReq handling and queue teardown | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-46136 | wifi: mt76: mt7921: fix a potential clc buffer length underflow | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46137 | mptcp: pm: ADD_ADDR rtx: fix potential data-race | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-46138 | Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-46140 | Bluetooth: btmtk: validate WMT event SKB length before struct access | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46142 | net: libwx: fix VF illegal register access | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46144 | RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46147 | KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46151 | usb: usblp: fix heap leak in IEEE 1284 device ID via short response | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46152 | wifi: mac80211: drop stray 'static' from fast-RX rx_result | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46153 | 8021q: delete cleared egress QoS mappings | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46155 | smb/client: fix out-of-bounds read in smb2_compound_op() | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46156 | LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46158 | mptcp: pm: ADD_ADDR rtx: always decrease sk refcount | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46159 | btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46161 | md/raid10: fix divide-by-zero in setup_geo() with zero far_copies | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46163 | wifi: b43legacy: enforce bounds check on firmware key index in RX path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46164 | btrfs: fix double free in create_space_info_sub_group() error path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46165 | openvswitch: vport: fix self-deadlock on release of tunnel ports | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46167 | usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46168 | mptcp: fix scheduling with atomic in timestamp sockopt | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46170 | mptcp: pm: ADD_ADDR rtx: free sk if last | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46171 | riscv: kvm: fix vector context allocation leak | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46172 | ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46173 | exit: prevent preemption of oopsing TASK_DEAD task | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46175 | f2fs: fix fsck inconsistency caused by FGGC of node block | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46176 | RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46178 | RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46180 | wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46181 | RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46185 | smb/client: fix out-of-bounds read in symlink_data() | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-46186 | Bluetooth: virtio_bt: validate rx pkt_type header length | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46187 | wifi: rsi: fix kthread lifetime race between self-exit and external-stop | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46189 | RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46190 | mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46195 | smb: client: validate dacloffset before building DACL pointers | MEDIUM | 5.5 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-46196 | tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46198 | batman-adv: fix integer overflow on buff_pos | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-46200 | spi: mpc52xx: fix controller deregistration | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46205 | staging: media: atomisp: Disallow all private IOCTLs | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46206 | batman-adv: reject new tp_meter sessions during teardown | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46208 | batman-adv: stop tp_meter sessions during mesh teardown | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46212 | batman-adv: bla: prevent use-after-free when deleting claims | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-46214 | vsock/virtio: fix accept queue count leak on transport mismatch | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46219 | spi: mpc52xx: fix use-after-free on unbind | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46234 | vsock: fix buffer size clamping order | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46236 | media: rc: xbox_remote: heed DMA restrictions | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46238 | batman-adv: stop caching unowned originator pointers in BAT IV | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-46241 | spi: mpc52xx: fix use-after-free on registration failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46333 | ptrace: slightly saner 'get_dumpable()' logic | MEDIUM | 5.5 | 73%ile | Microsoft | 2026-05-12 |
| CVE-2026-32185 | Microsoft Teams Spoofing Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-34339 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-35419 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-35440 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-41612 | Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-46235 | media: saa7164: add ioremap return checks and cleanups | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46157 | ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43022 | Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43416 | powerpc, perf: Check that current->mm is alive before getting user callchain | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46148 | spi: microchip-core-qspi: control built-in cs manually | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46179 | ASoC: SOF: Don't allow pointer operations on unconfigured streams | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46184 | sound: ua101: fix division by zero at probe | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45571 | go-git: Crafted repositories may modify main and submodule .git directories | MEDIUM | 5.4 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-6472 | PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege | MEDIUM | 5.4 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-35423 | Windows 11 Telnet Client Information Disclosure Vulnerability | MEDIUM | 5.4 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-42838 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | MEDIUM | 5.4 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-45494 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-32792 | Packet of death with DNSCrypt | MEDIUM | 5.3 | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-33007 | Apache HTTP Server: mod_authn_socache crash | MEDIUM | 5.3 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-33857 | Apache HTTP Server: Off-by-one OOB reads in AJP getter functions | MEDIUM | 5.3 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-34032 | Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) | MEDIUM | 5.3 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-3592 | Amplification vulnerabilities via self-pointed glue records | MEDIUM | 5.3 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-39819 | Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go | MEDIUM | 5.3 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-39825 | ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | MEDIUM | 5.3 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | MEDIUM | 5.3 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-42015 | Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling | MEDIUM | 5.3 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-42534 | Jostle logic bypass degrades resolution performance | MEDIUM | 5.3 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-42923 | Degradation of service with unbounded NSEC3 hash calculations | MEDIUM | 5.3 | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-44390 | Unbounded name compression in certain cases causes degradation of service | MEDIUM | 5.3 | 49%ile | Microsoft | 2026-05-12 |
| CVE-2026-46598 | Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent | MEDIUM | 5.3 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-48525 | PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS | MEDIUM | 5.3 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-4891 | CVE-2026-4891 | MEDIUM | 5.3 | 93%ile | Microsoft | 2026-05-12 |
| CVE-2026-4893 | CVE-2026-4893 | MEDIUM | 5.3 | 77%ile | Microsoft | 2026-05-12 |
| CVE-2026-5950 | Unbounded resend loop in BIND 9 resolver | MEDIUM | 5.3 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-6429 | netrc credential leak with reused proxy connection | MEDIUM | 5.3 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-7009 | OCSP stapling bypass with Apple SecTrust | MEDIUM | 5.3 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-7168 | cross-proxy Digest auth state leak | MEDIUM | 5.3 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-8368 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect | MEDIUM | 5.3 | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-8723 | qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly | MEDIUM | 5.3 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-6402 | webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins | MEDIUM | 5.3 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-43868 | Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern | MEDIUM | 5.3 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-33006 | Apache HTTP Server: mod_auth_digest timing attack | MEDIUM | 4.8 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-40701 | NGINX ngx_http_ssl_module vulnerability | MEDIUM | 4.8 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-42934 | NGINX ngx_http_charset_module vulnerability | MEDIUM | 4.8 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-43617 | Rsync < 3.4.3 Authorization Bypass via Hostname Resolution | MEDIUM | 4.8 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-44839 | RabbitMQ: Unsanitized vhost names allow for XSS in management UI | MEDIUM | 4.8 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-6324 | Libsoup: libsoup: http request smuggling via unsigned to signed conversion error | MEDIUM | 4.8 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-44899 | Mistune Image Directive CSS Injection Vulnerability | MEDIUM | 4.7 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-46011 | media: mtk-jpeg: fix use-after-free in release path due to uncancelled work | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46110 | net: stmmac: Prevent NULL deref when RX memory exhausted | MEDIUM | 4.7 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-46021 | thermal: core: Fix thermal zone governor cleanup issues | MEDIUM | 4.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43895 | jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published art | MEDIUM | 4.4 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-45986 | crypto: ccree - fix a memory leak in cc_mac_digest() | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-32209 | Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability | MEDIUM | 4.4 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-41100 | Microsoft 365 Copilot for Android Spoofing Vulnerability | MEDIUM | 4.4 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-45736 | ws: Uninitialized memory disclosure | MEDIUM | 4.4 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-10028 | Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificat | MEDIUM | 4.3 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-6474 | PostgreSQL timeofday() can disclose portions of server memory | MEDIUM | 4.3 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-6667 | PgBouncer missing authorization check in KILL_CLIENT admin command | MEDIUM | 4.3 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-32175 | .NET Core Tampering Vulnerability | MEDIUM | 4.3 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-35429 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 4.3 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-40416 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 4.3 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-40421 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 4.3 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-48522 | PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes | MEDIUM | 4.2 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-46004 | ALSA: caiaq: Handle probe errors properly | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | MEDIUM | 4.0 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-47104 | libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array() | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46232 | HID: playstation: Clamp num_touch_reports | MEDIUM | 4.0 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-46194 | f2fs: fix node_cnt race between extent node destroy and writeback | MEDIUM | 4.0 | — | Microsoft | 2026-05-12 |
| CVE-2026-46143 | ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46169 | hfsplus: fix uninit-value by validating catalog record size | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-40510 | OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c | LOW | 3.8 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-40528 | OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c | LOW | 3.8 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43964 | Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash v | LOW | 3.7 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-48524 | PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) | LOW | 3.7 | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-6638 | PostgreSQL REFRESH PUBLICATION allows SQL injection via table name | LOW | 3.7 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-46483 | Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag | LOW | 3.6 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-45803 | gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection | LOW | 3.5 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-46023 | dm mirror: fix integer overflow in create_dirty_log() | LOW | 3.4 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-39824 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | LOW | 3.3 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45893 | apparmor: Fix & Optimize table creation from possibly unaligned memory | LOW | 3.3 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46123 | Bluetooth: virtio_bt: clamp rx length before skb_put | LOW | 3.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43969 | Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 | LOW | 3.2 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45232 | Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy | LOW | 3.1 | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-45186 | In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via | LOW | 2.9 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-43073 | x86-64: rename misleadingly named '__copy_user_nocache()' function | LOW | 2.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46044 | ipmi:ssif: Clean up kthread on errors | LOW | 1.9 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2025-14179 | SQL injection in pdo_firebird via NUL bytes in quoted strings | UNKNOWN | — | 38%ile | Microsoft | 2026-05-12 |
| CVE-2025-71302 | drm/panthor: fix for dma-fence safe access rules | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-23479 | redis-server use-after-free in unblock client flow may allow remote code execution | UNKNOWN | — | 70%ile | Microsoft | 2026-05-12 |
| CVE-2026-23631 | redis-server Lua use-after-free may allow remote code execution | UNKNOWN | — | 86%ile | Microsoft | 2026-05-12 |
| CVE-2026-25243 | redis-server RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 89%ile | Microsoft | 2026-05-12 |
| CVE-2026-25588 | RedisTimeSeries RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 64%ile | Microsoft | 2026-05-12 |
| CVE-2026-25589 | RedisBloom RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 72%ile | Microsoft | 2026-05-12 |
| CVE-2026-32934 | CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service | UNKNOWN | — | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-32936 | CoreDNS DoH GET path missing size validation causes CPU and memory amplification | UNKNOWN | — | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-33079 | Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles | UNKNOWN | — | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-33190 | CoreDNS TSIG authentication bypass on encrypted DNS transports | UNKNOWN | — | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-33489 | CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison | UNKNOWN | — | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-35579 | CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports | UNKNOWN | — | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-40612 | jq: Stack overflow via unbounded recursion in jv_contains | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-40622 | Another 'ghost domain names' attack variant | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-41257 | jq: Signed-int overflow in `stack_reallocate` (jq VM stack) | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-41889 | pgx: SQL Injection via placeholder confusion with dollar quoted string literals | UNKNOWN | — | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-42250 | Off-by-One Leading to Out-of-Bounds Write in bzip2 | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-42789 | Non-CA certificate accepted as intermediate issuer in public_key path validation | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-42790 | nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification | UNKNOWN | — | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-43320 | drm/amd/display: Fix dsc eDP issue | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43398 | drm/amdgpu: add upper bound check on user inputs in wait ioctl | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43400 | drm/amdgpu: add upper bound check on user inputs in signal ioctl | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43474 | fs: init flags_valid before calling vfs_fileattr_get | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43968 | CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-44431 | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-44656 | Vim: OS Command Injection via 'path' completion | UNKNOWN | — | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-44777 | jq: stack overflow in module loading on mutual `include` | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-44896 | Mistune: XSS via unescaped figclass/figwidth in Figure directive | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-45570 | go-git: Improper single-quote escaping in go-git SSH transport | UNKNOWN | — | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-5222 | Cargo can be coerced to share credentials between registries | UNKNOWN | — | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-5223 | Crates in third party registries can override the cached source of other crates | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-6722 | Use-After-Free in SOAP using Apache map | UNKNOWN | — | 58%ile | Microsoft | 2026-05-12 |
| CVE-2026-6735 | XSS within PHP-FPM status endpoint | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-7210 | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection | UNKNOWN | — | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-7258 | Out-of-bounds read in urldecode() on NetBSD | UNKNOWN | — | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-7259 | Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7261 | SoapServer session-persisted object use-after-free via SOAP header fault | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-7262 | NULL pointer dereference in SOAP apache:Map decoder with missing <value> | UNKNOWN | — | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-7568 | Signed integer overflow in metaphone() | UNKNOWN | — | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-7790 | Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS | UNKNOWN | — | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-8328 | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address | UNKNOWN | — | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-8466 | Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2025-54518 | AMD: CVE-2025-54518 CPU OP Cache Corruption | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-10000 | Chromium: CVE-2026-10000 Use after free in Passwords | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-10001 | Chromium: CVE-2026-10001 Use after free in PerformanceManager | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-10002 | Chromium: CVE-2026-10002 Use after free in PDFium | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-10003 | Chromium: CVE-2026-10003 Use after free in Views | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-10004 | Chromium: CVE-2026-10004 Insufficient validation of untrusted input in Passwords | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-10005 | Chromium: CVE-2026-10005 Use after free in WebAppInstalls | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-10006 | Chromium: CVE-2026-10006 Race in WebAudio | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-10007 | Chromium: CVE-2026-10007 Use after free in SVG | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-10009 | Chromium: CVE-2026-10009 Integer overflow in Skia | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-10011 | Chromium: CVE-2026-10011 Inappropriate implementation in Skia | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-10012 | Chromium: CVE-2026-10012 Use after free in Skia | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-10013 | Chromium: CVE-2026-10013 Use after free in WebCodecs | UNKNOWN | — | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-10015 | Chromium: CVE-2026-10015 Integer overflow in WTF | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-10016 | Chromium: CVE-2026-10016 Use after free in DOM | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-10017 | Chromium: CVE-2026-10017 Out of bounds read in Headless | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-10018 | Chromium: CVE-2026-10018 Integer overflow in ANGLE | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-10019 | Chromium: CVE-2026-10019 Integer overflow in ANGLE | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-10020 | Chromium: CVE-2026-10020 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-10021 | Chromium: CVE-2026-10021 Insufficient validation of untrusted input in USB | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-10022 | Chromium: CVE-2026-10022 Type Confusion in V8 | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-43970 | Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame | UNKNOWN | — | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-44307 | Mako: Path traversal via backslash URI on Windows in TemplateLookup | UNKNOWN | — | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-45492 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-7896 | Chromium: CVE-2026-7896 Integer overflow in Blink | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-7897 | Chromium: CVE-2026-7897 Use after free in Mobile | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-7898 | Chromium: CVE-2026-7898 Use after free in Chromoting | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-7899 | Chromium: CVE-2026-7899 Out of bounds read and write in V8 | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-7900 | Chromium: CVE-2026-7900 Heap buffer overflow in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-7901 | Chromium: CVE-2026-7901 Use after free in ANGLE | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7902 | Chromium: CVE-2026-7902 Out of bounds memory access in V8 | UNKNOWN | — | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-7903 | Chromium: CVE-2026-7903 Integer overflow in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7904 | Chromium: CVE-2026-7904 Out of bounds read in Fonts | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7905 | Chromium: CVE-2026-7905 Insufficient validation of untrusted input in Media | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7906 | Chromium: CVE-2026-7906 Use after free in SVG | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7907 | Chromium: CVE-2026-7907 Use after free in DOM | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7908 | Chromium: CVE-2026-7908 Use after free in Fullscreen | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7909 | Chromium: CVE-2026-7909 Inappropriate implementation in ServiceWorker | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7910 | Chromium: CVE-2026-7910 Use after free in Views | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7911 | Chromium: CVE-2026-7911 Use after free in Aura | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7912 | Chromium: CVE-2026-7912 Integer overflow in GPU | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7913 | Chromium: CVE-2026-7913 Insufficient policy enforcement in DevTools | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7914 | Chromium: CVE-2026-7914 Type Confusion in Accessibility | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7915 | Chromium: CVE-2026-7915 Insufficient data validation in DevTools | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-7916 | Chromium: CVE-2026-7916 Insufficient data validation in InterestGroups | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7917 | Chromium: CVE-2026-7917 Use after free in Fullscreen | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7918 | Chromium: CVE-2026-7918 Use after free in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7919 | Chromium: CVE-2026-7919 Use after free in Aura | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7920 | Chromium: CVE-2026-7920 Use after free in Skia | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7921 | Chromium: CVE-2026-7921 Use after free in Passwords | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7922 | Chromium: CVE-2026-7922 Use after free in ServiceWorker | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7923 | Chromium: CVE-2026-7923 Out of bounds write in Skia | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7924 | Chromium: CVE-2026-7924 Uninitialized Use in Dawn | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7925 | Chromium: CVE-2026-7925 Use after free in Chromoting | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7926 | Chromium: CVE-2026-7926 Use after free in PresentationAPI | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7927 | Chromium: CVE-2026-7927 Type Confusion in Runtime | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-7928 | Chromium: CVE-2026-7928 Use after free in WebRTC | UNKNOWN | — | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-7929 | Chromium: CVE-2026-7929 Use after free in MediaRecording | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-7930 | Chromium: CVE-2026-7930 Insufficient validation of untrusted input in Cookies | UNKNOWN | — | — | Microsoft | 2026-05-12 |
| CVE-2026-7931 | Chromium: CVE-2026-7931 Insufficient validation of untrusted input in iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7932 | Chromium: CVE-2026-7932 Insufficient policy enforcement in Downloads | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7933 | Chromium: CVE-2026-7933 Out of bounds read in WebCodecs | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7934 | Chromium: CVE-2026-7934 Insufficient validation of untrusted input in Popup Blocker | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7935 | Chromium: CVE-2026-7935 Inappropriate implementation in Speech | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7936 | Chromium: CVE-2026-7936 Object lifecycle issue in V8 | UNKNOWN | — | — | Microsoft | 2026-05-12 |
| CVE-2026-7937 | Chromium: CVE-2026-7937 Insufficient policy enforcement in DevTools | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-7938 | Chromium: CVE-2026-7938 Use after free in CSS | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7939 | Chromium: CVE-2026-7939 Inappropriate implementation in SanitizerAPI | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-7940 | Chromium: CVE-2026-7940 Use after free in V8 | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7941 | Chromium: CVE-2026-7941 Insufficient validation of untrusted input in Mobile | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7942 | Chromium: CVE-2026-7942 Integer overflow in ANGLE | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7943 | Chromium: CVE-2026-7943 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-7944 | Chromium: CVE-2026-7944 Insufficient validation of untrusted input in Persistent Cache | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7945 | Chromium: CVE-2026-7945 Insufficient validation of untrusted input in COOP | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7946 | Chromium: CVE-2026-7946 Insufficient policy enforcement in WebUI | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7947 | Chromium: CVE-2026-7947 Insufficient validation of untrusted input in Network | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7948 | Chromium: CVE-2026-7948 Race in Chromoting | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-7949 | Chromium: CVE-2026-7949 Out of bounds read in Skia | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7950 | Chromium: CVE-2026-7950 Out of bounds read and write in GFX | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7951 | Chromium: CVE-2026-7951 Out of bounds write in WebRTC | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-7952 | Chromium: CVE-2026-7952 Insufficient policy enforcement in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7953 | Chromium: CVE-2026-7953 Insufficient validation of untrusted input in Omnibox | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7954 | Chromium: CVE-2026-7954 Race in Shared Storage | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7955 | Chromium: CVE-2026-7955 Uninitialized Use in GPU | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7956 | Chromium: CVE-2026-7956 Use after free in Navigation | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7957 | Chromium: CVE-2026-7957 Out of bounds write in Media | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-7958 | Chromium: CVE-2026-7958 Inappropriate implementation in ServiceWorker | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-7959 | Chromium: CVE-2026-7959 Inappropriate implementation in Navigation | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7960 | Chromium: CVE-2026-7960 Race in Speech | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7961 | Chromium: CVE-2026-7961 Insufficient validation of untrusted input in Permissions | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7962 | Chromium: CVE-2026-7962 Insufficient policy enforcement in DirectSockets | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7963 | Chromium: CVE-2026-7963 Inappropriate implementation in ServiceWorker | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7964 | Chromium: CVE-2026-7964 Insufficient validation of untrusted input in FileSystem | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7965 | Chromium: CVE-2026-7965 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7966 | Chromium: CVE-2026-7966 Insufficient validation of untrusted input in SiteIsolation | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-7967 | Chromium: CVE-2026-7967 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7968 | Chromium: CVE-2026-7968 Insufficient validation of untrusted input in CORS | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-7969 | Chromium: CVE-2026-7969 Integer overflow in Network | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7970 | Chromium: CVE-2026-7970 Use after free in TopChrome | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7971 | Chromium: CVE-2026-7971 Inappropriate implementation in ORB | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7972 | Chromium: CVE-2026-7972 Uninitialized Use in GPU | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7973 | Chromium: CVE-2026-7973 Integer overflow in Dawn | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7974 | Chromium: CVE-2026-7974 Use after free in Blink | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7975 | Chromium: CVE-2026-7975 Use after free in DevTools | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7976 | Chromium: CVE-2026-7976 Use after free in Views | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7977 | Chromium: CVE-2026-7977 Inappropriate implementation in Canvas | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7978 | Chromium: CVE-2026-7978 Inappropriate implementation in Companion | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7979 | Chromium: CVE-2026-7979 Inappropriate implementation in Media | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7980 | Chromium: CVE-2026-7980 Use after free in WebAudio | UNKNOWN | — | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-7981 | Chromium: CVE-2026-7981 Out of bounds read in Codecs | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7982 | Chromium: CVE-2026-7982 Uninitialized Use in WebCodecs | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7983 | Chromium: CVE-2026-7983 Out of bounds read in Dawn | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7984 | Chromium: CVE-2026-7984 Use after free in ReadingMode | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7985 | Chromium: CVE-2026-7985 Use after free in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7986 | Chromium: CVE-2026-7986 Insufficient policy enforcement in Autofill | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7987 | Chromium: CVE-2026-7987 Use after free in WebRTC | UNKNOWN | — | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-7988 | Chromium: CVE-2026-7988 Type Confusion in WebRTC | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-7989 | Chromium: CVE-2026-7989 Insufficient data validation in DataTransfer | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-7990 | Chromium: CVE-2026-7990 Insufficient validation of untrusted input in Updater | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7991 | Chromium: CVE-2026-7991 Use after free in UI | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7992 | Chromium: CVE-2026-7992 Insufficient validation of untrusted input in UI | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7993 | Chromium: CVE-2026-7993 Insufficient validation of untrusted input in Payments | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7994 | Chromium: CVE-2026-7994 Inappropriate implementation in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-7995 | Chromium: CVE-2026-7995 Out of bounds read in AdFilter | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7996 | Chromium: CVE-2026-7996 Insufficient validation of untrusted input in SSL | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7997 | Chromium: CVE-2026-7997 Insufficient validation of untrusted input in Updater | UNKNOWN | — | 0%ile | Microsoft | 2026-05-12 |
| CVE-2026-7998 | Chromium: CVE-2026-7998 Insufficient validation of untrusted input in Dialog | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7999 | Chromium: CVE-2026-7999 Inappropriate implementation in V8 | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8000 | Chromium: CVE-2026-8000 Insufficient validation of untrusted input in ChromeDriver | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8001 | Chromium: CVE-2026-8001 Use after free in Printing | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8002 | Chromium: CVE-2026-8002 Use after free in Audio | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8003 | Chromium: CVE-2026-8003 Insufficient validation of untrusted input in TabGroups | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8004 | Chromium: CVE-2026-8004 Insufficient policy enforcement in DevTools | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-8005 | Chromium: CVE-2026-8005 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-8006 | Chromium: CVE-2026-8006 Insufficient policy enforcement in DevTools | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-8007 | Chromium: CVE-2026-8007 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8008 | Chromium: CVE-2026-8008 Inappropriate implementation in DevTools | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-8009 | Chromium: CVE-2026-8009 Inappropriate implementation in Cast | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-8010 | Chromium: CVE-2026-8010 Insufficient validation of untrusted input in SiteIsolation | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-8011 | Chromium: CVE-2026-8011 Insufficient policy enforcement in Search | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8012 | Chromium: CVE-2026-8012 Inappropriate implementation in MHTML | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8013 | Chromium: CVE-2026-8013 Insufficient validation of untrusted input in FedCM | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8014 | Chromium: CVE-2026-8014 Inappropriate implementation in Preload | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8015 | Chromium: CVE-2026-8015 Inappropriate implementation in Media | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8016 | Chromium: CVE-2026-8016 Use after free in WebRTC | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-8017 | Chromium: CVE-2026-8017 Side-channel information leakage in Media | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8018 | Chromium: CVE-2026-8018 Insufficient policy enforcement in DevTools | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-8019 | Chromium: CVE-2026-8019 Insufficient policy enforcement in WebApp | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8020 | Chromium: CVE-2026-8020 Uninitialized Use in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8021 | Chromium: CVE-2026-8021 Script injection in UI | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8022 | Chromium: CVE-2026-8022 Inappropriate implementation in MHTML | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8509 | Chromium: CVE-2026-8509 Heap buffer overflow in WebML | UNKNOWN | — | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-8510 | Chromium: CVE-2026-8510 Integer overflow in Skia | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-8511 | Chromium: CVE-2026-8511 Use after free in UI | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-8512 | Chromium: CVE-2026-8512 Use after free in FileSystem | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8513 | Chromium: CVE-2026-8513 Use after free in Input | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8514 | Chromium: CVE-2026-8514 Use after free in Aura | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8515 | Chromium: CVE-2026-8515 Use after free in HID | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8516 | Chromium: CVE-2026-8516 Insufficient validation of untrusted input in DataTransfer | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-8517 | Chromium: CVE-2026-8517 Object lifecycle issue in WebShare | UNKNOWN | — | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-8518 | Chromium: CVE-2026-8518 Use after free in Blink | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-8519 | Chromium: CVE-2026-8519 Integer overflow in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-8520 | Chromium: CVE-2026-8520 Race in Payments | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8521 | Chromium: CVE-2026-8521 Use after free in Tab Groups | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8522 | Chromium: CVE-2026-8522 Use after free in Downloads | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-8523 | Chromium: CVE-2026-8523 Use after free in Mojo | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8524 | Chromium: CVE-2026-8524 Out of bounds write in WebAudio | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-8525 | Chromium: CVE-2026-8525 Heap buffer overflow in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-8526 | Chromium: CVE-2026-8526 Out of bounds write in WebRTC | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-8527 | Chromium: CVE-2026-8527 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-8528 | Chromium: CVE-2026-8528 Insufficient validation of untrusted input in SiteIsolation | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-8529 | Chromium: CVE-2026-8529 Heap buffer overflow in Codecs | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-8530 | Chromium: CVE-2026-8530 Use after free in Network | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-8531 | Chromium: CVE-2026-8531 Heap buffer overflow in WebML | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-8532 | Chromium: CVE-2026-8532 Integer overflow in XML | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-8533 | Chromium: CVE-2026-8533 Use after free in Accessibility | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8534 | Chromium: CVE-2026-8534 Integer overflow in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8535 | Chromium: CVE-2026-8535 Out of bounds read in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8536 | Chromium: CVE-2026-8536 Insufficient validation of untrusted input in ReadingMode | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8537 | Chromium: CVE-2026-8537 Insufficient policy enforcement in ViewTransitions | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8538 | Chromium: CVE-2026-8538 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-8539 | Chromium: CVE-2026-8539 Script injection in SanitizerAPI | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8540 | Chromium: CVE-2026-8540 Type Confusion in V8 | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-8541 | Chromium: CVE-2026-8541 Out of bounds read in UI | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8542 | Chromium: CVE-2026-8542 Use after free in Core | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8543 | Chromium: CVE-2026-8543 Out of bounds read in FileSystem | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-8544 | Chromium: CVE-2026-8544 Use after free in Media | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-8545 | Chromium: CVE-2026-8545 Object corruption in Compositing | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8546 | Chromium: CVE-2026-8546 Out of bounds read in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8547 | Chromium: CVE-2026-8547 Insufficient policy enforcement in Passwords | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-8548 | Chromium: CVE-2026-8548 Out of bounds write in Media | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8549 | Chromium: CVE-2026-8549 Use after free in Media | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-8550 | Chromium: CVE-2026-8550 Use after free in Google Lens | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-8551 | Chromium: CVE-2026-8551 Use after free in Downloads | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-8552 | Chromium: CVE-2026-8552 Heap buffer overflow in GPU | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-8553 | Chromium: CVE-2026-8553 Use after free in GPU | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8554 | Chromium: CVE-2026-8554 Type Confusion in ANGLE | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-8555 | Chromium: CVE-2026-8555 Use after free in GTK | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-8556 | Chromium: CVE-2026-8556 Inappropriate implementation in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-8557 | Chromium: CVE-2026-8557 Use after free in Accessibility | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8558 | Chromium: CVE-2026-8558 Out of bounds write in Fonts | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-8559 | Chromium: CVE-2026-8559 Integer overflow in Internationalization | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8560 | Chromium: CVE-2026-8560 Heap buffer overflow in SwiftShader | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-8561 | Chromium: CVE-2026-8561 Incorrect security UI in Fullscreen | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8562 | Chromium: CVE-2026-8562 Side-channel information leakage in Navigation | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8563 | Chromium: CVE-2026-8563 Insufficient policy enforcement in IFrame Sandbox | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8564 | Chromium: CVE-2026-8564 Incorrect security UI in Downloads | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8565 | Chromium: CVE-2026-8565 Inappropriate implementation in Downloads | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-8566 | Chromium: CVE-2026-8566 Insufficient policy enforcement in Payments | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8567 | Chromium: CVE-2026-8567 Integer overflow in ANGLE | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8568 | Chromium: CVE-2026-8568 Insufficient policy enforcement in AI | UNKNOWN | — | — | Microsoft | 2026-05-12 |
| CVE-2026-8569 | Chromium: CVE-2026-8569 Out of bounds write in Codecs | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8570 | Chromium: CVE-2026-8570 Type Confusion in V8 | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-8571 | Chromium: CVE-2026-8571 Insufficient policy enforcement in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-8572 | Chromium: CVE-2026-8572 Insufficient policy enforcement in Network | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8573 | Chromium: CVE-2026-8573 Integer overflow in Codecs | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-8574 | Chromium: CVE-2026-8574 Use after free in Core | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8575 | Chromium: CVE-2026-8575 Use after free in UI | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8576 | Chromium: CVE-2026-8576 Inappropriate implementation in CORS | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8577 | Chromium: CVE-2026-8577 Integer overflow in Fonts | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-8578 | Chromium: CVE-2026-8578 Out of bounds read in GPU | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8579 | Chromium: CVE-2026-8579 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-8580 | Chromium: CVE-2026-8580 Use after free in Mojo | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-8581 | Chromium: CVE-2026-8581 Use after free in GPU | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-8582 | Chromium: CVE-2026-8582 Object lifecycle issue in Dawn | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8583 | Chromium: CVE-2026-8583 Insufficient policy enforcement in WebXR | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8584 | Chromium: CVE-2026-8584 Inappropriate implementation in Views | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8585 | Chromium: CVE-2026-8585 Inappropriate implementation in Media | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8586 | Chromium: CVE-2026-8586 Inappropriate implementation in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-8587 | Chromium: CVE-2026-8587 Use after free in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-9110 | Chromium: CVE-2026-9110 Inappropriate implementation in UI | UNKNOWN | — | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-9111 | Chromium: CVE-2026-9111 Use after free in WebRTC | UNKNOWN | — | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-9112 | Chromium: CVE-2026-9112 Use after free in GPU | UNKNOWN | — | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-9113 | Chromium: CVE-2026-9113 Out of bounds read in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9114 | Chromium: CVE-2026-9114 Use after free in QUIC | UNKNOWN | — | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-9115 | Chromium: CVE-2026-9115 Insufficient policy enforcement in Service Worker | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9116 | Chromium: CVE-2026-9116 Insufficient policy enforcement in ServiceWorker | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9117 | Chromium: CVE-2026-9117 Type Confusion in GFX | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-9118 | Chromium: CVE-2026-9118 Use after free in XR | UNKNOWN | — | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-9119 | Chromium: CVE-2026-9119 Heap buffer overflow in WebRTC | UNKNOWN | — | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-9120 | Chromium: CVE-2026-9120 Use after free in WebRTC | UNKNOWN | — | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-9121 | Chromium: CVE-2026-9126 Use after free in DOM | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-9122 | Chromium: CVE-2026-9121 Out of bounds read in GPU | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-9123 | Chromium: CVE-2026-9122 Out of bounds read in GPU | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9124 | Chromium: CVE-2026-9123 Heap buffer overflow in Chromecast | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-9126 | Chromium: CVE-2026-9124 Insufficient validation of untrusted input in Input | UNKNOWN | — | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-9873 | Chromium: CVE-2026-9873 Use after free in Network | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9874 | Chromium: CVE-2026-9874 Use after free in Dawn | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9875 | Chromium: CVE-2026-9875 Out of bounds read in WebGL | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9876 | Chromium: CVE-2026-9876 Use after free in WebGL | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9877 | Chromium: CVE-2026-9877 Use after free in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9878 | Chromium: CVE-2026-9878 Use after free in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-9879 | Chromium: CVE-2026-9879 Out of bounds write in ANGLE | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9880 | Chromium: CVE-2026-9880 Insufficient validation of untrusted input in WebGL | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9881 | Chromium: CVE-2026-9881 Use after free in Bluetooth | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9882 | Chromium: CVE-2026-9882 Integer overflow in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9883 | Chromium: CVE-2026-9883 Use after free in Base | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9884 | Chromium: CVE-2026-9884 Use after free in Browser | UNKNOWN | — | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-9885 | Chromium: CVE-2026-9885 Insufficient validation of untrusted input in UI | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9886 | Chromium: CVE-2026-9886 Use after free in Base | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9887 | Chromium: CVE-2026-9887 Use after free in Proxy | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9888 | Chromium: CVE-2026-9888 Use after free in WebView | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9889 | Chromium: CVE-2026-9889 Out of bounds read and write in Dawn | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9890 | Chromium: CVE-2026-9890 Use after free in XR | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9891 | Chromium: CVE-2026-9891 Use after free in Extensions | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9892 | Chromium: CVE-2026-9892 Inappropriate implementation in Skia | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9893 | Chromium: CVE-2026-9893 Use after free in Skia | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-9894 | Chromium: CVE-2026-9894 Use after free in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9895 | Chromium: CVE-2026-9895 Out of bounds read in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9896 | Chromium: CVE-2026-9896 Out of bounds write in V8 | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9897 | Chromium: CVE-2026-9897 Use after free in DOM | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9898 | Chromium: CVE-2026-9898 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9899 | Chromium: CVE-2026-9899 Use after free in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9900 | Chromium: CVE-2026-9900 Out of bounds write in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9901 | Chromium: CVE-2026-9901 Use after free in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9902 | Chromium: CVE-2026-9902 Use after free in Accessibility | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9903 | Chromium: CVE-2026-9903 Insufficient validation of untrusted input in Site Isolation | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-9904 | Chromium: CVE-2026-9904 Use after free in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9905 | Chromium: CVE-2026-9905 Use after free in Accessibility | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9906 | Chromium: CVE-2026-9906 Out of bounds write in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9907 | Chromium: CVE-2026-9907 Out of bounds read in Dawn | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9908 | Chromium: CVE-2026-9908 Out of bounds read in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9909 | Chromium: CVE-2026-9909 Integer overflow in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9910 | Chromium: CVE-2026-9910 Out of bounds memory access in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-9911 | Chromium: CVE-2026-9911 Integer overflow in ANGLE | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9912 | Chromium: CVE-2026-9912 Inappropriate implementation in GPU | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9913 | Chromium: CVE-2026-9913 Inappropriate implementation in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9914 | Chromium: CVE-2026-9914 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9915 | Chromium: CVE-2026-9915 Heap buffer overflow in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9916 | Chromium: CVE-2026-9916 Out of bounds write in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9917 | Chromium: CVE-2026-9917 Uninitialized Use in WebGL | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-9918 | Chromium: CVE-2026-9918 Inappropriate implementation in Tint | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9919 | Chromium: CVE-2026-9919 Out of bounds read in WebGL | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9920 | Chromium: CVE-2026-9920 Uninitialized Use in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9921 | Chromium: CVE-2026-9921 Uninitialized Use in WebGL | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9922 | Chromium: CVE-2026-9922 Use after free in GPU | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9923 | Chromium: CVE-2026-9923 Use after free in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9924 | Chromium: CVE-2026-9924 Heap buffer overflow in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9925 | Chromium: CVE-2026-9925 Use after free in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9926 | Chromium: CVE-2026-9926 Heap buffer overflow in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9927 | Chromium: CVE-2026-9927 Use after free in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9928 | Chromium: CVE-2026-9928 Out of bounds read in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9929 | Chromium: CVE-2026-9929 Inappropriate implementation in WebGL | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9930 | Chromium: CVE-2026-9930 Out of bounds write in Dawn | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9931 | Chromium: CVE-2026-9931 Use after free in GPU | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9932 | Chromium: CVE-2026-9932 Use after free in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9933 | Chromium: CVE-2026-9933 Use after free in Input | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9934 | Chromium: CVE-2026-9934 Use after free in Aura | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9935 | Chromium: CVE-2026-9935 Uninitialized Use in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9936 | Chromium: CVE-2026-9936 Use after free in GFX | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9937 | Chromium: CVE-2026-9937 Use after free in UI | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9938 | Chromium: CVE-2026-9938 Inappropriate implementation in V8 | UNKNOWN | — | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-9939 | Chromium: CVE-2026-9939 Heap buffer overflow in WebCodecs | UNKNOWN | — | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-9940 | Chromium: CVE-2026-9940 Heap buffer overflow in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-9941 | Chromium: CVE-2026-9941 Use after free in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9942 | Chromium: CVE-2026-9942 Uninitialized Use in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-9943 | Chromium: CVE-2026-9943 Out of bounds read in WebGL | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9944 | Chromium: CVE-2026-9944 Uninitialized Use in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-9945 | Chromium: CVE-2026-9945 Use after free in Media | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9946 | Chromium: CVE-2026-9946 Use after free in ANGLE | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9947 | Chromium: CVE-2026-9947 Use after free in XML | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9948 | Chromium: CVE-2026-9948 Use after free in Views | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9949 | Chromium: CVE-2026-9949 Use after free in Core | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9950 | Chromium: CVE-2026-9950 Insufficient validation of untrusted input in iOS | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-9951 | Chromium: CVE-2026-9951 Use after free in UI | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9952 | Chromium: CVE-2026-9952 Use after free in WebAudio | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-9953 | Chromium: CVE-2026-9953 Out of bounds read in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9954 | Chromium: CVE-2026-9954 Use after free in TabStrip | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9955 | Chromium: CVE-2026-9955 Inappropriate implementation in iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9956 | Chromium: CVE-2026-9956 Use after free in iOS | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9957 | Chromium: CVE-2026-9957 Use after free in PDF | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-9958 | Chromium: CVE-2026-9958 Use after free in PDFium | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9959 | Chromium: CVE-2026-9959 Race in WebRTC | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-9960 | Chromium: CVE-2026-9960 Integer overflow in PDFium | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9961 | Chromium: CVE-2026-9961 Use after free in SurfaceCapture | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9962 | Chromium: CVE-2026-9962 Use after free in WebRTC | UNKNOWN | — | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-9963 | Chromium: CVE-2026-9963 Uninitialized Use in iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-9964 | Chromium: CVE-2026-9964 Use after free in Bluetooth | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9965 | Chromium: CVE-2026-9965 Out of bounds write in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9966 | Chromium: CVE-2026-9966 Integer overflow in XML | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9967 | Chromium: CVE-2026-9967 Out of bounds write in GPU | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9968 | Chromium: CVE-2026-9968 Integer overflow in V8 | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-9969 | Chromium: CVE-2026-9969 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9970 | Chromium: CVE-2026-9970 Use after free in WebGL | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9971 | Chromium: CVE-2026-9971 Inappropriate implementation in iOS | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-9972 | Chromium: CVE-2026-9972 Uninitialized Use in Gamepad | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9973 | Chromium: CVE-2026-9973 Out of bounds write in V8 | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-9974 | Chromium: CVE-2026-9974 Out of bounds write in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9975 | Chromium: CVE-2026-9975 Out of bounds read and write in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9976 | Chromium: CVE-2026-9976 Inappropriate implementation in USB | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9977 | Chromium: CVE-2026-9977 Insufficient validation of untrusted input in WebShare | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9978 | Chromium: CVE-2026-9978 Use after free in Glic | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9979 | Chromium: CVE-2026-9979 Insufficient validation of untrusted input in Input | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-9980 | Chromium: CVE-2026-9980 Insufficient validation of untrusted input in Printing | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-9981 | Chromium: CVE-2026-9981 Inappropriate implementation in Skia | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9982 | Chromium: CVE-2026-9982 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9983 | Chromium: CVE-2026-9983 Type Confusion in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9984 | Chromium: CVE-2026-9984 Use after free in UI | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9985 | Chromium: CVE-2026-9985 Insufficient validation of untrusted input in Media | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9986 | Chromium: CVE-2026-9986 Insufficient validation of untrusted input in OptimizationGuide | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-9988 | Chromium: CVE-2026-9988 Use after free in WebRTC | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-9989 | Chromium: CVE-2026-9989 Inappropriate implementation in Media | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-9990 | Chromium: CVE-2026-9990 Use after free in WebAppInstalls | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-9991 | Chromium: CVE-2026-9991 Inappropriate implementation in Media | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-9992 | Chromium: CVE-2026-9992 Use after free in Network | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9993 | Chromium: CVE-2026-9993 Use after free in Views | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-9994 | Chromium: CVE-2026-9994 Use after free in Core | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9995 | Chromium: CVE-2026-9995 Use after free in WebXR | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9996 | Chromium: CVE-2026-9996 Out of bounds read in WebRTC | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9997 | Chromium: CVE-2026-9997 Use after free in Input | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9998 | Chromium: CVE-2026-9998 Integer overflow in Skia | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-9999 | Chromium: CVE-2026-9999 Inappropriate implementation in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-31769 | gpib: fix use-after-free in IO ioctl handlers | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43021 | Bluetooth: hci_sync: fix leaks when hci_cmd_sync_queue_once fails | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43045 | mshv: Fix error handling in mshv_region_pin | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-41673 | xmldom: Denial of service via uncontrolled recursion in XML serialization | UNKNOWN | — | 49%ile | Microsoft | 2026-05-12 |
| CVE-2026-43443 | ASoC: amd: acp-mach-common: Add missing error check for clock acquisition | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43421 | usb: gadget: f_ncm: Fix net_device lifecycle with device_move | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-42256 | net-imap: Denial of service via high iteration count for `SCRAM-*` authentication | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-42246 | net-imap vulnerable to STARTTLS stripping via invalid response timing | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-6210 | Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-44662 | rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2025-14575 | Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-44844 | eml_parser: Recursion DoS via nested message/rfc822 attachments | UNKNOWN | — | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-41672 | xmldom: XML node injection through unvalidated comment serialization | UNKNOWN | — | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-41674 | xmldom: XML injection through unvalidated DocumentType serialization | UNKNOWN | — | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-41675 | xmldom: XML node injection through unvalidated processing instruction serialization | UNKNOWN | — | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-43317 | most: core: fix leak on early registration failure | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-42257 | net-imap: Command Injection via "raw" arguments to multiple commands | UNKNOWN | — | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-42258 | net-imap: Command Injection via unvalidated Symbol inputs | UNKNOWN | — | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-8295 | Integer overflow in simdjson | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-41184 | ServiceAccount token disclosure via install-cni container logs | UNKNOWN | — | 42%ile | Microsoft | 2026-05-12 |
| CVE-2025-68121 | Unexpected session resumption in crypto/tls | CRITICAL | 10.0 | 54%ile | Microsoft | 2026-02-10 |
| CVE-2026-27211 | Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse | CRITICAL | 10.0 | 42%ile | Microsoft | 2026-02-10 |
| CVE-2025-62878 | Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern | CRITICAL | 9.9 | 46%ile | Microsoft | 2026-02-10 |
| CVE-2025-61144 | libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function. | CRITICAL | 9.8 | 17%ile | Microsoft | 2026-02-10 |
| CVE-2026-24300 | Azure Front Door Elevation of Privilege Vulnerability | CRITICAL | 9.8 | 69%ile | Microsoft | 2026-02-10 |
| CVE-2026-21531 | Azure SDK for Python Remote Code Execution Vulnerability | CRITICAL | 9.8 | 84%ile | Microsoft | 2026-02-10 |
| CVE-2026-24834 | Kata Container to Guest micro VM privilege escalation | CRITICAL | 9.3 | 13%ile | Microsoft | 2026-02-10 |
| CVE-2026-21513 | MSHTML Framework Security Feature Bypass Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2026-02-10 |
| CVE-2026-21510 | Windows Shell Security Feature Bypass Vulnerability | HIGH | 8.8 | 98%ile | Microsoft | 2026-02-10 |
| CVE-2026-21537 | Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-02-10 |
| CVE-2026-21516 | GitHub Copilot for Jetbrains Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-02-10 |
| CVE-2026-21256 | GitHub Copilot and Visual Studio Remote Code Execution Vulnerability | HIGH | 8.8 | 65%ile | Microsoft | 2026-02-10 |
| CVE-2026-21255 | Windows Hyper-V Security Feature Bypass Vulnerability | HIGH | 8.8 | 31%ile | Microsoft | 2026-02-10 |
| CVE-2026-26119 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 8.8 | 67%ile | Microsoft | 2026-02-10 |
| CVE-2026-21518 | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.8 | 71%ile | Microsoft | 2026-02-10 |
| CVE-2025-61732 | Potential code smuggling via doc comments in cmd/cgo | HIGH | 8.6 | 41%ile | Microsoft | 2026-02-10 |
| CVE-2026-24302 | Azure Arc Elevation of Privilege Vulnerability | HIGH | 8.6 | 74%ile | Microsoft | 2026-02-10 |
| CVE-2025-67733 | Valkey Affected by RESP Protocol Injection via Lua error_reply | HIGH | 8.5 | 47%ile | Microsoft | 2026-02-10 |
| CVE-2025-71225 | md: suspend array while updating raid_disks via sysfs | HIGH | 8.4 | 0%ile | Microsoft | 2026-02-10 |
| CVE-2025-71229 | wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon() | HIGH | 8.4 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2025-71233 | PCI: endpoint: Avoid creating sub-groups asynchronously | HIGH | 8.4 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23213 | drm/amd/pm: Disable MMIO access during SMU Mode 1 reset | HIGH | 8.4 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23214 | btrfs: reject new transactions if the fs is fully read-only | HIGH | 8.4 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23215 | x86/vmware: Fix hypercall clobbers | HIGH | 8.4 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23216 | scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() | HIGH | 8.4 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23230 | smb: client: split cached_fid bitfields to avoid shared-byte RMW races | HIGH | 8.4 | 14%ile | Microsoft | 2026-02-10 |
| CVE-2025-71231 | crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode | HIGH | 8.4 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2025-71228 | LoongArch: Set correct protection_map[] for VM_NONE/VM_SHARED | HIGH | 8.4 | — | Microsoft | 2026-02-10 |
| CVE-2025-69299 | WordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability | HIGH | 8.3 | 9%ile | Microsoft | 2026-02-10 |
| CVE-2026-21532 | Azure Function Information Disclosure Vulnerability | HIGH | 8.2 | 57%ile | Microsoft | 2026-02-10 |
| CVE-2026-21535 | Microsoft Teams Information Disclosure Vulnerability | HIGH | 8.2 | 48%ile | Microsoft | 2026-02-10 |
| CVE-2026-21228 | Azure Local Remote Code Execution Vulnerability | HIGH | 8.1 | 54%ile | Microsoft | 2026-02-10 |
| CVE-2026-21257 | GitHub Copilot and Visual Studio Elevation of Privilege Vulnerability | HIGH | 8.0 | 58%ile | Microsoft | 2026-02-10 |
| CVE-2026-21523 | GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability | HIGH | 8.0 | 55%ile | Microsoft | 2026-02-10 |
| CVE-2026-21229 | Power BI Remote Code Execution Vulnerability | HIGH | 8.0 | 59%ile | Microsoft | 2026-02-10 |
| CVE-2026-28364 | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re | HIGH | 7.9 | 12%ile | Microsoft | 2026-02-10 |
| CVE-2026-23208 | ALSA: usb-audio: Prevent excessive number of frames | HIGH | 7.8 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23221 | bus: fsl-mc: fix use-after-free in driver_override_show() | HIGH | 7.8 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-21519 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 84%ile | Microsoft | 2026-02-10 |
| CVE-2026-21259 | Microsoft Excel Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2026-02-10 |
| CVE-2026-21236 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-02-10 |
| CVE-2026-21533 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 90%ile | Microsoft | 2026-02-10 |
| CVE-2026-21514 | Microsoft Word Security Feature Bypass Vulnerability | HIGH | 7.8 | 74%ile | Microsoft | 2026-02-10 |
| CVE-2026-21251 | Cluster Client Failover (CCF) Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-02-10 |
| CVE-2026-21250 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 64%ile | Microsoft | 2026-02-10 |
| CVE-2026-21245 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-02-10 |
| CVE-2026-21240 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-02-10 |
| CVE-2026-21239 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-02-10 |
| CVE-2026-21238 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2026-02-10 |
| CVE-2026-21232 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-02-10 |
| CVE-2026-21231 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 85%ile | Microsoft | 2026-02-10 |
| CVE-2025-71234 | wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add | HIGH | 7.8 | 8%ile | Microsoft | 2026-02-10 |
| CVE-2026-20841 | Windows Notepad App Remote Code Execution Vulnerability | HIGH | 7.8 | 96%ile | Microsoft | 2026-02-10 |
| CVE-2026-21246 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-02-10 |
| CVE-2026-23068 | spi: spi-sprd-adi: Fix double free in probe error path | HIGH | 7.8 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-21863 | Malformed Valkey Cluster bus message can lead to Remote DoS | HIGH | 7.5 | 54%ile | Microsoft | 2026-02-10 |
| CVE-2026-25541 | Bytes is vulnerable to integer overflow in BytesMut::reserve | HIGH | 7.5 | 45%ile | Microsoft | 2026-02-10 |
| CVE-2026-27141 | Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net | HIGH | 7.5 | 42%ile | Microsoft | 2026-02-10 |
| CVE-2026-27903 | minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments | HIGH | 7.5 | 43%ile | Microsoft | 2026-02-10 |
| CVE-2026-21260 | Microsoft Outlook Spoofing Vulnerability | HIGH | 7.5 | 73%ile | Microsoft | 2026-02-10 |
| CVE-2026-21218 | .NET Spoofing Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-02-10 |
| CVE-2026-21511 | Microsoft Outlook Spoofing Vulnerability | HIGH | 7.5 | 89%ile | Microsoft | 2026-02-10 |
| CVE-2026-21243 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | HIGH | 7.5 | 71%ile | Microsoft | 2026-02-10 |
| CVE-2026-23226 | ksmbd: add chann_lock to protect ksmbd_chann_list xarray | HIGH | 7.5 | 38%ile | Microsoft | 2026-02-10 |
| CVE-2026-20846 | GDI+ Denial of Service Vulnerability | HIGH | 7.5 | 71%ile | Microsoft | 2026-02-10 |
| CVE-2026-27623 | Valkey has Pre-Authentication DOS from malformed RESP request | HIGH | 7.5 | 29%ile | Microsoft | 2026-02-10 |
| CVE-2026-23066 | rxrpc: Fix recvmsg() unconditional requeue | HIGH | 7.4 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-21248 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 7.3 | 69%ile | Microsoft | 2026-02-10 |
| CVE-2026-21247 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 7.3 | 46%ile | Microsoft | 2026-02-10 |
| CVE-2026-21235 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.3 | 52%ile | Microsoft | 2026-02-10 |
| CVE-2026-21244 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 7.3 | 69%ile | Microsoft | 2026-02-10 |
| CVE-2026-23204 | net/sched: cls_u32: use skb_header_pointer_careful() | HIGH | 7.1 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2025-71226 | wifi: iwlwifi: Implement settime64 as stub for MVM/MLD PTP | HIGH | 7.1 | — | Microsoft | 2026-02-10 |
| CVE-2026-26960 | node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction | HIGH | 7.1 | 22%ile | Microsoft | 2026-02-10 |
| CVE-2026-23191 | ALSA: aloop: Fix racy access at PCM trigger | HIGH | 7.0 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-2492 | TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-02-10 |
| CVE-2026-21242 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | HIGH | 7.0 | 29%ile | Microsoft | 2026-02-10 |
| CVE-2026-21234 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2026-02-10 |
| CVE-2026-21508 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.0 | 38%ile | Microsoft | 2026-02-10 |
| CVE-2026-21253 | Mailslot File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 55%ile | Microsoft | 2026-02-10 |
| CVE-2026-21241 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 84%ile | Microsoft | 2026-02-10 |
| CVE-2026-21237 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2026-02-10 |
| CVE-2026-23227 | drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free | HIGH | 7.0 | 5%ile | Microsoft | 2026-02-10 |
| CVE-2025-71221 | dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() | HIGH | 7.0 | 1%ile | Microsoft | 2026-02-10 |
| CVE-2026-24051 | OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking | HIGH | 7.0 | 6%ile | Microsoft | 2026-02-10 |
| CVE-2026-23171 | bonding: fix use-after-free due to enslave fail after slave array update | MEDIUM | 6.7 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-21522 | Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 37%ile | Microsoft | 2026-02-10 |
| CVE-2026-0665 | Qemu-kvm: heap off-by-one in kvm xen physdevop_map_pirq | MEDIUM | 6.5 | 5%ile | Microsoft | 2026-02-10 |
| CVE-2026-21512 | Azure DevOps Server Cross-Site Scripting Vulnerability | MEDIUM | 6.5 | 61%ile | Microsoft | 2026-02-10 |
| CVE-2026-23655 | Microsoft ACI Confidential Containers Information Disclosure Vulnerability | MEDIUM | 6.5 | 61%ile | Microsoft | 2026-02-10 |
| CVE-2026-0391 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-02-10 |
| CVE-2026-21527 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 6.5 | 94%ile | Microsoft | 2026-02-10 |
| CVE-2026-21528 | Azure IoT Explorer Information Disclosure Vulnerability | MEDIUM | 6.5 | 44%ile | Microsoft | 2026-02-10 |
| CVE-2023-2804 | Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo | MEDIUM | 6.5 | 66%ile | Microsoft | 2026-02-10 |
| CVE-2026-25727 | time affected by a stack exhaustion denial of service attack | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-02-10 |
| CVE-2026-21525 | Windows Remote Access Connection Manager Denial of Service Vulnerability | MEDIUM | 6.2 | 92%ile | Microsoft | 2026-02-10 |
| CVE-2026-27571 | nats-server websockets are vulnerable to pre-auth memory DoS | MEDIUM | 5.9 | 40%ile | Microsoft | 2026-02-10 |
| CVE-2026-21529 | Azure HDInsight Spoofing Vulnerability | MEDIUM | 5.7 | 50%ile | Microsoft | 2026-02-10 |
| CVE-2025-61143 | libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c. | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2025-61145 | libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2025-71202 | iommu/sva: invalidate stale IOTLB entries for kernel address space | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2025-71227 | wifi: mac80211: don't WARN for connections on invalid channels | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-02-10 |
| CVE-2025-71232 | scsi: qla2xxx: Free sp in error path to fix system crash | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2025-71235 | scsi: qla2xxx: Delay module unload while fabric scan in progress | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2025-71236 | scsi: qla2xxx: Validate sp before freeing associated memory | MEDIUM | 5.5 | 16%ile | Microsoft | 2026-02-10 |
| CVE-2025-71237 | nilfs2: Fix potential block overflow that cause system hang | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23069 | vsock/virtio: fix potential underflow in virtio_transport_get_credit() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23086 | vsock/virtio: cap TX credit to local buffer size | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-02-10 |
| CVE-2026-23088 | tracing: Fix crash on synthetic stacktrace field usage | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23100 | mm/hugetlb: fix hugetlb_pmd_shared() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23113 | io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23137 | of: unittest: Fix memory leak in unittest_data_add() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23138 | tracing: Add recursion protection in kernel stack trace recording | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23141 | btrfs: send: check for inline extents in range_is_hole_in_parent() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23154 | net: fix segmentation of forwarding fraglist GRO | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23157 | btrfs: do not strictly require dirty metadata threshold for metadata writepages | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23207 | spi: tegra210-quad: Protect curr_xfer check in IRQ handler | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-02-10 |
| CVE-2026-23212 | bonding: annotate data-races around slave->last_rx | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-02-10 |
| CVE-2026-23220 | ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23222 | crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23223 | xfs: fix UAF in xchk_btree_check_block_owner | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23228 | smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23229 | crypto: virtio - Add spinlock protection with virtqueue notification | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-21258 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 48%ile | Microsoft | 2026-02-10 |
| CVE-2026-21261 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 48%ile | Microsoft | 2026-02-10 |
| CVE-2026-21222 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-02-10 |
| CVE-2026-23217 | riscv: trace: fix snapshot deadlock with sbi ecall | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-02-10 |
| CVE-2026-23224 | erofs: fix UAF issue for file-backed mounts w/ directio option | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-23225 | sched/mmcid: Don't assume CID is CPU owned on mode switch | MEDIUM | 5.3 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-2443 | Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure | MEDIUM | 5.3 | 38%ile | Microsoft | 2026-02-10 |
| CVE-2026-28419 | Vim has Heap-based Buffer Underflow in Emacs tags parsing | MEDIUM | 5.3 | 6%ile | Microsoft | 2026-02-10 |
| CVE-2026-28421 | Vim has a heap-buffer-overflow and a segmentation fault | MEDIUM | 5.3 | 8%ile | Microsoft | 2026-02-10 |
| CVE-2026-1979 | mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free | MEDIUM | 5.3 | 6%ile | Microsoft | 2026-02-10 |
| CVE-2026-2243 | Qemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsing | MEDIUM | 5.1 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-23110 | scsi: core: Wake up the error handler when final completions race against each other | MEDIUM | 4.7 | 1%ile | Microsoft | 2026-02-10 |
| CVE-2026-23118 | rxrpc: Fix data-race warning and potential load/store tearing | MEDIUM | 4.7 | 0%ile | Microsoft | 2026-02-10 |
| CVE-2026-23126 | netdevsim: fix a race issue related to the operation on bpf_bound_progs list | MEDIUM | 4.7 | 0%ile | Microsoft | 2026-02-10 |
| CVE-2026-23169 | mptcp: fix race in mptcp_pm_nl_flush_addrs_doit() | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-02-10 |
| CVE-2026-21517 | Windows App for Mac Installer Elevation of Privilege Vulnerability | MEDIUM | 4.7 | 31%ile | Microsoft | 2026-02-10 |
| CVE-2025-11563 | wcurl path traversal with percent-encoded slashes | MEDIUM | 4.6 | 30%ile | Microsoft | 2026-02-10 |
| CVE-2026-28417 | Vim has OS Command Injection in netrw | MEDIUM | 4.4 | 66%ile | Microsoft | 2026-02-10 |
| CVE-2026-28418 | Vim has Heap-based Buffer Overflow in Emacs tags parsing | MEDIUM | 4.4 | 13%ile | Microsoft | 2026-02-10 |
| CVE-2026-28420 | Vim has Heap-based Buffer Overflow and OOB Read in :terminal | MEDIUM | 4.4 | 8%ile | Microsoft | 2026-02-10 |
| CVE-2025-71230 | hfs: ensure sb->s_fs_info is always cleaned up | MEDIUM | 4.2 | 2%ile | Microsoft | 2026-02-10 |
| CVE-2026-21249 | Windows NTLM Spoofing Vulnerability | LOW | 3.3 | 96%ile | Microsoft | 2026-02-10 |
| CVE-2026-0102 | Microsoft Edge (Chromium-based) Defense in Depth Vulnerability | LOW | 3.1 | 41%ile | Microsoft | 2026-02-10 |
| CVE-2026-27171 | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts | LOW | 2.9 | 14%ile | Microsoft | 2026-02-10 |
| CVE-2025-69873 | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the | LOW | 2.9 | 42%ile | Microsoft | 2026-02-10 |
| CVE-2026-28422 | Vim has stack-buffer-overflow in build_stl_str_hl() | LOW | 2.2 | 4%ile | Microsoft | 2026-02-10 |
| CVE-2026-1703 | Limited path traversal when installing wheel archives | UNKNOWN | — | 35%ile | Microsoft | 2026-02-10 |
| CVE-2026-21620 | TFTP Path Traversal | UNKNOWN | — | 39%ile | Microsoft | 2026-02-10 |
| CVE-2026-27199 | Werkzeug safe_join() allows Windows special device names | UNKNOWN | — | 45%ile | Microsoft | 2026-02-10 |
| CVE-2026-2739 | This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state | UNKNOWN | — | 40%ile | Microsoft | 2026-02-10 |
| CVE-2026-27965 | Vitess users with backup storage access can gain unauthorized access to production deployment environments | UNKNOWN | — | 36%ile | Microsoft | 2026-02-10 |
| CVE-2026-27969 | Vitess users with backup storage access can write to arbitrary file paths on restore | UNKNOWN | — | 34%ile | Microsoft | 2026-02-10 |
| CVE-2026-2320 | Chromium: CVE-2026-2320 Inappropriate implementation in File input | UNKNOWN | — | 13%ile | Microsoft | 2026-02-10 |
| CVE-2026-1861 | Chromium: CVE-2026-1861 Heap buffer overflow in libvpx | UNKNOWN | — | 37%ile | Microsoft | 2026-02-10 |
| CVE-2026-2441 | Chromium: CVE-2026-2441 Use after free in CSS | UNKNOWN | — | 98%ile | Microsoft | 2026-02-10 |
| CVE-2026-2323 | Chromium: CVE-2026-2323 Inappropriate implementation in Downloads | UNKNOWN | — | 14%ile | Microsoft | 2026-02-10 |
| CVE-2026-2319 | Chromium: CVE-2026-2319 Race in DevTools | UNKNOWN | — | 12%ile | Microsoft | 2026-02-10 |
| CVE-2026-2316 | Chromium: CVE-2026-2316 Insufficient policy enforcement in Frames | UNKNOWN | — | 15%ile | Microsoft | 2026-02-10 |
| CVE-2026-2314 | Chromium: CVE-2026-2314 Heap buffer overflow in Codecs | UNKNOWN | — | 91%ile | Microsoft | 2026-02-10 |
| CVE-2026-3063 | Chromium: CVE-2026-3063 Inappropriate implementation in DevTools | UNKNOWN | — | 8%ile | Microsoft | 2026-02-10 |
| CVE-2026-1862 | Chromium: CVE-2026-1862 Type Confusion in V8 | UNKNOWN | — | 47%ile | Microsoft | 2026-02-10 |
| CVE-2026-2318 | CVE-2026-2318 | UNKNOWN | — | 15%ile | Microsoft | 2026-02-10 |
| CVE-2026-2313 | Chromium: CVE-2026-2313 Use after free in CSS | UNKNOWN | — | 91%ile | Microsoft | 2026-02-10 |
| CVE-2026-2322 | Chromium: CVE-2026-2322 Heap buffer overflow in Codecs | UNKNOWN | — | 14%ile | Microsoft | 2026-02-10 |
| CVE-2026-2649 | Chromium: CVE-2026-2649 Integer overflow in V8 | UNKNOWN | — | 50%ile | Microsoft | 2026-02-10 |
| CVE-2026-2648 | Chromium: CVE-2026-2648 Heap buffer overflow in PDFium | UNKNOWN | — | 41%ile | Microsoft | 2026-02-10 |
| CVE-2026-3062 | Chromium: CVE-2026-3062 Out of bounds read and write in Tint | UNKNOWN | — | 28%ile | Microsoft | 2026-02-10 |
| CVE-2026-3061 | Chromium: CVE-2026-3061 Out of bounds read in Media | UNKNOWN | — | 24%ile | Microsoft | 2026-02-10 |
| CVE-2026-2317 | Chromium: CVE-2026-2317 Inappropriate implementation in Animation | UNKNOWN | — | 11%ile | Microsoft | 2026-02-10 |
| CVE-2026-2650 | Chromium: CVE-2026-2650 Heap buffer overflow in Media | UNKNOWN | — | 43%ile | Microsoft | 2026-02-10 |
| CVE-2026-24304 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 49%ile | Microsoft | 2026-01-13 |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98%ile | Microsoft | 2026-01-13 |
| CVE-2026-24306 | Azure Front Door Elevation of Privilege Vulnerability | CRITICAL | 9.8 | 55%ile | Microsoft | 2026-01-13 |
| CVE-2025-68789 | hwmon: (ibmpex) fix use-after-free in high/low store | CRITICAL | 9.8 | — | Microsoft | 2026-01-13 |
| CVE-2025-68814 | io_uring: fix filename leak in __io_openat_prep() | CRITICAL | 9.8 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68819 | media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() | CRITICAL | 9.8 | 5%ile | Microsoft | 2026-01-13 |
| CVE-2025-68822 | Input: alps - fix use-after-free bugs caused by dev3_register_work | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-68823 | ublk: fix deadlock when reading partition table | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71064 | net: hns3: using the num_tqps in the vf driver to apply for resources | CRITICAL | 9.8 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-71072 | shmem: fix recovery on rename failures | CRITICAL | 9.8 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2025-71073 | Input: lkkbd - disable pending work before freeing device | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71074 | functionfs: fix the open/removal races | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-01-13 |
| CVE-2025-71098 | ip6_gre: make ip6gre_header() robust | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71066 | net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change | CRITICAL | 9.8 | 7%ile | Microsoft | 2026-01-13 |
| CVE-2026-21264 | Microsoft Account Spoofing Vulnerability | CRITICAL | 9.3 | 32%ile | Microsoft | 2026-01-13 |
| CVE-2026-24305 | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2026-24307 | M365 Copilot Information Disclosure Vulnerability | CRITICAL | 9.3 | 56%ile | Microsoft | 2026-01-13 |
| CVE-2026-0899 | Chromium: CVE-2026-0899 Out of bounds memory access in V8 | HIGH | 8.8 | 36%ile | Microsoft | 2026-01-13 |
| CVE-2026-20868 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 71%ile | Microsoft | 2026-01-13 |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2026-01-13 |
| CVE-2025-69194 | Wget2: arbitrary file write via metalink path traversal in gnu wget2 | HIGH | 8.8 | 55%ile | Microsoft | 2026-01-13 |
| CVE-2025-15444 | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium | HIGH | 8.6 | 19%ile | Microsoft | 2026-01-13 |
| CVE-2025-68782 | scsi: target: Reset t_task_cdb pointer in error case | HIGH | 8.6 | 47%ile | Microsoft | 2026-01-13 |
| CVE-2026-20944 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2026-20952 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2026-20953 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 47%ile | Microsoft | 2026-01-13 |
| CVE-2026-21227 | Azure Logic Apps Elevation of Privilege Vulnerability | HIGH | 8.2 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2026-20856 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | HIGH | 8.1 | 65%ile | Microsoft | 2026-01-13 |
| CVE-2025-62291 | In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted | HIGH | 8.1 | 61%ile | Microsoft | 2026-01-13 |
| CVE-2026-20931 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 8.0 | 57%ile | Microsoft | 2026-01-13 |
| CVE-2026-20960 | PowerApps Desktop Client Remote Code Execution Vulnerability | HIGH | 8.0 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2023-31096 | MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2024-55414 | Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 65%ile | Microsoft | 2026-01-13 |
| CVE-2026-20809 | Windows Kernel Memory Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2026-20810 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20811 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20816 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 84%ile | Microsoft | 2026-01-13 |
| CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 92%ile | Microsoft | 2026-01-13 |
| CVE-2026-20820 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 85%ile | Microsoft | 2026-01-13 |
| CVE-2026-20822 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-01-13 |
| CVE-2026-20826 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20831 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20832 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2026-20837 | Windows Media Remote Code Execution Vulnerability | HIGH | 7.8 | 52%ile | Microsoft | 2026-01-13 |
| CVE-2026-20840 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 91%ile | Microsoft | 2026-01-13 |
| CVE-2026-20843 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 89%ile | Microsoft | 2026-01-13 |
| CVE-2026-20857 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2026-20858 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20859 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2026-20860 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 95%ile | Microsoft | 2026-01-13 |
| CVE-2026-20861 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20864 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 45%ile | Microsoft | 2026-01-13 |
| CVE-2026-20865 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-01-13 |
| CVE-2026-20866 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20867 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20870 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-20871 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 90%ile | Microsoft | 2026-01-13 |
| CVE-2026-20873 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20874 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20877 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-01-13 |
| CVE-2026-20918 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-01-13 |
| CVE-2026-20920 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20922 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 64%ile | Microsoft | 2026-01-13 |
| CVE-2026-20923 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2026-01-13 |
| CVE-2026-20924 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-01-13 |
| CVE-2026-20938 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-20940 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2026-20941 | Host Process for Windows Tasks Elevation of Privilege Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2026-20946 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-20948 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 48%ile | Microsoft | 2026-01-13 |
| CVE-2026-20949 | Microsoft Excel Security Feature Bypass Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-20950 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20951 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.8 | 55%ile | Microsoft | 2026-01-13 |
| CVE-2026-20955 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 48%ile | Microsoft | 2026-01-13 |
| CVE-2026-20956 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-20957 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-21224 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-01-13 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | HIGH | 7.8 | 99%ile | Microsoft | 2026-01-13 |
| CVE-2025-61731 | Arbitrary file write using cgo pkg-config directive in cmd/go | HIGH | 7.8 | 46%ile | Microsoft | 2026-01-13 |
| CVE-2025-68786 | ksmbd: skip lock-range check on equal size to avoid size==0 underflow | HIGH | 7.8 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-68801 | mlxsw: spectrum_router: Fix neighbour use-after-free | HIGH | 7.8 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-68817 | ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency | HIGH | 7.8 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2025-71068 | svcrdma: bound check rq_pages index in inline path | HIGH | 7.8 | 29%ile | Microsoft | 2026-01-13 |
| CVE-2025-71089 | iommu: disable SVA when CONFIG_X86 is set | HIGH | 7.8 | 6%ile | Microsoft | 2026-01-13 |
| CVE-2025-71101 | platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing | HIGH | 7.8 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71109 | MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits | HIGH | 7.8 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-71122 | iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED | HIGH | 7.8 | 12%ile | Microsoft | 2026-01-13 |
| CVE-2025-71152 | net: dsa: properly keep track of conduit reference | HIGH | 7.8 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2026-22184 | zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname() | HIGH | 7.8 | 36%ile | Microsoft | 2026-01-13 |
| CVE-2026-22980 | nfsd: provide locking for v4_end_grace | HIGH | 7.8 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-68753 | ALSA: firewire-motu: add bounds check in put_user loop for DSP events | HIGH | 7.8 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71162 | dmaengine: tegra-adma: Fix use-after-free | HIGH | 7.8 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2026-20804 | Windows Hello Tampering Vulnerability | HIGH | 7.7 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20852 | Windows Hello Tampering Vulnerability | HIGH | 7.7 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2025-69195 | Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls | HIGH | 7.6 | 28%ile | Microsoft | 2026-01-13 |
| CVE-2026-0386 | Windows Deployment Services Remote Code Execution Vulnerability | HIGH | 7.5 | 45%ile | Microsoft | 2026-01-13 |
| CVE-2026-20848 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-01-13 |
| CVE-2026-20849 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-01-13 |
| CVE-2026-20854 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-01-13 |
| CVE-2026-20875 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | HIGH | 7.5 | 74%ile | Microsoft | 2026-01-13 |
| CVE-2026-20919 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 55%ile | Microsoft | 2026-01-13 |
| CVE-2026-20921 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 67%ile | Microsoft | 2026-01-13 |
| CVE-2026-20926 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 55%ile | Microsoft | 2026-01-13 |
| CVE-2026-20929 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.5 | 86%ile | Microsoft | 2026-01-13 |
| CVE-2026-20934 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-01-13 |
| CVE-2026-20965 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 7.5 | 14%ile | Microsoft | 2026-01-13 |
| CVE-2026-21226 | Azure Core shared client library for Python Remote Code Execution Vulnerability | HIGH | 7.5 | 59%ile | Microsoft | 2026-01-13 |
| CVE-2026-21520 | Copilot Studio Information Disclosure Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2026-01-13 |
| CVE-2025-61726 | Memory exhaustion in query parameter parsing in net/url | HIGH | 7.5 | 82%ile | Microsoft | 2026-01-13 |
| CVE-2025-68151 | CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages | HIGH | 7.5 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2026-0897 | Denial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata | HIGH | 7.5 | 27%ile | Microsoft | 2026-01-13 |
| CVE-2026-21441 | urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) | HIGH | 7.5 | 87%ile | Microsoft | 2026-01-13 |
| CVE-2026-0719 | Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication | HIGH | 7.5 | 48%ile | Microsoft | 2026-01-13 |
| CVE-2026-23490 | pyasn1 has a DoS vulnerability in decoder | HIGH | 7.5 | 54%ile | Microsoft | 2026-01-13 |
| CVE-2026-20844 | Windows Clipboard Server Elevation of Privilege Vulnerability | HIGH | 7.4 | 26%ile | Microsoft | 2026-01-13 |
| CVE-2026-20853 | Windows WalletService Elevation of Privilege Vulnerability | HIGH | 7.4 | 25%ile | Microsoft | 2026-01-13 |
| CVE-2026-21521 | Word Copilot Information Disclosure Vulnerability | HIGH | 7.4 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2026-21524 | Azure Data Explorer Information Disclosure Vulnerability | HIGH | 7.4 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2026-0861 | Integer overflow in memalign leads to heap corruption | HIGH | 7.3 | 33%ile | Microsoft | 2026-01-13 |
| CVE-2026-20803 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 7.2 | 68%ile | Microsoft | 2026-01-13 |
| CVE-2026-21223 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | HIGH | 7.1 | 20%ile | Microsoft | 2026-01-13 |
| CVE-2025-24528 | In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update | HIGH | 7.1 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2025-68756 | block: Use RCU in blk_mq_[un]quiesce_tagset() instead of set->tag_list_lock | HIGH | 7.1 | 8%ile | Microsoft | 2026-01-13 |
| CVE-2025-68759 | wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring() | HIGH | 7.1 | 9%ile | Microsoft | 2026-01-13 |
| CVE-2025-68771 | ocfs2: fix kernel BUG in ocfs2_find_victim_chain | HIGH | 7.1 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68785 | net: openvswitch: fix middle attribute validation in push_nsh() action | HIGH | 7.1 | 5%ile | Microsoft | 2026-01-13 |
| CVE-2025-68795 | ethtool: Avoid overflowing userspace buffer on stats query | HIGH | 7.1 | 6%ile | Microsoft | 2026-01-13 |
| CVE-2025-68800 | mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats | HIGH | 7.1 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-68815 | net/sched: ets: Remove drr class from the active list if it changes to strict | HIGH | 7.1 | 5%ile | Microsoft | 2026-01-13 |
| CVE-2025-71081 | ASoC: stm32: sai: fix OF node leak on probe | HIGH | 7.1 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71082 | Bluetooth: btusb: revert use of devm_kzalloc in btusb | HIGH | 7.1 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71087 | iavf: fix off-by-one issues in iavf_config_rss_reg() | HIGH | 7.1 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71093 | e1000: fix OOB in e1000_tbi_should_accept() | HIGH | 7.1 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2025-71096 | RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly | HIGH | 7.1 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71105 | f2fs: use global inline_xattr_slab instead of per-sb slab cache | HIGH | 7.1 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71114 | via_wdt: fix critical boot hang due to unnamed resource allocation | HIGH | 7.1 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71130 | drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer | HIGH | 7.1 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71133 | RDMA/irdma: avoid invalid read in irdma_net_event | HIGH | 7.1 | 8%ile | Microsoft | 2026-01-13 |
| CVE-2025-71143 | clk: samsung: exynos-clkout: Assign .num before accessing .hws | HIGH | 7.1 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2026-22984 | libceph: prevent potential out-of-bounds reads in handle_auth_done() | HIGH | 7.1 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2025-68766 | irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc() | HIGH | 7.1 | 9%ile | Microsoft | 2026-01-13 |
| CVE-2025-68808 | media: vidtv: initialize local pointers upon transfer of memory ownership | HIGH | 7.1 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71067 | ntfs: set dummy blocksize to read boot_block when mounting | HIGH | 7.1 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2026-20808 | Windows File Explorer Elevation of Privilege Vulnerability | HIGH | 7.0 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20814 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20815 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20830 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20836 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20842 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.0 | 34%ile | Microsoft | 2026-01-13 |
| CVE-2026-20863 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 34%ile | Microsoft | 2026-01-13 |
| CVE-2026-20869 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | HIGH | 7.0 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20943 | Microsoft Office Click-To-Run Remote Code Execution Vulnerability | HIGH | 7.0 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-21219 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | HIGH | 7.0 | 32%ile | Microsoft | 2026-01-13 |
| CVE-2026-21221 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-01-13 |
| CVE-2025-68119 | Unexpected code execution when invoking toolchain in cmd/go | HIGH | 7.0 | 29%ile | Microsoft | 2026-01-13 |
| CVE-2025-68781 | usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal | HIGH | 7.0 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-71075 | scsi: aic94xx: fix use-after-free in device removal path | HIGH | 7.0 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2026-22801 | LIBPNG has an integer truncation causing heap buffer over-read in png_image_write_* | MEDIUM | 6.8 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2026-20876 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2025-68816 | net/mlx5: fw_tracer, Validate format string parameters | MEDIUM | 6.6 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2026-20812 | LDAP Tampering Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-01-13 |
| CVE-2026-20847 | Microsoft Windows File Explorer Spoofing Vulnerability | MEDIUM | 6.5 | 71%ile | Microsoft | 2026-01-13 |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5 | 97%ile | Microsoft | 2026-01-13 |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5 | 97%ile | Microsoft | 2026-01-13 |
| CVE-2025-61728 | Excessive CPU consumption when building archive index in archive/zip | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-01-13 |
| CVE-2025-68468 | Avahi has a reachable assertion in lookup_multicast_callback | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-01-13 |
| CVE-2025-68471 | Avahi has a reachable assertion in lookup_start | MEDIUM | 6.5 | 35%ile | Microsoft | 2026-01-13 |
| CVE-2025-68775 | net/handshake: duplicate handshake cancellations leak socket | MEDIUM | 6.5 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2025-71097 | ipv4: Fix reference count leak when using error routes with nexthop objects | MEDIUM | 6.5 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2026-21265 | Secure Boot Certificate Expiration Security Feature Bypass Vulnerability | MEDIUM | 6.4 | 63%ile | Microsoft | 2026-01-13 |
| CVE-2025-68809 | ksmbd: vfs: fix race on m_flags in vfs_cache | MEDIUM | 6.3 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2025-71091 | team: fix check for port enabled in team_queue_override_port_prio_changed() | MEDIUM | 6.3 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71111 | hwmon: (w83791d) Convert macros to functions to avoid TOCTOU | MEDIUM | 6.3 | 1%ile | Microsoft | 2026-01-13 |
| CVE-2026-20818 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 6.2 | 53%ile | Microsoft | 2026-01-13 |
| CVE-2026-20821 | Remote Procedure Call Information Disclosure Vulnerability | MEDIUM | 6.2 | 52%ile | Microsoft | 2026-01-13 |
| CVE-2026-20851 | Capability Access Management Service (camsvc) Information Disclosure Vulnerability | MEDIUM | 6.2 | 47%ile | Microsoft | 2026-01-13 |
| CVE-2026-20935 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | MEDIUM | 6.2 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2025-15281 | wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory | MEDIUM | 6.2 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2025-68778 | btrfs: don't log conflicting inode if it's a dir moved in the current transaction | MEDIUM | 6.1 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-68794 | iomap: adjust read range correctly for non-block-aligned positions | MEDIUM | 6.1 | 47%ile | Microsoft | 2026-01-13 |
| CVE-2026-22695 | LIBPNG has a heap buffer over-read in png_image_read_direct_scaled (regression from CVE-2025-65018 fix) | MEDIUM | 6.1 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-13034 | No QUIC certificate pinning with GnuTLS | MEDIUM | 5.9 | 16%ile | Microsoft | 2026-01-13 |
| CVE-2025-14017 | broken TLS options for threaded LDAPS | MEDIUM | 5.9 | 2%ile | Microsoft | 2026-01-13 |
| CVE-2026-0990 | Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing | MEDIUM | 5.9 | 58%ile | Microsoft | 2026-01-13 |
| CVE-2025-68798 | perf/x86/amd: Check event before enable to avoid GPF | MEDIUM | 5.8 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 92%ile | Microsoft | 2026-01-13 |
| CVE-2026-20819 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | MEDIUM | 5.5 | 45%ile | Microsoft | 2026-01-13 |
| CVE-2026-20823 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-20824 | Windows Remote Assistance Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 57%ile | Microsoft | 2026-01-13 |
| CVE-2026-20827 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability | MEDIUM | 5.5 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-20829 | TPM Trustlet Information Disclosure Vulnerability | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-01-13 |
| CVE-2026-20833 | Windows Kerberos Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2026-20835 | Capability Access Management Service (camsvc) Information Disclosure Vulnerability | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-01-13 |
| CVE-2026-20838 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-20839 | Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2026-20862 | Windows Management Services Information Disclosure Vulnerability | MEDIUM | 5.5 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-20932 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 51%ile | Microsoft | 2026-01-13 |
| CVE-2026-20937 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20939 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2025-68276 | Avahi has a reachable assertion in avahi_wide_area_scan_cache | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-01-13 |
| CVE-2025-68755 | staging: most: remove broken i2c driver | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-01-13 |
| CVE-2025-68757 | drm/vgem-fence: Fix potential deadlock on release | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-01-13 |
| CVE-2025-68758 | backlight: led-bl: Add devlink to supplier LEDs | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-01-13 |
| CVE-2025-68763 | crypto: starfive - Correctly handle return of sg_nents_for_len | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68764 | NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-68765 | mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add() | MEDIUM | 5.5 | 9%ile | Microsoft | 2026-01-13 |
| CVE-2025-68767 | hfsplus: Verify inode mode when loading from disk | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68768 | inet: frags: flush pending skbs in fqdir_pre_exit() | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-68769 | f2fs: fix return value of f2fs_recover_fsync_data() | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-68773 | spi: fsl-cpm: Check length parity before switching to 16 bit mode | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68774 | hfsplus: fix missing hfs_bnode_get() in __hfs_bnode_create | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-01-13 |
| CVE-2025-68776 | net/hsr: fix NULL pointer dereference in prp_get_untagged_frame() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68777 | Input: ti_am335x_tsc - fix off-by-one error in wire_order validation | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-68780 | sched/deadline: only set free_cpus for online runqueues | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68787 | netrom: Fix memory leak in nr_sendmsg() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68788 | fsnotify: do not generate ACCESS/MODIFY events on child for special files | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68797 | char: applicom: fix NULL pointer dereference in ac_ioctl | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2025-68803 | NFSD: NFSv4 file creation neglects setting ACL | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2025-68806 | ksmbd: fix buffer validation by including null terminator size in EA length | MEDIUM | 5.5 | 37%ile | Microsoft | 2026-01-13 |
| CVE-2025-68818 | scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path" | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2025-71069 | f2fs: invalidate dentry cache on failed whiteout creation | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-71077 | tpm: Cap the number of PCR banks | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71079 | net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-01-13 |
| CVE-2025-71083 | drm/ttm: Avoid NULL pointer deref for evicted BOs | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71084 | RDMA/cm: Fix leaking the multicast GID table reference | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71088 | mptcp: fallback earlier on simult connection | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71095 | net: stmmac: fix the crash issue for zero copy XDP_TX action | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2025-71102 | scs: fix a wrong parameter in __scs_magic | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71107 | f2fs: ensure node page reads complete before f2fs_put_super() finishes | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-01-13 |
| CVE-2025-71108 | usb: typec: ucsi: Handle incorrect num_connectors capability | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71112 | net: hns3: add VLAN id validation before using | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-01-13 |
| CVE-2025-71113 | crypto: af_alg - zero initialize memory allocated via sock_kmalloc | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71116 | libceph: make decode_pool() more resilient against corrupted osdmaps | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-01-13 |
| CVE-2025-71118 | ACPICA: Avoid walking the Namespace if start_node is NULL | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71120 | SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2025-71121 | parisc: Do not reprogram affinitiy on ASP chip | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71125 | tracing: Do not register unsupported perf events | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-01-13 |
| CVE-2025-71127 | wifi: mac80211: Discard Beacon frames to non-broadcast address | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-01-13 |
| CVE-2025-71129 | LoongArch: BPF: Sign extend kfunc call arguments | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71131 | crypto: seqiv - Do not use req->iv after crypto_aead_encrypt | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2025-71132 | smc91x: fix broken irq-context in PREEMPT_RT | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-01-13 |
| CVE-2025-71136 | media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71137 | octeontx2-pf: fix "UBSAN: shift-out-of-bounds error" | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-01-13 |
| CVE-2025-71138 | drm/msm/dpu: Add missing NULL pointer check for pingpong interface | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-71147 | KEYS: trusted: Fix a memory leak in tpm2_load_cmd | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-01-13 |
| CVE-2025-71150 | ksmbd: Fix refcount leak when invalid session is found on session lookup | MEDIUM | 5.5 | 16%ile | Microsoft | 2026-01-13 |
| CVE-2025-71154 | net: usb: rtl8150: fix memory leak on usb_submit_urb() failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-01-13 |
| CVE-2025-71160 | netfilter: nf_tables: avoid chain re-validation if possible | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-01-13 |
| CVE-2025-71161 | dm-verity: disable recursive forward error correction | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-01-13 |
| CVE-2025-71163 | dmaengine: idxd: fix device leaks on compat bind and unbind | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-71183 | btrfs: always detect conflicting inodes when logging inode refs | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-01-13 |
| CVE-2025-71184 | btrfs: fix NULL dereference on root when tracing inode eviction | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-01-13 |
| CVE-2026-22976 | net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2026-22977 | net: sock: fix hardened usercopy panic in sock_recv_errqueue | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2026-22979 | net: fix memory leak in skb_segment_list for GRO packets | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2026-22982 | net: mscc: ocelot: Fix crash when adding interface under a lag | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2026-22990 | libceph: replace overzealous BUG_ON in osdmap_apply_incremental() | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-01-13 |
| CVE-2026-22991 | libceph: make free_choose_arg_map() resilient to partial allocation | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-01-13 |
| CVE-2026-22992 | libceph: return the handler error from mon_handle_auth_done() | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-22996 | net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-01-13 |
| CVE-2026-22997 | net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-22998 | nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec | MEDIUM | 5.5 | 53%ile | Microsoft | 2026-01-13 |
| CVE-2026-22999 | net/sched: sch_qfq: do not free existing class in qfq_change_class() | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-01-13 |
| CVE-2026-23000 | net/mlx5e: Fix crash on profile change rollback failure | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-01-13 |
| CVE-2025-71115 | um: init cpu_tasks[] earlier | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2026-21444 | libtpms returns wrong initialization vector when certain symmetric ciphers are used | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-01-13 |
| CVE-2026-20958 | Microsoft SharePoint Information Disclosure Vulnerability | MEDIUM | 5.4 | 28%ile | Microsoft | 2026-01-13 |
| CVE-2026-20927 | Windows SMB Server Denial of Service Vulnerability | MEDIUM | 5.3 | 59%ile | Microsoft | 2026-01-13 |
| CVE-2025-14524 | bearer token leak on cross-protocol redirect | MEDIUM | 5.3 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2025-15079 | libssh global known_hosts override | MEDIUM | 5.3 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2025-56226 | Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode | MEDIUM | 5.3 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2025-61730 | Handshake messages may be processed at the incorrect encryption level in crypto/tls | MEDIUM | 5.3 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2025-68799 | caif: fix integer underflow in cffrml_receive() | MEDIUM | 5.3 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-0915 | getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler | MEDIUM | 5.3 | 49%ile | Microsoft | 2026-01-13 |
| CVE-2026-22693 | Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS | MEDIUM | 5.3 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-22701 | filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock | MEDIUM | 5.3 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-14819 | OpenSSL partial chain store policy bypass | MEDIUM | 5.3 | 53%ile | Microsoft | 2026-01-13 |
| CVE-2026-21860 | Werkzeug safe_join() allows Windows special device names with compound extensions | MEDIUM | 5.3 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2025-68772 | f2fs: fix to avoid updating compression context during writeback | MEDIUM | 5.0 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-68796 | f2fs: fix to avoid updating zero-sized extent in extent cache | MEDIUM | 5.0 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2025-71065 | f2fs: fix to avoid potential deadlock | MEDIUM | 5.0 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2026-0716 | Libsoup: out-of-bounds read in libsoup websocket frame processing | MEDIUM | 4.8 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2025-71078 | powerpc/64s/slb: Fix SLB multihit issue during SLB preload | MEDIUM | 4.7 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2025-71119 | powerpc/kexec: Enable SMT before waking offline CPUs | MEDIUM | 4.7 | 4%ile | Microsoft | 2026-01-13 |
| CVE-2026-23004 | dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-01-13 |
| CVE-2026-20828 | Windows rndismp6.sys Information Disclosure Vulnerability | MEDIUM | 4.6 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-20834 | Windows Spoofing Vulnerability | MEDIUM | 4.6 | 53%ile | Microsoft | 2026-01-13 |
| CVE-2026-20959 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 94%ile | Microsoft | 2026-01-13 |
| CVE-2025-68783 | ALSA: usb-mixer: us16x08: validate meter packet indices | MEDIUM | 4.6 | 10%ile | Microsoft | 2026-01-13 |
| CVE-2026-22702 | virtualenv Has TOCTOU Vulnerabilities in Directory Creation | MEDIUM | 4.5 | 1%ile | Microsoft | 2026-01-13 |
| CVE-2026-20825 | Windows Hyper-V Information Disclosure Vulnerability | MEDIUM | 4.4 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2026-20962 | Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability | MEDIUM | 4.4 | 37%ile | Microsoft | 2026-01-13 |
| CVE-2026-20936 | Windows NDIS Information Disclosure Vulnerability | MEDIUM | 4.3 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2026-0989 | Libxml2: unbounded relaxng include recursion leading to stack overflow | LOW | 3.7 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2025-15504 | lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference | LOW | 3.3 | 19%ile | Microsoft | 2026-01-13 |
| CVE-2026-22978 | wifi: avoid kernel-infoleak from struct iw_point | LOW | 3.3 | 2%ile | Microsoft | 2026-01-13 |
| CVE-2025-15224 | libssh key passphrase bypass without agent set | LOW | 3.1 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2025-13151 | CVE-2025-13151 | LOW | 2.9 | 65%ile | Microsoft | 2026-01-13 |
| CVE-2026-0992 | Libxml2: libxml2: denial of service via crafted xml catalogs | LOW | 2.9 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2025-71094 | net: usb: asix: validate PHY address before use | LOW | 1.8 | 3%ile | Microsoft | 2026-01-13 |
| CVE-2026-0628 | Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag | UNKNOWN | — | 94%ile | Microsoft | 2026-01-13 |
| CVE-2026-0900 | Chromium: CVE-2026-0900 Inappropriate implementation in V8 | UNKNOWN | — | 29%ile | Microsoft | 2026-01-13 |
| CVE-2026-0901 | Chromium: CVE-2026-0901 Inappropriate implementation in Blink | UNKNOWN | — | 11%ile | Microsoft | 2026-01-13 |
| CVE-2026-0902 | Chromium: CVE-2026-0902 Inappropriate implementation in V8 | UNKNOWN | — | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-0903 | Chromium: CVE-2026-0903 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 10%ile | Microsoft | 2026-01-13 |
| CVE-2026-0904 | Chromium: CVE-2026-0904 Incorrect security UI in Digital Credentials | UNKNOWN | — | 9%ile | Microsoft | 2026-01-13 |
| CVE-2026-0905 | Chromium: CVE-2026-0905 Insufficient policy enforcement in Network | UNKNOWN | — | 16%ile | Microsoft | 2026-01-13 |
| CVE-2026-0906 | Chromium: CVE-2026-0906 Incorrect security UI | UNKNOWN | — | 28%ile | Microsoft | 2026-01-13 |
| CVE-2026-0907 | Chromium: CVE-2026-0907 Incorrect security UI in Split View | UNKNOWN | — | 95%ile | Microsoft | 2026-01-13 |
| CVE-2026-0908 | Chromium: CVE-2026-0908 Use after free in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-01-13 |
| CVE-2026-1220 | Chromium: CVE-2026-1220 Race in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-1504 | Chromium: CVE-2026-1504 Inappropriate implementation in Background Fetch API | UNKNOWN | — | 14%ile | Microsoft | 2026-01-13 |
| CVE-2026-21895 | rsa crate has potential panic on a prime being equal to 1 | UNKNOWN | — | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-22185 | OpenLDAP <= 2.6.10 LMDB mdb_load Heap Buffer Underflow in readline() | UNKNOWN | — | 4%ile | Microsoft | 2026-01-13 |
| CVE-2026-24821 | A heap-based buffer over-read that might affect a system that compiles untrusted Lua code in turanszkij/WickedEngine. | UNKNOWN | — | 26%ile | Microsoft | 2026-01-13 |
| CVE-2025-55241 | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 74%ile | Microsoft | 2025-09-09 |
| CVE-2025-54914 | Azure Networking Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 83%ile | Microsoft | 2025-09-09 |
| CVE-2025-39743 | jfs: truncate good inode pages when hard link is 0 | CRITICAL | 9.8 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-57052 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c | CRITICAL | 9.8 | 53%ile | Microsoft | 2025-09-09 |
| CVE-2025-55232 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability | CRITICAL | 9.8 | 80%ile | Microsoft | 2025-09-09 |
| CVE-2025-38714 | hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() | CRITICAL | 9.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-55244 | Azure Bot Service Elevation of Privilege Vulnerability | CRITICAL | 9.0 | 48%ile | Microsoft | 2025-09-09 |
| CVE-2025-47906 | Unexpected paths returned from LookPath in os/exec | HIGH | 8.8 | 43%ile | Microsoft | 2025-09-09 |
| CVE-2025-9900 | Libtiff: libtiff write-what-where | HIGH | 8.8 | 55%ile | Microsoft | 2025-09-09 |
| CVE-2025-54106 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 71%ile | Microsoft | 2025-09-09 |
| CVE-2025-54110 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 90%ile | Microsoft | 2025-09-09 |
| CVE-2025-54897 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-54918 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-54113 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2025-09-09 |
| CVE-2025-55227 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 70%ile | Microsoft | 2025-09-09 |
| CVE-2025-55234 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-55319 | Agentic AI and Visual Studio Code Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2025-09-09 |
| CVE-2025-54910 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 45%ile | Microsoft | 2025-09-09 |
| CVE-2025-59362 | Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c. | HIGH | 8.2 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-9566 | Podman: podman kube play command may overwrite host files | HIGH | 8.1 | 64%ile | Microsoft | 2025-09-09 |
| CVE-2025-58060 | cups has Authentication bypass with AuthType Negotiate | HIGH | 8.0 | 60%ile | Microsoft | 2025-09-09 |
| CVE-2023-53187 | btrfs: fix use-after-free of new block group that became unused | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2023-53218 | rxrpc: Make it so that a waiting process can be aborted | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38685 | fbdev: Fix vmalloc out-of-bounds write in fast_imageblit | HIGH | 7.8 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38699 | scsi: bfa: Double-free fix | HIGH | 7.8 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-38702 | fbdev: fix potential buffer overflow in do_register_framebuffer() | HIGH | 7.8 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-38718 | sctp: linearize cloned gso packets in sctp_rcv | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38724 | nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() | HIGH | 7.8 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-38729 | ALSA: usb-audio: Validate UAC3 power domain descriptors, too | HIGH | 7.8 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39689 | ftrace: Also allocate and copy hash for reading of filter files | HIGH | 7.8 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39691 | fs/buffer: fix use-after-free when call bh_read() helper | HIGH | 7.8 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39730 | NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() | HIGH | 7.8 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2025-39738 | btrfs: do not allow relocation of partially dropped subvolumes | HIGH | 7.8 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39757 | ALSA: usb-audio: Validate UAC3 cluster segment descriptors | HIGH | 7.8 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39766 | net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit | HIGH | 7.8 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39776 | mm/debug_vm_pgtable: clear page table entries at destroy_args() | HIGH | 7.8 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39810 | bnxt_en: Fix memory corruption when FW resources change during ifdown | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39823 | KVM: x86: use array_index_nospec with indices that come from guest | HIGH | 7.8 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39824 | HID: asus: fix UAF via HID_CLAIMED_INPUT validation | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39835 | xfs: do not propagate ENODATA disk errors into xattr code | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39841 | scsi: lpfc: Fix buffer free/clear order in deferred receive path | HIGH | 7.8 | 40%ile | Microsoft | 2025-09-09 |
| CVE-2025-39861 | Bluetooth: vhci: Prevent use-after-free by removing debugfs files early | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39863 | wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39864 | wifi: cfg80211: fix use-after-free in cmp_bss() | HIGH | 7.8 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-39866 | fs: writeback: fix use-after-free in __mark_inode_dirty() | HIGH | 7.8 | 24%ile | Microsoft | 2025-09-09 |
| CVE-2025-39873 | can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-41244 | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-202 | HIGH | 7.8 | 95%ile | Microsoft | 2025-09-09 |
| CVE-2025-39788 | scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39751 | ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control | HIGH | 7.8 | — | Microsoft | 2025-09-09 |
| CVE-2025-39790 | bus: mhi: host: Detect events pointing to unexpected TREs | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50406 | iomap: iomap: fix memory corruption when recording errors during writeback | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38703 | drm/xe: Make dma-fences compliant with the safe access rules | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-54102 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-54111 | Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-54894 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-54895 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-54896 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-54898 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-54899 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-54902 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-54903 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-54904 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-54906 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 52%ile | Microsoft | 2025-09-09 |
| CVE-2025-54907 | Microsoft Office Visio Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54908 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 47%ile | Microsoft | 2025-09-09 |
| CVE-2025-54913 | Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-54916 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 82%ile | Microsoft | 2025-09-09 |
| CVE-2025-55228 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2025-09-09 |
| CVE-2025-55245 | Xbox Gaming Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-55316 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-09-09 |
| CVE-2025-55317 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-49692 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-53800 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2025-09-09 |
| CVE-2025-53801 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-54091 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-54092 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2025-09-09 |
| CVE-2025-54098 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.8 | 86%ile | Microsoft | 2025-09-09 |
| CVE-2025-54900 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-54912 | Windows BitLocker Elevation of Privilege Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2025-09-09 |
| CVE-2025-55224 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2025-09-09 |
| CVE-2025-59251 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.6 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-11021 | Libsoup: out-of-bounds read in cookie date handling of libsoup http library | HIGH | 7.5 | 49%ile | Microsoft | 2025-09-09 |
| CVE-2025-40928 | JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabl | HIGH | 7.5 | 49%ile | Microsoft | 2025-09-09 |
| CVE-2025-48041 | SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles | HIGH | 7.5 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-55551 | An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when per | HIGH | 7.5 | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-55552 | pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are us | HIGH | 7.5 | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-55560 | An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse | HIGH | 7.5 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-58767 | REXML has a DoS condition when parsing malformed XML file | HIGH | 7.5 | 16%ile | Microsoft | 2025-09-09 |
| CVE-2025-59375 | libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is | HIGH | 7.5 | 69%ile | Microsoft | 2025-09-09 |
| CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | HIGH | 7.5 | 74%ile | Microsoft | 2025-09-09 |
| CVE-2025-58754 | Axios is vulnerable to DoS attack through lack of data size check | HIGH | 7.5 | 65%ile | Microsoft | 2025-09-09 |
| CVE-2025-55553 | A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS). | HIGH | 7.5 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-55557 | A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading | HIGH | 7.5 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-55558 | A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshr | HIGH | 7.5 | 39%ile | Microsoft | 2025-09-09 |
| CVE-2025-54919 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.5 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-55243 | Microsoft OfficePlus Spoofing Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2025-09-09 |
| CVE-2025-53805 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2025-09-09 |
| CVE-2025-55238 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability | HIGH | 7.5 | 56%ile | Microsoft | 2025-09-09 |
| CVE-2025-4953 | Podman: build context bind mount | HIGH | 7.4 | 49%ile | Microsoft | 2025-09-09 |
| CVE-2025-54103 | Windows Management Service Elevation of Privilege Vulnerability | HIGH | 7.4 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-9905 | Arbitary Code execution in Keras load_model() | HIGH | 7.3 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-9906 | Arbitrary Code execution in Keras Safe Mode | HIGH | 7.3 | 10%ile | Microsoft | 2025-09-09 |
| CVE-2025-55236 | Graphics Kernel Remote Code Execution Vulnerability | HIGH | 7.3 | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-54116 | Windows MultiPoint Services Elevation of Privilege Vulnerability | HIGH | 7.3 | 43%ile | Microsoft | 2025-09-09 |
| CVE-2025-54911 | Windows BitLocker Elevation of Privilege Vulnerability | HIGH | 7.3 | 49%ile | Microsoft | 2025-09-09 |
| CVE-2025-55322 | OmniParser Remote Code Execution Vulnerability | HIGH | 7.3 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2023-53254 | cacheinfo: Fix shared_cpu_map to handle shared caches at different levels | HIGH | 7.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38679 | media: venus: Fix OOB read due to missing payload bound check | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38680 | media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() | HIGH | 7.1 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38698 | jfs: Regular file corruption check | HIGH | 7.1 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38728 | smb3: fix for slab out of bounds on mount to ksmbd | HIGH | 7.1 | 24%ile | Microsoft | 2025-09-09 |
| CVE-2025-39683 | tracing: Limit access to parser->buffer when trace_get_user failed | HIGH | 7.1 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39702 | ipv6: sr: Fix MAC comparison to be constant-time | HIGH | 7.1 | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-39806 | HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() | HIGH | 7.1 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-39817 | efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39828 | atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39839 | batman-adv: fix OOB read/write in network-coding decode | HIGH | 7.1 | 17%ile | Microsoft | 2025-09-09 |
| CVE-2025-39853 | i40e: Fix potential invalid access when MAC list is empty | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39860 | Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() | HIGH | 7.1 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-39883 | mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory | HIGH | 7.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-58063 | CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion | HIGH | 7.1 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-39761 | wifi: ath12k: Decrement TID on RX peer frag setup error handling | HIGH | 7.1 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-38688 | iommufd: Prevent ALIGN() overflow | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38697 | jfs: upper bound check of tree index in dbAllocAG | HIGH | 7.1 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-54905 | Microsoft Word Information Disclosure Vulnerability | HIGH | 7.1 | 49%ile | Microsoft | 2025-09-09 |
| CVE-2025-38695 | scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure | HIGH | 7.0 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38701 | ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr | HIGH | 7.0 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-38709 | loop: Avoid updating block size under exclusive owner | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38710 | gfs2: Validate i_depth for exhash directories | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38732 | netfilter: nf_reject: don't leak dst refcount for loopback packets | HIGH | 7.0 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39673 | ppp: fix race conditions in ppp_fill_forward_path | HIGH | 7.0 | 23%ile | Microsoft | 2025-09-09 |
| CVE-2025-39677 | net/sched: Fix backlog accounting in qdisc_dequeue_internal | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39703 | net, hsr: reject HSR frame if skb can't hold tag | HIGH | 7.0 | 30%ile | Microsoft | 2025-09-09 |
| CVE-2025-39746 | wifi: ath10k: shutdown driver when hardware is unreliable | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39749 | rcu: Protect ->defer_qs_iw_pending from data race | HIGH | 7.0 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39759 | btrfs: qgroup: fix race between quota disable and quota rescan ioctl | HIGH | 7.0 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39825 | smb: client: fix race with concurrent opens in rename(2) | HIGH | 7.0 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39832 | net/mlx5: Fix lockdep assertion on sync reset unload event | HIGH | 7.0 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39833 | mISDN: hfcpci: Fix warning when deleting uninitialized timer | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39838 | cifs: prevent NULL pointer dereference in UTF16 conversion | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39850 | vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39851 | vxlan: Fix NPD when refreshing an FDB entry with a nexthop object | HIGH | 7.0 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-39732 | wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask() | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39750 | wifi: ath12k: Correct tid cleanup when tid setup fails | HIGH | 7.0 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-39742 | RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() | HIGH | 7.0 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38684 | net/sched: ets: use old 'nbands' while purging unused classes | HIGH | 7.0 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38692 | exfat: add cluster chain loop check for dir | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38735 | gve: prevent ethtool ops after shutdown | HIGH | 7.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39711 | media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39721 | crypto: qat - flush misc workqueue during device shutdown | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39694 | s390/sclp: Fix SCCB present check | HIGH | 7.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39713 | media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() | HIGH | 7.0 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39843 | mm: slub: avoid wake up kswapd in set_track_prepare | HIGH | 7.0 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39865 | tee: fix NULL pointer dereference in tee_shm_put | HIGH | 7.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39877 | mm/damon/sysfs: fix use-after-free in state_show() | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-49734 | PowerShell Direct Elevation of Privilege Vulnerability | HIGH | 7.0 | 26%ile | Microsoft | 2025-09-09 |
| CVE-2025-54099 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-55223 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-59215 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 25%ile | Microsoft | 2025-09-09 |
| CVE-2025-53802 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-53807 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-54093 | Windows TCP/IP Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-54105 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-54108 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-54112 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | HIGH | 7.0 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-54114 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-54115 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.0 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-59216 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2025-09-09 |
| CVE-2025-59220 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2025-09-09 |
| CVE-2025-55226 | Graphics Kernel Remote Code Execution Vulnerability | MEDIUM | 6.7 | 40%ile | Microsoft | 2025-09-09 |
| CVE-2025-53808 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 40%ile | Microsoft | 2025-09-09 |
| CVE-2025-53810 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 40%ile | Microsoft | 2025-09-09 |
| CVE-2025-54094 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 40%ile | Microsoft | 2025-09-09 |
| CVE-2025-54104 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54109 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 40%ile | Microsoft | 2025-09-09 |
| CVE-2025-54915 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 41%ile | Microsoft | 2025-09-09 |
| CVE-2025-39783 | PCI: endpoint: Fix configfs group list head handling | MEDIUM | 6.6 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-10148 | predictable WebSocket mask | MEDIUM | 6.5 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-39682 | tls: fix handling of zero-length records on the rx_list | MEDIUM | 6.5 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-40300 | x86/vmscape: Add conditional IBPB mitigation | MEDIUM | 6.5 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-58364 | cups: Remote DoS via null dereference | MEDIUM | 6.5 | 63%ile | Microsoft | 2025-09-09 |
| CVE-2025-9231 | Timing side-channel in SM2 algorithm on 64 bit ARM | MEDIUM | 6.5 | 82%ile | Microsoft | 2025-09-09 |
| CVE-2025-53797 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 66%ile | Microsoft | 2025-09-09 |
| CVE-2025-53798 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 66%ile | Microsoft | 2025-09-09 |
| CVE-2025-54095 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 66%ile | Microsoft | 2025-09-09 |
| CVE-2025-54096 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 66%ile | Microsoft | 2025-09-09 |
| CVE-2025-54097 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 66%ile | Microsoft | 2025-09-09 |
| CVE-2025-55225 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 67%ile | Microsoft | 2025-09-09 |
| CVE-2025-47997 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2025-09-09 |
| CVE-2025-53796 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 66%ile | Microsoft | 2025-09-09 |
| CVE-2025-53806 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 66%ile | Microsoft | 2025-09-09 |
| CVE-2025-53809 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | MEDIUM | 6.5 | 72%ile | Microsoft | 2025-09-09 |
| CVE-2025-55242 | Xbox Certification Bug Copilot Djando Information Disclosure Vulnerability | MEDIUM | 6.5 | 54%ile | Microsoft | 2025-09-09 |
| CVE-2025-38704 | rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access | MEDIUM | 6.3 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38708 | drbd: add missing kref_get in handle_write_conflicts | MEDIUM | 6.3 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-39794 | ARM: tegra: Use I/O memcpy to write to IRAM | MEDIUM | 6.2 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39801 | usb: dwc3: Remove WARN_ON for device endpoint command timeouts | MEDIUM | 6.2 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2022-50256 | drm/meson: remove drm bridges at aggregate driver unbind time | MEDIUM | 6.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50303 | drm/amdkfd: Fix double release compute pasid | MEDIUM | 6.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38713 | hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() | MEDIUM | 6.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39797 | xfrm: Duplicate SPI Handling | MEDIUM | 6.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53376 | scsi: mpi3mr: Use number of bits to manage bitmap sizes | MEDIUM | 6.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38678 | netfilter: nf_tables: reject duplicate device on updates | MEDIUM | 6.0 | 20%ile | Microsoft | 2025-09-09 |
| CVE-2025-9232 | Out-of-bounds read in HTTP client no_proxy handling | MEDIUM | 5.9 | 80%ile | Microsoft | 2025-09-09 |
| CVE-2025-9901 | Libsoup: improper handling of http vary header in libsoup caching | MEDIUM | 5.9 | 39%ile | Microsoft | 2025-09-09 |
| CVE-2025-39857 | net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() | MEDIUM | 5.8 | 24%ile | Microsoft | 2025-09-09 |
| CVE-2025-39739 | iommu/arm-smmu-qcom: Add SM6115 MDSS compatible | MEDIUM | 5.6 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50260 | drm/msm: Make .remove and .shutdown HW shutdown consistent | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50266 | kprobes: Fix check for probe enabled in kill_kprobe() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50304 | mtd: core: fix possible resource leak in init_mtd() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50327 | ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50350 | scsi: target: iscsi: Fix a race condition between login_work and the login thread | MEDIUM | 5.5 | 19%ile | Microsoft | 2025-09-09 |
| CVE-2022-50357 | usb: dwc3: core: fix some leaks in probe | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-09-09 |
| CVE-2022-50380 | mm: /proc/pid/smaps_rollup: fix no vma's null-deref | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50393 | drm/amdgpu: SDMA update use unlocked iterator | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2022-50407 | crypto: hisilicon/qm - increase the memory of local variables | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2022-50418 | wifi: ath11k: mhi: fix potential memory leak in ath11k_mhi_register() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53149 | ext4: avoid deadlock in fs reclaim with page writeback | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2023-53152 | drm/amdgpu: fix calltrace warning in amddrm_buddy_fini | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53209 | wifi: mac80211_hwsim: Fix possible NULL dereference | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53221 | bpf: Fix memleak due to fentry attach failure | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53240 | xsk: check IFF_UP earlier in Tx path | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53247 | btrfs: set_page_extent_mapped after read_folio in btrfs_cont_expand | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53248 | drm/amdgpu: install stub fence into potential unused fence pointers | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53292 | blk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53323 | ext2/dax: Fix ext2_setsize when len is page aligned | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53332 | genirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53347 | net/mlx5: Handle pairing of E-switch via uplink un/load APIs | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-09-09 |
| CVE-2023-53348 | btrfs: fix deadlock when aborting transaction during relocation with scrub | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53353 | accel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2023-53355 | staging: pi433: fix memory leak with using debugfs_lookup() | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2023-53366 | block: be a bit more careful in checking for NULL bdev while polling | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2023-53370 | drm/amdgpu: fix memory leak in mes self test | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53383 | irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4 | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53421 | blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2023-53424 | clk: mediatek: fix of_iomap memory leak | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53429 | btrfs: don't check PageError in __extent_writepage | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53438 | x86/MCE: Always save CS register on AMD Zen IF Poison errors | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2024-58241 | Bluetooth: hci_core: Disable works on hci_unregister_dev | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-10911 | Libxslt: use-after-free with key data stored cross-rvt | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-11083 | GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow | MEDIUM | 5.5 | 17%ile | Microsoft | 2025-09-09 |
| CVE-2025-38681 | mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-38683 | hv_netvsc: Fix panic during namespace deletion with VF | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38687 | comedi: fix race between polling and detaching | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-38691 | pNFS: Fix uninited ptr deref in block/scsi layout | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-38693 | media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38696 | MIPS: Don't crash in stack_top() for tasks without ABI or vDSO | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-38700 | scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38705 | drm/amd/pm: fix null pointer access | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38707 | fs/ntfs3: Add sanity check for file name | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38711 | smb/server: avoid deadlock when linking with ReplaceIfExists | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-38712 | hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38715 | hfs: fix slab-out-of-bounds in hfs_bnode_read() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38716 | hfs: fix general protection fault in hfs_find_init() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38717 | net: kcm: Fix race condition in kcm_unattach() | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-38721 | netfilter: ctnetlink: fix refcount leak on table dump | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38722 | habanalabs: fix UAF in export_dmabuf() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38723 | LoongArch: BPF: Fix jump offset calculation in tailcall | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38725 | net: usb: asix_devices: add phy_mask for ax88772 mdio bus | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38730 | io_uring/net: commit partial buffers on retry | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38734 | net/smc: fix UAF on smcsk after smc_listen_out() | MEDIUM | 5.5 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-38736 | net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39675 | drm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39676 | scsi: qla4xxx: Prevent a potential error pointer dereference | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39679 | drm/nouveau/nvif: Fix potential memory leak in nvif_vmm_ctor(). | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39681 | x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39684 | comedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39685 | comedi: pcl726: Prevent invalid irq number | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39686 | comedi: Make insn_rw_emulate_bits() do insn->n samples | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39687 | iio: light: as73211: Ensure buffer holes are zeroed | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39692 | smb: server: split ksmbd_rdma_stop_listening() out of ksmbd_rdma_destroy() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39693 | drm/amd/display: Avoid a NULL pointer dereference | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39697 | NFS: Fix a race when updating an existing write | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39701 | ACPI: pfr_update: Fix the driver update version check | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39705 | drm/amd/display: fix a Null pointer dereference vulnerability | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39706 | drm/amdkfd: Destroy KFD debugfs after destroy KFD wq | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39707 | drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39709 | media: venus: protect against spurious interrupts during probe | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39710 | media: venus: Add a check for packet size after reading from shared memory | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39714 | media: usbtv: Lock resolution while streaming | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39715 | parisc: Revise gateway LWS calls to probe user read access | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39716 | parisc: Revise __get_user() to probe user read access | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39718 | vsock/virtio: Validate length in packet header before skb_put() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39719 | iio: imu: bno055: fix OOB access of hw_xlate array | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39720 | ksmbd: fix refcount leak causing resource not released | MEDIUM | 5.5 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-39724 | serial: 8250: fix panic due to PSLVERR | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39726 | s390/ism: fix concurrency management in ism_cmd() | MEDIUM | 5.5 | 15%ile | Microsoft | 2025-09-09 |
| CVE-2025-39731 | f2fs: vm_unmap_ram() may be called from an invalid context | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39736 | mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39737 | mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39744 | rcu: Fix rcu_read_unlock() deadloop due to IRQ work | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39747 | drm/msm: Add error handling for krealloc in metadata setup | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39748 | bpf: Forget ranges when refining tnum after JSET | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39752 | ARM: rockchip: fix kernel hang during smp initialization | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39753 | gfs2: Set .migrate_folio in gfs2_{rgrp,meta}_aops | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39754 | mm/smaps: fix race between smaps_hugetlb_range and migration | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39756 | fs: Prevent file descriptor table allocations exceeding INT_MAX | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39758 | RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages | MEDIUM | 5.5 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-39760 | usb: core: config: Prevent OOB read in SS endpoint companion parsing | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39762 | drm/amd/display: add null check | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39763 | ACPI: APEI: send SIGBUS to current task if synchronous memory error not recovered | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39764 | netfilter: ctnetlink: remove refcounting in expectation dumpers | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39767 | LoongArch: Optimize module load time by optimizing PLT/GOT counting | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39770 | net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM | MEDIUM | 5.5 | 30%ile | Microsoft | 2025-09-09 |
| CVE-2025-39772 | drm/hisilicon/hibmc: fix the hibmc loaded failed bug | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39773 | net: bridge: fix soft lockup in br_multicast_query_expired() | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39779 | btrfs: subpage: keep TOWRITE tag until folio is cleaned | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39781 | parisc: Drop WARN_ON_ONCE() from flush_cache_vmap | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39782 | jbd2: prevent softlockup in jbd2_log_do_checkpoint() | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39787 | soc: qcom: mdt_loader: Ensure we don't read past the ELF header | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39789 | crypto: x86/aegis - Add missing error checks | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39795 | block: avoid possible overflow for chunk_sectors check in blk_stack_limits() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39798 | NFS: Fix the setting of capabilities when automounting a new filesystem | MEDIUM | 5.5 | 19%ile | Microsoft | 2025-09-09 |
| CVE-2025-39800 | btrfs: abort transaction on unexpected eb generation at btrfs_copy_root() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39805 | net: macb: fix unregister_netdev call order in macb_remove() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39808 | HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39812 | sctp: initialize more fields in sctp_v6_from_sk() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39813 | ftrace: Fix potential warning in trace_printk_seq during ftrace_dump | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39819 | fs/smb: Fix inconsistent refcnt update | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39826 | net: rose: convert 'use' field to refcount_t | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-09-09 |
| CVE-2025-39827 | net: rose: include node references in rose_neigh refcount | MEDIUM | 5.5 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-39829 | trace/fgraph: Fix the warning caused by missing unregister notifier | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39842 | ocfs2: prevent release journal inode after journal shutdown | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39844 | mm: move page table sync declarations to linux/pgtable.h | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39845 | x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39846 | pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39847 | ppp: fix memory leak in pad_compress_skb | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39848 | ax25: properly unshare skbs in ax25_kiss_rcv() | MEDIUM | 5.5 | 15%ile | Microsoft | 2025-09-09 |
| CVE-2025-39849 | wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() | MEDIUM | 5.5 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-39859 | ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39862 | wifi: mt76: mt7915: fix list corruption after hardware restart | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2025-39876 | net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39880 | libceph: fix invalid accesses to ceph_connection_v1_info | MEDIUM | 5.5 | 26%ile | Microsoft | 2025-09-09 |
| CVE-2025-39881 | kernfs: Fix UAF in polling when open file is released | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39886 | bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39745 | rcutorture: Fix rcutorture_one_extend_check() splat in RT kernels | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53231 | erofs: Fix detection of atomic context | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53410 | USB: ULPI: fix memory leak with using debugfs_lookup() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53387 | scsi: ufs: core: Fix device management cmd timeout flow | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39799 | ACPI: processor: perflib: Move problematic pr->performance check | MEDIUM | 5.5 | — | Microsoft | 2025-09-09 |
| CVE-2025-39885 | ocfs2: fix recursive semaphore deadlock in fiemap call | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39869 | dmaengine: ti: edma: Fix memory allocation size for queue_priority_map | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2022-50236 | iommu/mediatek: Fix crash on isr after kexec() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53261 | coresight: Fix memory leak in acpi_buffer->pointer | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2022-50316 | orangefs: Fix kmemleak in orangefs_sysfs_init() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53367 | accel/habanalabs: fix mem leak in capture user mappings | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2022-50390 | drm/ttm: fix undefined behavior in bit shift for TTM_TT_FLAG_PRIV_POPULATED | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2023-53371 | net/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39734 | Revert "fs/ntfs3: Replace inode_trylock with inode_lock" | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-53799 | Windows Imaging Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 54%ile | Microsoft | 2025-09-09 |
| CVE-2025-53803 | Windows Kernel Memory Information Disclosure Vulnerability | MEDIUM | 5.5 | 50%ile | Microsoft | 2025-09-09 |
| CVE-2025-53804 | Windows Kernel-Mode Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 50%ile | Microsoft | 2025-09-09 |
| CVE-2025-54901 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 49%ile | Microsoft | 2025-09-09 |
| CVE-2025-10824 | axboe fio init.c __parse_jobs_ini use after free | MEDIUM | 5.3 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-11082 | GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow | MEDIUM | 5.3 | 17%ile | Microsoft | 2025-09-09 |
| CVE-2025-46149 | In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error. | MEDIUM | 5.3 | 30%ile | Microsoft | 2025-09-09 |
| CVE-2025-46150 | In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results. | MEDIUM | 5.3 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-46152 | In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" a | MEDIUM | 5.3 | 39%ile | Microsoft | 2025-09-09 |
| CVE-2025-46153 | PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency wit | MEDIUM | 5.3 | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-48040 | Malicious Key Exchange Messages may Lead to Excessive Resource Consumption | MEDIUM | 5.3 | 37%ile | Microsoft | 2025-09-09 |
| CVE-2025-55554 | pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). | MEDIUM | 5.3 | 25%ile | Microsoft | 2025-09-09 |
| CVE-2025-58749 | WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode | MEDIUM | 5.3 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-46148 | In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results. | MEDIUM | 5.3 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-60018 | Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certific | MEDIUM | 4.8 | 24%ile | Microsoft | 2025-09-09 |
| CVE-2025-54101 | Windows SMB Client Remote Code Execution Vulnerability | MEDIUM | 4.8 | 84%ile | Microsoft | 2025-09-09 |
| CVE-2023-53178 | mm: fix zswap writeback race condition | MEDIUM | 4.7 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2023-53401 | mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required() | MEDIUM | 4.7 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-38706 | ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() | MEDIUM | 4.7 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2025-39867 | netfilter: nft_set_pipapo: fix null deref for empty set | MEDIUM | 4.7 | — | Microsoft | 2025-09-09 |
| CVE-2023-53447 | f2fs: don't reset unchangable mount option in f2fs_remount() | MEDIUM | 4.7 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2025-47967 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 4.7 | 30%ile | Microsoft | 2025-09-09 |
| CVE-2025-53791 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | MEDIUM | 4.7 | 33%ile | Microsoft | 2025-09-09 |
| CVE-2025-48038 | Unverified File Handles can Cause Excessive Use of System Resources | MEDIUM | 4.3 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-48039 | Unverified Paths can Cause Excessive Use of System Resources | MEDIUM | 4.3 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-9086 | Out of bounds read for cookie path | MEDIUM | 4.3 | 71%ile | Microsoft | 2025-09-09 |
| CVE-2025-54107 | MapUrlToZone Security Feature Bypass Vulnerability | MEDIUM | 4.3 | 59%ile | Microsoft | 2025-09-09 |
| CVE-2025-54917 | MapUrlToZone Security Feature Bypass Vulnerability | MEDIUM | 4.3 | 58%ile | Microsoft | 2025-09-09 |
| CVE-2025-49728 | Microsoft PC Manager Security Feature Bypass Vulnerability | MEDIUM | 4.0 | 16%ile | Microsoft | 2025-09-09 |
| CVE-2025-7039 | Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file() | LOW | 3.7 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-60019 | Glib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via | LOW | 3.7 | 29%ile | Microsoft | 2025-09-09 |
| CVE-2025-10823 | axboe fio options.c str_buffer_pattern_cb null pointer dereference | LOW | 3.3 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-11081 | GNU Binutils objdump.c dump_dwarf_section out-of-bounds | LOW | 3.3 | 11%ile | Microsoft | 2025-09-09 |
| CVE-2025-8277 | Libssh: memory exhaustion via repeated key exchange in libssh | LOW | 3.1 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-58354 | Kata Containers coco-tdx malicious host can circumvent initdata verification | UNKNOWN | — | 27%ile | Microsoft | 2025-09-09 |
| CVE-2025-59825 | astral-tokio-tar has a path traversal in tar extraction | UNKNOWN | — | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-8869 | Fallback tar extraction in pip doesn't check symbolic links point to extraction directory | UNKNOWN | — | 40%ile | Microsoft | 2025-09-09 |
| CVE-2025-9648 | Denial of Service in CivetWeb | UNKNOWN | — | 54%ile | Microsoft | 2025-09-09 |
| CVE-2025-10501 | Chromium: CVE-2025-10501 Use after free in WebRTC | UNKNOWN | — | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-10585 | Chromium: CVE-2025-10585 Type Confusion in V8 | UNKNOWN | — | 92%ile | Microsoft | 2025-09-09 |
| CVE-2025-10890 | Chromium: CVE-2025-10890 Side-channel information leakage in V8 | UNKNOWN | — | 24%ile | Microsoft | 2025-09-09 |
| CVE-2024-21907 | VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json | UNKNOWN | — | 98%ile | Microsoft | 2025-09-09 |
| CVE-2025-9867 | Chromium: CVE-2025-9867 Inappropriate implementation in Downloads | UNKNOWN | — | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-9866 | Chromium: CVE-2025-9866 Inappropriate implementation in Extensions | UNKNOWN | — | 30%ile | Microsoft | 2025-09-09 |
| CVE-2025-9865 | Chromium: CVE-2025-9865 Inappropriate implementation in Toolbar | UNKNOWN | — | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-9864 | Chromium: CVE-2025-9864 Use after free in V8 | UNKNOWN | — | — | Microsoft | 2025-09-09 |
| CVE-2025-10201 | Chromium: CVE-2025-10201 Inappropriate implementation in Mojo | UNKNOWN | — | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-10200 | Chromium: CVE-2025-10200 Use after free in Serviceworker | UNKNOWN | — | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-10502 | Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2025-09-09 |
| CVE-2025-10500 | Chromium: CVE-2025-10500 Use after free in Dawn | UNKNOWN | — | 19%ile | Microsoft | 2025-09-09 |
| CVE-2025-10891 | Chromium: CVE-2025-10891 Integer overflow in V8 | UNKNOWN | — | 94%ile | Microsoft | 2025-09-09 |
| CVE-2025-10892 | Chromium: CVE-2025-10892 Integer overflow in V8 | UNKNOWN | — | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-53767 | Azure OpenAI Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 64%ile | Microsoft | 2025-08-12 |
| CVE-2025-38561 | ksmbd: fix Preauh_HashValue race condition | CRITICAL | 9.8 | 37%ile | Microsoft | 2025-08-12 |
| CVE-2025-38615 | fs/ntfs3: cancle set bad inode after removing name fails | CRITICAL | 9.8 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-53763 | Azure Databricks Elevation of Privilege Vulnerability | CRITICAL | 9.8 | 50%ile | Microsoft | 2025-08-12 |
| CVE-2025-50165 | Windows Graphics Component Remote Code Execution Vulnerability | CRITICAL | 9.8 | 95%ile | Microsoft | 2025-08-12 |
| CVE-2025-53766 | GDI+ Remote Code Execution Vulnerability | CRITICAL | 9.8 | 94%ile | Microsoft | 2025-08-12 |
| CVE-2025-53795 | Microsoft PC Manager Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 47%ile | Microsoft | 2025-08-12 |
| CVE-2025-50171 | Remote Desktop Spoofing Vulnerability | CRITICAL | 9.1 | 60%ile | Microsoft | 2025-08-12 |
| CVE-2025-53792 | Azure Portal Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 55%ile | Microsoft | 2025-08-12 |
| CVE-2025-54351 | In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv). | HIGH | 8.9 | 35%ile | Microsoft | 2025-08-12 |
| CVE-2025-8714 | PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client | HIGH | 8.8 | 53%ile | Microsoft | 2025-08-12 |
| CVE-2025-8715 | PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server | HIGH | 8.8 | 35%ile | Microsoft | 2025-08-12 |
| CVE-2025-49758 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 60%ile | Microsoft | 2025-08-12 |
| CVE-2025-53727 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 64%ile | Microsoft | 2025-08-12 |
| CVE-2025-24999 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 76%ile | Microsoft | 2025-08-12 |
| CVE-2025-53772 | Web Deploy Remote Code Execution Vulnerability | HIGH | 8.8 | 98%ile | Microsoft | 2025-08-12 |
| CVE-2025-49757 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 60%ile | Microsoft | 2025-08-12 |
| CVE-2025-49759 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 65%ile | Microsoft | 2025-08-12 |
| CVE-2025-50163 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2025-08-12 |
| CVE-2025-53131 | Windows Media Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2025-08-12 |
| CVE-2025-53143 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.8 | 94%ile | Microsoft | 2025-08-12 |
| CVE-2025-53144 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.8 | 93%ile | Microsoft | 2025-08-12 |
| CVE-2025-53145 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.8 | 93%ile | Microsoft | 2025-08-12 |
| CVE-2025-47954 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 73%ile | Microsoft | 2025-08-12 |
| CVE-2025-53778 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 8.8 | 98%ile | Microsoft | 2025-08-12 |
| CVE-2025-49712 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2025-08-12 |
| CVE-2025-53731 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 43%ile | Microsoft | 2025-08-12 |
| CVE-2025-53733 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 42%ile | Microsoft | 2025-08-12 |
| CVE-2025-53740 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 43%ile | Microsoft | 2025-08-12 |
| CVE-2025-53784 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 39%ile | Microsoft | 2025-08-12 |
| CVE-2025-38499 | clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns | HIGH | 8.2 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2025-53787 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | HIGH | 8.2 | 51%ile | Microsoft | 2025-08-12 |
| CVE-2025-50177 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.1 | 90%ile | Microsoft | 2025-08-12 |
| CVE-2025-38556 | HID: core: Harden s32ton() against conversion to 0 bits | HIGH | 8.0 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-53786 | Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability | HIGH | 8.0 | 94%ile | Microsoft | 2025-08-12 |
| CVE-2025-50160 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.0 | 57%ile | Microsoft | 2025-08-12 |
| CVE-2025-50162 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.0 | 57%ile | Microsoft | 2025-08-12 |
| CVE-2025-50164 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.0 | 57%ile | Microsoft | 2025-08-12 |
| CVE-2025-53720 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.0 | 59%ile | Microsoft | 2025-08-12 |
| CVE-2025-49707 | Azure Virtual Machines Spoofing Vulnerability | HIGH | 7.9 | 35%ile | Microsoft | 2025-08-12 |
| CVE-2024-58240 | tls: separate no-async decryption request handling from async | HIGH | 7.8 | 26%ile | Microsoft | 2025-08-12 |
| CVE-2025-38500 | xfrm: interface: fix use-after-free after changing collect_md xfrm interface | HIGH | 7.8 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2025-38527 | smb: client: fix use-after-free in cifs_oplock_break | HIGH | 7.8 | 35%ile | Microsoft | 2025-08-12 |
| CVE-2025-38563 | perf/core: Prevent VMA split of buffer mappings | HIGH | 7.8 | 33%ile | Microsoft | 2025-08-12 |
| CVE-2025-38565 | perf/core: Exit early on perf_mmap() fail | HIGH | 7.8 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38568 | net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing | HIGH | 7.8 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38572 | ipv6: reject malicious packets in ipv6_gso_segment() | HIGH | 7.8 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38574 | pptp: ensure minimal skb length in pptp_xmit() | HIGH | 7.8 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-38584 | padata: Fix pd UAF once and for all | HIGH | 7.8 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38585 | staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() | HIGH | 7.8 | 12%ile | Microsoft | 2025-08-12 |
| CVE-2025-38609 | PM / devfreq: Check governor before using governor->name | HIGH | 7.8 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38618 | vsock: Do not allow binding to VMADDR_PORT_ANY | HIGH | 7.8 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38656 | wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start() | HIGH | 7.8 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38666 | net: appletalk: Fix use-after-free in AARP proxy probe | HIGH | 7.8 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38676 | iommu/amd: Avoid stack buffer overflow from kernel cmdline | HIGH | 7.8 | 34%ile | Microsoft | 2025-08-12 |
| CVE-2025-8747 | Keras safe_mode bypass allows arbitrary code execution when loading a malicious model. | HIGH | 7.8 | 2%ile | Microsoft | 2025-08-12 |
| CVE-2025-38535 | phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode | HIGH | 7.8 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38538 | dmaengine: nbpfaxi: Fix memory corruption in probe() | HIGH | 7.8 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38533 | net: libwx: fix the using of Rx buffer DMA | HIGH | 7.8 | 23%ile | Microsoft | 2025-08-12 |
| CVE-2025-38555 | usb: gadget : fix use-after-free in composite_dev_cleanup() | HIGH | 7.8 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38579 | f2fs: fix KMSAN uninit-value in extent_info usage | HIGH | 7.8 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38582 | RDMA/hns: Fix double destruction of rsv_qp | HIGH | 7.8 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38595 | xen: fix UAF in dmabuf_exp_from_pages() | HIGH | 7.8 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-53729 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2025-08-12 |
| CVE-2025-53730 | Microsoft Office Visio Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2025-08-12 |
| CVE-2025-53741 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 43%ile | Microsoft | 2025-08-12 |
| CVE-2025-53759 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 43%ile | Microsoft | 2025-08-12 |
| CVE-2025-53761 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 43%ile | Microsoft | 2025-08-12 |
| CVE-2025-53773 | GitHub Copilot and Visual Studio Remote Code Execution Vulnerability | HIGH | 7.8 | 84%ile | Microsoft | 2025-08-12 |
| CVE-2025-55230 | Windows MBT Transport Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-08-12 |
| CVE-2025-49761 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-50153 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-50168 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 54%ile | Microsoft | 2025-08-12 |
| CVE-2025-50170 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2025-08-12 |
| CVE-2025-50173 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-08-12 |
| CVE-2025-50176 | DirectX Graphics Kernel Remote Code Execution Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2025-08-12 |
| CVE-2025-53132 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2025-08-12 |
| CVE-2025-53133 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-53141 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53149 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 52%ile | Microsoft | 2025-08-12 |
| CVE-2025-53151 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53152 | Desktop Windows Manager Remote Code Execution Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53154 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53155 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2025-08-12 |
| CVE-2025-53723 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2025-08-12 |
| CVE-2025-53724 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53725 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53726 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53732 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2025-08-12 |
| CVE-2025-53734 | Microsoft Office Visio Remote Code Execution Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53735 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-08-12 |
| CVE-2025-53737 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2025-08-12 |
| CVE-2025-53738 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 43%ile | Microsoft | 2025-08-12 |
| CVE-2025-53739 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-08-12 |
| CVE-2025-50155 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-08-12 |
| CVE-2025-53789 | Windows StateRepository API Server file Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-9288 | Missing type checks leading to hash rewind and passing on crafted data | HIGH | 7.7 | 51%ile | Microsoft | 2025-08-12 |
| CVE-2025-53781 | Azure Virtual Machines Information Disclosure Vulnerability | HIGH | 7.7 | 65%ile | Microsoft | 2025-08-12 |
| CVE-2025-52194 | A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malf | HIGH | 7.5 | 49%ile | Microsoft | 2025-08-12 |
| CVE-2025-33051 | Microsoft Exchange Server Information Disclosure Vulnerability | HIGH | 7.5 | 67%ile | Microsoft | 2025-08-12 |
| CVE-2025-50169 | Windows SMB Remote Code Execution Vulnerability | HIGH | 7.5 | 49%ile | Microsoft | 2025-08-12 |
| CVE-2025-53722 | Windows Remote Desktop Services Denial of Service Vulnerability | HIGH | 7.5 | 97%ile | Microsoft | 2025-08-12 |
| CVE-2025-53783 | Microsoft Teams Remote Code Execution Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2025-08-12 |
| CVE-2025-53793 | Azure Stack Hub Information Disclosure Vulnerability | HIGH | 7.5 | 69%ile | Microsoft | 2025-08-12 |
| CVE-2025-55231 | Windows Storage-based Management Service Remote Code Execution Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2025-08-12 |
| CVE-2025-38578 | f2fs: fix to avoid UAF in f2fs_sync_inode_meta() | HIGH | 7.3 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-50159 | Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability | HIGH | 7.3 | 46%ile | Microsoft | 2025-08-12 |
| CVE-2025-50161 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.3 | 47%ile | Microsoft | 2025-08-12 |
| CVE-2025-53779 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.2 | 85%ile | Microsoft | 2025-08-12 |
| CVE-2025-38502 | bpf: Fix oob access in cgroup local storage | HIGH | 7.1 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38608 | bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls | HIGH | 7.1 | 34%ile | Microsoft | 2025-08-12 |
| CVE-2025-38660 | [ceph] parse_longname(): strrchr() expects NUL-terminated string | HIGH | 7.1 | 33%ile | Microsoft | 2025-08-12 |
| CVE-2025-38532 | net: libwx: properly reset Rx ring descriptor | HIGH | 7.1 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2025-38543 | drm/tegra: nvdec: Fix dma_alloc_coherent error check | HIGH | 7.1 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-53760 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 7.1 | 96%ile | Microsoft | 2025-08-12 |
| CVE-2025-3770 | SMM IDT Privilege Escalation Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2025-38617 | net/packet: fix a race in packet_set_ring() and packet_notifier() | HIGH | 7.0 | 27%ile | Microsoft | 2025-08-12 |
| CVE-2025-38665 | can: netlink: can_changelink(): fix NULL pointer deref of struct can_priv::do_set_mode | HIGH | 7.0 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-38668 | regulator: core: fix NULL dereference on unbind due to stale coupling data | HIGH | 7.0 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-47907 | Incorrect results returned from Rows.Scan in database/sql | HIGH | 7.0 | 31%ile | Microsoft | 2025-08-12 |
| CVE-2025-38605 | wifi: ath12k: Pass ab pointer directly to ath12k_dp_tx_get_encap_type() | HIGH | 7.0 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-49762 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2025-08-12 |
| CVE-2025-50158 | Windows NTFS Information Disclosure Vulnerability | HIGH | 7.0 | 32%ile | Microsoft | 2025-08-12 |
| CVE-2025-50167 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.0 | 28%ile | Microsoft | 2025-08-12 |
| CVE-2025-53134 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 25%ile | Microsoft | 2025-08-12 |
| CVE-2025-53135 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2025-08-12 |
| CVE-2025-53137 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 33%ile | Microsoft | 2025-08-12 |
| CVE-2025-53140 | Windows Kernel Transaction Manager Elevation of Privilege Vulnerability | HIGH | 7.0 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-53142 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-53147 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 39%ile | Microsoft | 2025-08-12 |
| CVE-2025-53718 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-53721 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-53788 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2025-08-12 |
| CVE-2025-49751 | Windows Hyper-V Denial of Service Vulnerability | MEDIUM | 6.8 | 40%ile | Microsoft | 2025-08-12 |
| CVE-2025-53736 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 6.8 | 42%ile | Microsoft | 2025-08-12 |
| CVE-2025-49743 | Windows Graphics Component Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 40%ile | Microsoft | 2025-08-12 |
| CVE-2025-48807 | Windows Hyper-V Remote Code Execution Vulnerability | MEDIUM | 6.7 | 40%ile | Microsoft | 2025-08-12 |
| CVE-2025-38577 | f2fs: fix to avoid panic in f2fs_evict_inode | MEDIUM | 6.6 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38501 | ksmbd: limit repeated connections from clients with the same IP | MEDIUM | 6.5 | 81%ile | Microsoft | 2025-08-12 |
| CVE-2025-38646 | wifi: rtw89: avoid NULL dereference when RX problematic packet on unsupported 6 GHz band | MEDIUM | 6.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-54349 | In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. | MEDIUM | 6.5 | 34%ile | Microsoft | 2025-08-12 |
| CVE-2025-55198 | Helm May Panic Due To Incorrect YAML Content | MEDIUM | 6.5 | 27%ile | Microsoft | 2025-08-12 |
| CVE-2025-55199 | Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion | MEDIUM | 6.5 | 27%ile | Microsoft | 2025-08-12 |
| CVE-2025-25005 | Microsoft Exchange Server Tampering Vulnerability | MEDIUM | 6.5 | 70%ile | Microsoft | 2025-08-12 |
| CVE-2025-50154 | Microsoft Windows File Explorer Spoofing Vulnerability | MEDIUM | 6.5 | 98%ile | Microsoft | 2025-08-12 |
| CVE-2025-50166 | Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure Vulnerability | MEDIUM | 6.5 | 70%ile | Microsoft | 2025-08-12 |
| CVE-2025-50172 | DirectX Graphics Kernel Denial of Service Vulnerability | MEDIUM | 6.5 | 72%ile | Microsoft | 2025-08-12 |
| CVE-2025-53716 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | MEDIUM | 6.5 | 72%ile | Microsoft | 2025-08-12 |
| CVE-2025-53728 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | MEDIUM | 6.5 | 66%ile | Microsoft | 2025-08-12 |
| CVE-2025-53774 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | MEDIUM | 6.5 | 47%ile | Microsoft | 2025-08-12 |
| CVE-2025-54389 | AIDE improper output neutralization vulnerability | MEDIUM | 6.2 | 14%ile | Microsoft | 2025-08-12 |
| CVE-2025-54409 | AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS) | MEDIUM | 6.2 | 15%ile | Microsoft | 2025-08-12 |
| CVE-2025-38539 | tracing: Add down_write(trace_event_sem) when adding trace event | MEDIUM | 6.1 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38566 | sunrpc: fix handling of server side tls alerts | MEDIUM | 5.8 | 47%ile | Microsoft | 2025-08-12 |
| CVE-2025-38512 | wifi: prevent A-MSDU attacks in mesh networks | MEDIUM | 5.7 | 14%ile | Microsoft | 2025-08-12 |
| CVE-2025-50156 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 5.7 | 66%ile | Microsoft | 2025-08-12 |
| CVE-2025-53138 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 5.7 | 65%ile | Microsoft | 2025-08-12 |
| CVE-2025-53148 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 5.7 | 65%ile | Microsoft | 2025-08-12 |
| CVE-2025-53153 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 5.7 | 65%ile | Microsoft | 2025-08-12 |
| CVE-2025-53719 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 5.7 | 68%ile | Microsoft | 2025-08-12 |
| CVE-2025-50157 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 5.7 | 65%ile | Microsoft | 2025-08-12 |
| CVE-2025-53859 | NGINX ngx_mail_smtp_module vulnerability | MEDIUM | 5.6 | 33%ile | Microsoft | 2025-08-12 |
| CVE-2022-50233 | Bluetooth: eir: Fix using strlen with hdev->{dev_name,short_name} | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-38510 | kasan: remove kasan_find_vm_area() to prevent possible deadlock | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-38513 | wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38514 | rxrpc: Fix oops due to non-existence of prealloc backlog struct | MEDIUM | 5.5 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-38515 | drm/sched: Increment job count before swapping tail spsc queue | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2025-38516 | pinctrl: qcom: msm: mark certain pins as invalid for interrupts | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38520 | drm/amdkfd: Don't call mmput from MMU notifier callback | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-08-12 |
| CVE-2025-38526 | ice: add NULL check in eswitch lag check | MEDIUM | 5.5 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-38528 | bpf: Reject %p% format string in bprintf-like helpers | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38529 | comedi: aio_iiro_16: Fix bit shift out of bounds | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38530 | comedi: pcl812: Fix bit shift out of bounds | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38531 | iio: common: st_sensors: Fix use of uninitialize device structs | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38537 | net: phy: Don't register LEDs for genphy | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-38540 | HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38542 | net: appletalk: Fix device refcount leak in atrtr_create() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38544 | rxrpc: Fix bug due to prealloc collision | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-38546 | atm: clip: Fix memory leak of struct clip_vcc. | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38548 | hwmon: (corsair-cpro) Validate the size of the received input buffer | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38550 | ipv6: mcast: Delay put pmc->idev in mld_del_delrec() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2025-38552 | mptcp: plug races between subflow fail and subflow creation | MEDIUM | 5.5 | 24%ile | Microsoft | 2025-08-12 |
| CVE-2025-38553 | net/sched: Restrict conditions for adding duplicating netems to qdisc tree | MEDIUM | 5.5 | — | Microsoft | 2025-08-12 |
| CVE-2025-38560 | x86/sev: Evict cache lines during SNP memory validation | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38562 | ksmbd: fix null pointer dereference error in generate_encryptionkey | MEDIUM | 5.5 | 95%ile | Microsoft | 2025-08-12 |
| CVE-2025-38569 | benet: fix BUG when creating VFs | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38571 | sunrpc: fix client side handling of tls alerts | MEDIUM | 5.5 | 27%ile | Microsoft | 2025-08-12 |
| CVE-2025-38576 | powerpc/eeh: Make EEH driver device hotplug safe | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38581 | crypto: ccp - Fix crash when rebind ccp device for ccp.ko | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38583 | clk: xilinx: vcu: unregister pll_post only if registered correctly | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38591 | bpf: Reject narrower access to pointer ctx fields | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-08-12 |
| CVE-2025-38601 | wifi: ath11k: clear initialized flag for deinit-ed srng lists | MEDIUM | 5.5 | 15%ile | Microsoft | 2025-08-12 |
| CVE-2025-38602 | iwlwifi: Add missing check for alloc_ordered_workqueue | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38604 | wifi: rtl818x: Kill URBs before clearing tx status queue | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38610 | powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38612 | staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38614 | eventpoll: Fix semi-unbounded recursion | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38616 | tls: handle data disappearing from under the TLS ULP | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-08-12 |
| CVE-2025-38622 | net: drop UFO packets in udp_rcv_segment() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38623 | PCI: pnv_php: Fix surprise plug detection and recovery | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38624 | PCI: pnv_php: Clean up allocated IRQs on unplug | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38625 | vfio/pds: Fix missing detach_ioas op | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38626 | f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38627 | f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38630 | fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38634 | power: supply: cpcap-charger: Fix null check for power_supply_get_by_name | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38635 | clk: davinci: Add NULL check in davinci_lpsc_clk_register() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38636 | rv: Use strings in da monitors tracepoints | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2025-38639 | netfilter: xt_nfacct: don't assume acct name is null-terminated | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38640 | bpf: Disable migration in nf_hook_run_bpf(). | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38643 | wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-38644 | wifi: mac80211: reject TDLS operations when station is not associated | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38645 | net/mlx5: Check device memory pointer before usage | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38648 | spi: stm32: Check for cfg availability in stm32_spi_probe | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38650 | hfsplus: remove mutex_lock check in hfsplus_free_extents | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-08-12 |
| CVE-2025-38652 | f2fs: fix to avoid out-of-boundary access in devs.path | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38653 | proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38659 | gfs2: No more self recovery | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38663 | nilfs2: reject invalid file types when reading inodes | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38664 | ice: Fix a null pointer dereference in ice_copy_and_init_pkg() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38670 | arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38671 | i2c: qup: jump out of the loop in case of timeout | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-9165 | LibTIFF tiffcmp tiffcmp.c InitCCITTFax3 memory leak | MEDIUM | 5.5 | 12%ile | Microsoft | 2025-08-12 |
| CVE-2025-38525 | rxrpc: Fix irq-disabled in local_bh_enable() | MEDIUM | 5.5 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-38611 | vmci: Prevent the dispatching of uninitialized payloads | MEDIUM | 5.5 | — | Microsoft | 2025-08-12 |
| CVE-2025-38507 | HID: nintendo: avoid bluetooth suspend/resume stalls | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-38597 | drm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2025-53136 | NT OS Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 58%ile | Microsoft | 2025-08-12 |
| CVE-2025-53156 | Windows Storage Port Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 51%ile | Microsoft | 2025-08-12 |
| CVE-2025-53769 | Windows Security App Spoofing Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2025-08-12 |
| CVE-2025-49745 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | MEDIUM | 5.4 | 42%ile | Microsoft | 2025-08-12 |
| CVE-2025-58058 | github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives | MEDIUM | 5.3 | 35%ile | Microsoft | 2025-08-12 |
| CVE-2025-8837 | JasPer JPEG2000 File jpc_dec.c jpc_dec_dump use after free | MEDIUM | 5.3 | 14%ile | Microsoft | 2025-08-12 |
| CVE-2025-8842 | NASM Netwide Assember preproc.c do_directive use after free | MEDIUM | 5.3 | 14%ile | Microsoft | 2025-08-12 |
| CVE-2025-8843 | NASM Netwide Assember outmacho.c macho_no_dead_strip heap-based overflow | MEDIUM | 5.3 | 18%ile | Microsoft | 2025-08-12 |
| CVE-2025-8845 | NASM Netwide Assember nasm.c assemble_file stack-based overflow | MEDIUM | 5.3 | 20%ile | Microsoft | 2025-08-12 |
| CVE-2025-8846 | NASM Netwide Assember parser.c parse_line stack-based overflow | MEDIUM | 5.3 | 20%ile | Microsoft | 2025-08-12 |
| CVE-2025-8851 | LibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflow | MEDIUM | 5.3 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2025-9390 | vim xxd xxd.c main buffer overflow | MEDIUM | 5.3 | 20%ile | Microsoft | 2025-08-12 |
| CVE-2025-25006 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 5.3 | 57%ile | Microsoft | 2025-08-12 |
| CVE-2025-25007 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 5.3 | 56%ile | Microsoft | 2025-08-12 |
| CVE-2025-55229 | Windows Certificate Spoofing Vulnerability | MEDIUM | 5.3 | 41%ile | Microsoft | 2025-08-12 |
| CVE-2025-38677 | f2fs: fix to avoid out-of-boundary access in dnode page | MEDIUM | 5.1 | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-38503 | btrfs: fix assertion when building free space tree | MEDIUM | 5.0 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-38524 | rxrpc: Fix recv-recv race of completed call | MEDIUM | 4.7 | 19%ile | Microsoft | 2025-08-12 |
| CVE-2025-38590 | net/mlx5e: Remove skb secpath if xfrm state is not found | MEDIUM | 4.7 | 30%ile | Microsoft | 2025-08-12 |
| CVE-2025-38593 | Bluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()' | MEDIUM | 4.7 | 7%ile | Microsoft | 2025-08-12 |
| CVE-2025-38675 | xfrm: state: initialize state_ptrs earlier in xfrm_state_find | MEDIUM | 4.7 | 2%ile | Microsoft | 2025-08-12 |
| CVE-2025-4877 | Libssh: write beyond bounds in binary to base64 conversion functions | MEDIUM | 4.5 | 10%ile | Microsoft | 2025-08-12 |
| CVE-2025-53765 | Azure Stack Hub Information Disclosure Vulnerability | MEDIUM | 4.4 | 41%ile | Microsoft | 2025-08-12 |
| CVE-2025-49755 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 4.3 | 39%ile | Microsoft | 2025-08-12 |
| CVE-2025-49736 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 4.3 | 41%ile | Microsoft | 2025-08-12 |
| CVE-2025-54350 | In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authenti | LOW | 3.7 | 36%ile | Microsoft | 2025-08-12 |
| CVE-2025-8732 | libxml2 xmlcatalog xmlParseSGMLCatalog recursion | LOW | 3.3 | 11%ile | Microsoft | 2025-08-12 |
| CVE-2025-8835 | JasPer Image Color Space Conversion jas_image.c jas_image_chclrspc null pointer dereference | LOW | 3.3 | 12%ile | Microsoft | 2025-08-12 |
| CVE-2025-8836 | JasPer JPEG2000 Encoder jpc_enc.c jpc_floorlog2 assertion | LOW | 3.3 | 11%ile | Microsoft | 2025-08-12 |
| CVE-2025-8844 | NASM Netwide Assember preproc.c parse_smacro_template null pointer dereference | LOW | 3.3 | 18%ile | Microsoft | 2025-08-12 |
| CVE-2025-8961 | LibTIFF tiffcrop tiffcrop.c main memory corruption | LOW | 3.3 | 11%ile | Microsoft | 2025-08-12 |
| CVE-2025-9301 | cmake cmForEachCommand.cxx ReplayItems assertion | LOW | 3.3 | 4%ile | Microsoft | 2025-08-12 |
| CVE-2025-9403 | jqlang jq JSON jq_test.c run_jq_tests assertion | LOW | 3.3 | 12%ile | Microsoft | 2025-08-12 |
| CVE-2025-8713 | PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table | LOW | 3.1 | 13%ile | Microsoft | 2025-08-12 |
| CVE-2023-26819 | cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,999999999999999 | LOW | 2.9 | 14%ile | Microsoft | 2025-08-12 |
| CVE-2025-50422 | Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_f | LOW | 2.9 | 12%ile | Microsoft | 2025-08-12 |
| CVE-2024-13978 | LibTIFF fax2ps tiff2pdf.c t2p_read_tiff_init null pointer dereference | LOW | 2.5 | 9%ile | Microsoft | 2025-08-12 |
| CVE-2025-8534 | libtiff tiff2ps tiff2ps.c PS_Lvl2page null pointer dereference | LOW | 2.5 | 8%ile | Microsoft | 2025-08-12 |
| CVE-2015-3310 | Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when th | UNKNOWN | — | 92%ile | Microsoft | 2025-08-12 |
| CVE-2022-4743 | A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerab | UNKNOWN | — | 68%ile | Microsoft | 2025-08-12 |
| CVE-2023-37464 | Incorrect Authentication Tag length usage in AES GCM decryption in OpenIDC/cjose | UNKNOWN | — | 52%ile | Microsoft | 2025-08-12 |
| CVE-2025-55159 | slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check | UNKNOWN | — | 6%ile | Microsoft | 2025-08-12 |
| CVE-2025-58160 | Tracing logging user input may result in poisoning logs with ANSI escape sequences | UNKNOWN | — | 26%ile | Microsoft | 2025-08-12 |
| CVE-2025-8733 | GNU Bison obprintf.c __obstack_vprintf_internal assertion | UNKNOWN | — | — | Microsoft | 2025-08-12 |
| CVE-2025-8734 | GNU Bison scan-code.c code_free double free | UNKNOWN | — | — | Microsoft | 2025-08-12 |
| CVE-2025-9132 | Chromium: CVE-2025-9132 Out of bounds write in V8 | UNKNOWN | — | 87%ile | Microsoft | 2025-08-12 |
| CVE-2025-8582 | Chromium: CVE-2025-8582 Insufficient validation of untrusted input in DOM | UNKNOWN | — | 16%ile | Microsoft | 2025-08-12 |
| CVE-2025-8581 | Chromium: CVE-2025-8581 Inappropriate implementation in Extensions | UNKNOWN | — | 21%ile | Microsoft | 2025-08-12 |
| CVE-2025-8580 | Chromium: CVE-2025-8580 Inappropriate implementation in Filesystems | UNKNOWN | — | 16%ile | Microsoft | 2025-08-12 |
| CVE-2025-8578 | Chromium: CVE-2025-8578 Use after free in Cast | UNKNOWN | — | 27%ile | Microsoft | 2025-08-12 |
| CVE-2025-8576 | Chromium: CVE-2025-8576 Use after free in Extensions | UNKNOWN | — | 25%ile | Microsoft | 2025-08-12 |
| CVE-2025-8882 | Chromium: CVE-2025-8882 Use after free in Aura | UNKNOWN | — | 18%ile | Microsoft | 2025-08-12 |
| CVE-2025-8881 | Chromium: CVE-2025-8881 Inappropriate implementation in File Picker | UNKNOWN | — | 15%ile | Microsoft | 2025-08-12 |
| CVE-2025-8901 | Chromium: CVE-2025-8901 Out of bounds write in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2025-08-12 |
| CVE-2025-8880 | Chromium: CVE-2025-8880 Race in V8 | UNKNOWN | — | 18%ile | Microsoft | 2025-08-12 |
| CVE-2025-8879 | Chromium: CVE-2025-8879 Heap buffer overflow in libaom | UNKNOWN | — | 20%ile | Microsoft | 2025-08-12 |
| CVE-2025-8583 | Chromium: CVE-2025-8583 Inappropriate implementation in Permissions | UNKNOWN | — | 14%ile | Microsoft | 2025-08-12 |
| CVE-2025-8579 | Chromium: CVE-2025-8579 Inappropriate implementation in Gemini Live in Chrome | UNKNOWN | — | 16%ile | Microsoft | 2025-08-12 |
| CVE-2025-8577 | Chromium: CVE-2025-8577 Inappropriate implementation in Picture In Picture | UNKNOWN | — | 16%ile | Microsoft | 2025-08-12 |
| CVE-2025-9478 | Chromium: CVE-2025-9478 Use after free in ANGLE | UNKNOWN | — | 89%ile | Microsoft | 2025-08-12 |
| CVE-2022-48716 | ASoC: codecs: wcd938x: fix incorrect used of portid | CRITICAL | 9.8 | 39%ile | Microsoft | 2024-06-11 |
| CVE-2024-24790 | Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip | CRITICAL | 9.8 | 79%ile | Microsoft | 2024-06-11 |
| CVE-2024-39331 | In Emacs before 29.4 org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe | CRITICAL | 9.8 | 70%ile | Microsoft | 2024-06-11 |
| CVE-2024-4577 | Argument Injection in PHP-CGI | CRITICAL | 9.8 | 100%ile | Microsoft | 2024-06-11 |
| CVE-2024-5699 | In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by | CRITICAL | 9.8 | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-38541 | of: module: add buffer overflow check in of_modalias() | CRITICAL | 9.8 | 58%ile | Microsoft | 2024-06-11 |
| CVE-2024-5701 | Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that w | CRITICAL | 9.8 | 46%ile | Microsoft | 2024-06-11 |
| CVE-2024-5171 | heap buffer overflow in libaom | CRITICAL | 9.8 | 68%ile | Microsoft | 2024-06-11 |
| CVE-2024-30080 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99%ile | Microsoft | 2024-06-11 |
| CVE-2024-37371 | In MIT Kerberos 5 (aka krb5) before 1.21.3 an attacker can cause invalid memory reads during GSS message token handling | CRITICAL | 9.1 | 78%ile | Microsoft | 2024-06-11 |
| CVE-2024-37407 | Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enable | CRITICAL | 9.1 | 60%ile | Microsoft | 2024-06-11 |
| CVE-2024-38428 | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insec | CRITICAL | 9.1 | 50%ile | Microsoft | 2024-06-11 |
| CVE-2024-5197 | Integer overflow in libvpx | CRITICAL | 9.1 | 56%ile | Microsoft | 2024-06-11 |
| CVE-2024-29039 | Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state | CRITICAL | 9.0 | 61%ile | Microsoft | 2024-06-11 |
| CVE-2024-5187 | Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx | HIGH | 8.8 | 66%ile | Microsoft | 2024-06-11 |
| CVE-2024-5585 | Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix) | HIGH | 8.8 | 98%ile | Microsoft | 2024-06-11 |
| CVE-2024-38620 | Bluetooth: HCI: Remove HCI_AMP support | HIGH | 8.8 | 24%ile | Microsoft | 2024-06-11 |
| CVE-2024-30078 | Windows Wi-Fi Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 92%ile | Microsoft | 2024-06-11 |
| CVE-2024-30064 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2024-06-11 |
| CVE-2024-30068 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-30097 | Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | HIGH | 8.8 | 76%ile | Microsoft | 2024-06-11 |
| CVE-2024-30103 | Microsoft Outlook Remote Code Execution Vulnerability | HIGH | 8.8 | 88%ile | Microsoft | 2024-06-11 |
| CVE-2024-35249 | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | HIGH | 8.8 | 88%ile | Microsoft | 2024-06-11 |
| CVE-2024-37676 | An issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSett | HIGH | 8.4 | 11%ile | Microsoft | 2024-06-11 |
| CVE-2024-6257 | HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation | HIGH | 8.4 | 60%ile | Microsoft | 2024-06-11 |
| CVE-2024-37325 | Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability | HIGH | 8.1 | 65%ile | Microsoft | 2024-06-11 |
| CVE-2024-30074 | Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | HIGH | 8.0 | 66%ile | Microsoft | 2024-06-11 |
| CVE-2024-30075 | Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | HIGH | 8.0 | 58%ile | Microsoft | 2024-06-11 |
| CVE-2024-30077 | Windows OLE Remote Code Execution Vulnerability | HIGH | 8.0 | 78%ile | Microsoft | 2024-06-11 |
| CVE-2024-35260 | Microsoft Dataverse Remote Code Execution Vulnerability | HIGH | 8.0 | 56%ile | Microsoft | 2024-06-11 |
| CVE-2022-48744 | net/mlx5e: Avoid field-overflowing memcpy() | HIGH | 7.8 | 47%ile | Microsoft | 2024-06-11 |
| CVE-2024-36477 | tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer | HIGH | 7.8 | 13%ile | Microsoft | 2024-06-11 |
| CVE-2024-36971 | net: fix __dst_negative_advice() race | HIGH | 7.8 | 85%ile | Microsoft | 2024-06-11 |
| CVE-2024-38545 | RDMA/hns: Fix UAF for cq async event | HIGH | 7.8 | 17%ile | Microsoft | 2024-06-11 |
| CVE-2024-38556 | net/mlx5: Add a timeout to acquire the command queue semaphore | HIGH | 7.8 | 18%ile | Microsoft | 2024-06-11 |
| CVE-2024-38570 | gfs2: Fix potential glock use-after-free on unmount | HIGH | 7.8 | 51%ile | Microsoft | 2024-06-11 |
| CVE-2024-38577 | rcu-tasks: Fix show_rcu_tasks_trace_gp_kthread buffer overflow | HIGH | 7.8 | 18%ile | Microsoft | 2024-06-11 |
| CVE-2024-38581 | drm/amdgpu/mes: fix use-after-free issue | HIGH | 7.8 | 14%ile | Microsoft | 2024-06-11 |
| CVE-2024-38583 | nilfs2: fix use-after-free of timer for log writer thread | HIGH | 7.8 | 18%ile | Microsoft | 2024-06-11 |
| CVE-2024-38588 | ftrace: Fix possible use-after-free issue in ftrace_location() | HIGH | 7.8 | 15%ile | Microsoft | 2024-06-11 |
| CVE-2024-38630 | watchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger | HIGH | 7.8 | 17%ile | Microsoft | 2024-06-11 |
| CVE-2024-38664 | drm: zynqmp_dpsub: Always register bridge | HIGH | 7.8 | 10%ile | Microsoft | 2024-06-11 |
| CVE-2024-38667 | riscv: prevent pt_regs corruption for secondary idle threads | HIGH | 7.8 | 14%ile | Microsoft | 2024-06-11 |
| CVE-2024-39277 | dma-mapping: benchmark: handle NUMA_NO_NODE correctly | HIGH | 7.8 | 13%ile | Microsoft | 2024-06-11 |
| CVE-2024-39291 | drm/amdgpu: Fix buffer size in gfx_v9_4_3_init_ cp_compute_microcode() and rlc_microcode() | HIGH | 7.8 | 16%ile | Microsoft | 2024-06-11 |
| CVE-2024-39463 | 9p: add missing locking around taking dentry fid list | HIGH | 7.8 | 17%ile | Microsoft | 2024-06-11 |
| CVE-2024-38628 | usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind. | HIGH | 7.8 | 8%ile | Microsoft | 2024-06-11 |
| CVE-2024-30072 | Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2024-06-11 |
| CVE-2024-30082 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 68%ile | Microsoft | 2024-06-11 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 98%ile | Microsoft | 2024-06-11 |
| CVE-2024-30062 | Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability | HIGH | 7.8 | 61%ile | Microsoft | 2024-06-11 |
| CVE-2024-30085 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 96%ile | Microsoft | 2024-06-11 |
| CVE-2024-30086 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 65%ile | Microsoft | 2024-06-11 |
| CVE-2024-30087 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 95%ile | Microsoft | 2024-06-11 |
| CVE-2024-30089 | Microsoft Streaming Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 95%ile | Microsoft | 2024-06-11 |
| CVE-2024-30091 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 91%ile | Microsoft | 2024-06-11 |
| CVE-2024-30094 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.8 | 58%ile | Microsoft | 2024-06-11 |
| CVE-2024-30095 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.8 | 62%ile | Microsoft | 2024-06-11 |
| CVE-2024-30100 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.8 | 66%ile | Microsoft | 2024-06-11 |
| CVE-2024-30104 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 74%ile | Microsoft | 2024-06-11 |
| CVE-2024-33655 | The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by | HIGH | 7.5 | 77%ile | Microsoft | 2024-06-11 |
| CVE-2024-36972 | af_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock. | HIGH | 7.5 | 43%ile | Microsoft | 2024-06-11 |
| CVE-2024-37370 | In MIT Kerberos 5 (aka krb5) before 1.21.3 an attacker can modify the plaintext Extra Count field of a confidential GSS | HIGH | 7.5 | 53%ile | Microsoft | 2024-06-11 |
| CVE-2024-37890 | Denial of service when handling a request with many HTTP headers in ws | HIGH | 7.5 | 70%ile | Microsoft | 2024-06-11 |
| CVE-2024-39134 | A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_f | HIGH | 7.5 | 48%ile | Microsoft | 2024-06-11 |
| CVE-2024-4032 | Incorrect IPv4 and IPv6 private ranges | HIGH | 7.5 | 64%ile | Microsoft | 2024-06-11 |
| CVE-2024-5702 | Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects | HIGH | 7.5 | 57%ile | Microsoft | 2024-06-11 |
| CVE-2024-5694 | An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section | HIGH | 7.5 | 40%ile | Microsoft | 2024-06-11 |
| CVE-2024-30070 | DHCP Server Service Denial of Service Vulnerability | HIGH | 7.5 | 83%ile | Microsoft | 2024-06-11 |
| CVE-2023-50868 | MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU | HIGH | 7.5 | 100%ile | Microsoft | 2024-06-11 |
| CVE-2024-30083 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | HIGH | 7.5 | 84%ile | Microsoft | 2024-06-11 |
| CVE-2024-30101 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.5 | 77%ile | Microsoft | 2024-06-11 |
| CVE-2024-35252 | Azure Storage Movement Client Library Denial of Service Vulnerability | HIGH | 7.5 | 84%ile | Microsoft | 2024-06-11 |
| CVE-2024-0397 | Memory race condition in ssl.SSLContext certificate store methods | HIGH | 7.4 | 55%ile | Microsoft | 2024-06-11 |
| CVE-2024-29187 | GitHub: CVE-2024-29187 WiX Burn-based bundles are vulnerable to binary hijack when run as SYSTEM | HIGH | 7.3 | 39%ile | Microsoft | 2024-06-11 |
| CVE-2024-30093 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.3 | 65%ile | Microsoft | 2024-06-11 |
| CVE-2024-30102 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.3 | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-35248 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | HIGH | 7.3 | 60%ile | Microsoft | 2024-06-11 |
| CVE-2024-38381 | nfc: nci: Fix uninit-value in nci_rx_work | HIGH | 7.1 | 32%ile | Microsoft | 2024-06-11 |
| CVE-2024-38538 | net: bridge: xmit: make sure we have at least eth header len bytes | HIGH | 7.1 | 21%ile | Microsoft | 2024-06-11 |
| CVE-2024-38635 | soundwire: cadence: fix invalid PDI offset | HIGH | 7.1 | 15%ile | Microsoft | 2024-06-11 |
| CVE-2024-35254 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 7.1 | 56%ile | Microsoft | 2024-06-11 |
| CVE-2024-30084 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 93%ile | Microsoft | 2024-06-11 |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 99%ile | Microsoft | 2024-06-11 |
| CVE-2024-30090 | Microsoft Streaming Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 80%ile | Microsoft | 2024-06-11 |
| CVE-2024-30099 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 44%ile | Microsoft | 2024-06-11 |
| CVE-2024-35265 | Windows Perception Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 31%ile | Microsoft | 2024-06-11 |
| CVE-2024-30076 | Windows Container Manager Service Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 76%ile | Microsoft | 2024-06-11 |
| CVE-2024-5742 | Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious s | MEDIUM | 6.7 | 28%ile | Microsoft | 2024-06-11 |
| CVE-2024-29060 | Visual Studio Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 58%ile | Microsoft | 2024-06-11 |
| CVE-2024-30063 | Windows Distributed File System (DFS) Remote Code Execution Vulnerability | MEDIUM | 6.7 | 62%ile | Microsoft | 2024-06-11 |
| CVE-2022-4968 | netplan leaks the private key of wireguard to local users. | MEDIUM | 6.5 | 18%ile | Microsoft | 2024-06-11 |
| CVE-2024-24789 | Mishandling of corrupt central directory record in archive/zip | MEDIUM | 6.5 | 38%ile | Microsoft | 2024-06-11 |
| CVE-2024-36968 | Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() | MEDIUM | 6.5 | 22%ile | Microsoft | 2024-06-11 |
| CVE-2024-5642 | Buffer overread when using an empty list with SSLContext.set_npn_protocols() | MEDIUM | 6.5 | 53%ile | Microsoft | 2024-06-11 |
| CVE-2024-6104 | go-retryablehttp can leak basic auth credentials to log files | MEDIUM | 6.0 | 30%ile | Microsoft | 2024-06-11 |
| CVE-2024-2408 | PHP is vulnerable to the Marvin Attack | MEDIUM | 5.9 | 66%ile | Microsoft | 2024-06-11 |
| CVE-2024-35263 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | MEDIUM | 5.7 | 76%ile | Microsoft | 2024-06-11 |
| CVE-2022-48766 | drm/amd/display: Wrap dcn301_calculate_wm_and_dlg for FPU. | MEDIUM | 5.5 | 8%ile | Microsoft | 2024-06-11 |
| CVE-2024-36244 | net/sched: taprio: extend minimum interval restriction to entire cycle too | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-06-11 |
| CVE-2024-36288 | SUNRPC: Fix loop termination condition in gss_free_in_token_pages() | MEDIUM | 5.5 | 53%ile | Microsoft | 2024-06-11 |
| CVE-2024-36478 | null_blk: fix null-ptr-dereference while configuring 'power' and 'submit_queues' | MEDIUM | 5.5 | 19%ile | Microsoft | 2024-06-11 |
| CVE-2024-36481 | tracing/probes: fix error check in parse_btf_field() | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-06-11 |
| CVE-2024-36965 | remoteproc: mediatek: Make sure IPI buffer fits in L2TCM | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-06-11 |
| CVE-2024-36967 | KEYS: trusted: Fix memory leak in tpm2_key_encode() | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-06-11 |
| CVE-2024-36969 | drm/amd/display: Fix division by zero in setup_dsc_config | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-06-11 |
| CVE-2024-38564 | bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-06-11 |
| CVE-2024-38571 | thermal/drivers/tsens: Fix null pointer dereference | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-06-11 |
| CVE-2024-38595 | net/mlx5: Fix peer devlink set for SF representor devlink port | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-06-11 |
| CVE-2024-38603 | drivers/perf: hisi: hns3: Actually use devm_add_action_or_reset() | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-06-11 |
| CVE-2024-38780 | dma-buf/sw-sync: don't enable IRQ from sync_print_obj() | MEDIUM | 5.5 | 9%ile | Microsoft | 2024-06-11 |
| CVE-2024-39292 | um: Add winch to winch_handlers before registering winch IRQ | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-06-11 |
| CVE-2024-38608 | net/mlx5e: Fix netif state handling | MEDIUM | 5.5 | 9%ile | Microsoft | 2024-06-11 |
| CVE-2024-38553 | net: fec: remove .ndo_poll_controller to avoid deadlocks | MEDIUM | 5.5 | 9%ile | Microsoft | 2024-06-11 |
| CVE-2024-38557 | net/mlx5: Reload only IB representors upon lag disable/enable | MEDIUM | 5.5 | 8%ile | Microsoft | 2024-06-11 |
| CVE-2024-38543 | lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-06-11 |
| CVE-2024-36479 | fpga: bridge: add owner module and take its refcount | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-06-11 |
| CVE-2024-37021 | fpga: manager: add owner module and take its refcount | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-06-11 |
| CVE-2024-38625 | fs/ntfs3: Check 'folio' pointer for NULL | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-06-11 |
| CVE-2024-35255 | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 56%ile | Microsoft | 2024-06-11 |
| CVE-2024-30065 | Windows Themes Denial of Service Vulnerability | MEDIUM | 5.5 | 56%ile | Microsoft | 2024-06-11 |
| CVE-2024-30066 | Winlogon Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 49%ile | Microsoft | 2024-06-11 |
| CVE-2024-30067 | Winlogon Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 49%ile | Microsoft | 2024-06-11 |
| CVE-2024-30096 | Windows Cryptographic Services Information Disclosure Vulnerability | MEDIUM | 5.5 | 60%ile | Microsoft | 2024-06-11 |
| CVE-2024-30058 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 34%ile | Microsoft | 2024-06-11 |
| CVE-2024-30057 | Microsoft Edge for iOS Spoofing Vulnerability | MEDIUM | 5.4 | 35%ile | Microsoft | 2024-06-11 |
| CVE-2024-5458 | Filter bypass in filter_var (FILTER_VALIDATE_URL) | MEDIUM | 5.3 | 96%ile | Microsoft | 2024-06-11 |
| CVE-2024-37354 | btrfs: fix crash on racing fsync and size-extending write into prealloc | MEDIUM | 4.7 | 7%ile | Microsoft | 2024-06-11 |
| CVE-2024-38662 | bpf: Allow delete from sockmap/sockhash only if update is allowed | MEDIUM | 4.7 | 13%ile | Microsoft | 2024-06-11 |
| CVE-2024-30069 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 4.7 | 46%ile | Microsoft | 2024-06-11 |
| CVE-2024-38082 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.7 | 42%ile | Microsoft | 2024-06-11 |
| CVE-2024-30052 | Visual Studio Remote Code Execution Vulnerability | MEDIUM | 4.7 | 70%ile | Microsoft | 2024-06-11 |
| CVE-2023-52890 | NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that | MEDIUM | 4.5 | 6%ile | Microsoft | 2024-06-11 |
| CVE-2024-35235 | Cupsd Listen arbitrary chmod 0140777 | MEDIUM | 4.4 | 83%ile | Microsoft | 2024-06-11 |
| CVE-2024-37535 | GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape | MEDIUM | 4.4 | 15%ile | Microsoft | 2024-06-11 |
| CVE-2024-37891 | Proxy-Authorization request header isn't stripped during cross-origin redirects in urllib3 | MEDIUM | 4.4 | 65%ile | Microsoft | 2024-06-11 |
| CVE-2024-38540 | bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq | MEDIUM | 4.4 | 17%ile | Microsoft | 2024-06-11 |
| CVE-2024-35253 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | MEDIUM | 4.4 | 53%ile | Microsoft | 2024-06-11 |
| CVE-2024-29038 | tpm2 does not detect if quote was not generated by TPM | MEDIUM | 4.3 | 31%ile | Microsoft | 2024-06-11 |
| CVE-2024-29040 | Fapi Verify Quote: Does not detect if quote was not generated by TPM | MEDIUM | 4.3 | 26%ile | Microsoft | 2024-06-11 |
| CVE-2024-39133 | Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_pars | MEDIUM | 4.3 | 42%ile | Microsoft | 2024-06-11 |
| CVE-2024-5690 | By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were fun | MEDIUM | 4.3 | 53%ile | Microsoft | 2024-06-11 |
| CVE-2024-38093 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 42%ile | Microsoft | 2024-06-11 |
| CVE-2024-38083 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 42%ile | Microsoft | 2024-06-11 |
| CVE-2024-38594 | net: stmmac: move the EST lock to struct stmmac_priv | LOW | 3.3 | 12%ile | Microsoft | 2024-06-11 |
| CVE-2022-2601-M | CVE-2022-2601-M | UNKNOWN | — | — | Microsoft | 2024-06-11 |
| CVE-2022-3775-M | CVE-2022-3775-M | UNKNOWN | — | — | Microsoft | 2024-06-11 |
| CVE-2024-5841 | Chromium: CVE-2024-5841 Use after free in V8 | UNKNOWN | — | 92%ile | Microsoft | 2024-06-11 |
| CVE-2024-5835 | Chromium: CVE-2024-5835 Heap buffer overflow in Tab Groups | UNKNOWN | — | 43%ile | Microsoft | 2024-06-11 |
| CVE-2024-5837 | Chromium: CVE-2024-5837 Type Confusion in V8 | UNKNOWN | — | 44%ile | Microsoft | 2024-06-11 |
| CVE-2024-5844 | Chromium: CVE-2024-5844 Heap buffer overflow in Tab Strip | UNKNOWN | — | 44%ile | Microsoft | 2024-06-11 |
| CVE-2024-5833 | Chromium: CVE-2024-5833 Type Confusion in V8 | UNKNOWN | — | 43%ile | Microsoft | 2024-06-11 |
| CVE-2024-5839 | Chromium: CVE-2024-5839 Inappropriate Implementation in Memory Allocator | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-5836 | Chromium: CVE-2024-5836 Inappropriate Implementation in DevTools | UNKNOWN | — | 42%ile | Microsoft | 2024-06-11 |
| CVE-2024-5834 | Chromium: CVE-2024-5834 Inappropriate implementation in Dawn | UNKNOWN | — | 46%ile | Microsoft | 2024-06-11 |
| CVE-2024-5843 | Chromium: CVE-2024-5843 Inappropriate implementation in Downloads | UNKNOWN | — | 40%ile | Microsoft | 2024-06-11 |
| CVE-2024-5831 | Chromium: CVE-2024-5831 Use after free in Dawn | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-5840 | Chromium: CVE-2024-5840 Policy Bypass in CORS | UNKNOWN | — | 35%ile | Microsoft | 2024-06-11 |
| CVE-2024-5842 | Chromium: CVE-2024-5842 Use after free in Browser UI | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-5838 | Chromium: CVE-2024-5838 Type Confusion in V8 | UNKNOWN | — | 43%ile | Microsoft | 2024-06-11 |
| CVE-2024-5832 | Chromium: CVE-2024-5832 Use after free in Dawn | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-5830 | Chromium: CVE-2024-5830 Type Confusion in V8 | UNKNOWN | — | 59%ile | Microsoft | 2024-06-11 |
| CVE-2024-5493 | Chromium: CVE-2024-5493 Heap buffer overflow in WebRTC | UNKNOWN | — | 57%ile | Microsoft | 2024-06-11 |
| CVE-2024-5498 | Chromium: CVE-2024-5498 Use after free in Presentation API | UNKNOWN | — | 53%ile | Microsoft | 2024-06-11 |
| CVE-2024-5496 | Chromium: CVE-2024-5496 Use after free in Media Session | UNKNOWN | — | 58%ile | Microsoft | 2024-06-11 |
| CVE-2024-5499 | Chromium: CVE-2024-5499 Out of bounds write in Streams API | UNKNOWN | — | 60%ile | Microsoft | 2024-06-11 |
| CVE-2024-5494 | Chromium: CVE-2024-5494 Use after free in Dawn | UNKNOWN | — | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-5497 | Chromium: CVE-2024-5497 Out of bounds memory access in Keyboard Inputs | UNKNOWN | — | 57%ile | Microsoft | 2024-06-11 |
| CVE-2024-5495 | Chromium: CVE-2024-5495 Use after free in Dawn | UNKNOWN | — | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-6103 | Chromium: CVE-2024-6103: Use after free in Dawn | UNKNOWN | — | 49%ile | Microsoft | 2024-06-11 |
| CVE-2024-6102 | Chromium: CVE-2024-6102: Out of bounds memory access in Dawn | UNKNOWN | — | 52%ile | Microsoft | 2024-06-11 |
| CVE-2024-6101 | Chromium: CVE-2024-6101: Inappropriate implementation in WebAssembly | UNKNOWN | — | 55%ile | Microsoft | 2024-06-11 |
| CVE-2024-6100 | Chromium: CVE-2024-6100 Type Confusion in V8 | UNKNOWN | — | 65%ile | Microsoft | 2024-06-11 |
| CVE-2024-6290 | Chromium: CVE-2024-6290 Use after free in Dawn | UNKNOWN | — | 48%ile | Microsoft | 2024-06-11 |
| CVE-2024-6293 | Chromium: CVE-2024-6293 Use after free in Dawn | UNKNOWN | — | 48%ile | Microsoft | 2024-06-11 |
| CVE-2024-6292 | Chromium: CVE-2024-6292 Use after free in Dawn | UNKNOWN | — | 48%ile | Microsoft | 2024-06-11 |
| CVE-2024-6291 | Chromium: CVE-2024-6291 Use after free in Swiftshader | UNKNOWN | — | 50%ile | Microsoft | 2024-06-11 |
| CVE-2024-34122 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | UNKNOWN | — | 25%ile | Microsoft | 2024-06-11 |
| CVE-2024-5846 | Chromium: CVE-2024-5846 Use after free in PDFium | UNKNOWN | — | 40%ile | Microsoft | 2024-06-11 |
| CVE-2024-5847 | Chromium: CVE-2024-5847 Use after free in PDFium | UNKNOWN | — | 40%ile | Microsoft | 2024-06-11 |
| CVE-2024-5845 | Chromium: CVE-2024-5845 Use after free in Audio | UNKNOWN | — | 39%ile | Microsoft | 2024-06-11 |
| CVE-2020-19692 | Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs | CRITICAL | 9.8 | 70%ile | Microsoft | 2023-04-11 |
| CVE-2020-19695 | Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parame | CRITICAL | 9.8 | 70%ile | Microsoft | 2023-04-11 |
| CVE-2021-28235 | Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug func | CRITICAL | 9.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24538 | Backticks not treated as string delimiters in html/template | CRITICAL | 9.8 | 82%ile | Microsoft | 2023-04-11 |
| CVE-2023-26463 | strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two di | CRITICAL | 9.8 | 82%ile | Microsoft | 2023-04-11 |
| CVE-2023-21554 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100%ile | Microsoft | 2023-04-11 |
| CVE-2023-28250 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 80%ile | Microsoft | 2023-04-11 |
| CVE-2021-45955 | CVE-2021-45955 | CRITICAL | 9.8 | 84%ile | Microsoft | 2023-04-11 |
| CVE-2021-45957 | CVE-2021-45957 | CRITICAL | 9.8 | 84%ile | Microsoft | 2023-04-11 |
| CVE-2022-37601 | CVE-2022-37601 | CRITICAL | 9.8 | 86%ile | Microsoft | 2023-04-11 |
| CVE-2023-21727 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24926 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24885 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24927 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24886 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24928 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24929 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24887 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-28297 | Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability | HIGH | 8.8 | 76%ile | Microsoft | 2023-04-11 |
| CVE-2023-24924 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24925 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-24884 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-28231 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 8.8 | 98%ile | Microsoft | 2023-04-11 |
| CVE-2023-28240 | Windows Network Load Balancing Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2023-04-11 |
| CVE-2023-28243 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2023-28275 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 72%ile | Microsoft | 2023-04-11 |
| CVE-2023-28291 | Raw Image Extension Remote Code Execution Vulnerability | HIGH | 8.4 | 48%ile | Microsoft | 2023-04-11 |
| CVE-2023-1668 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0 OVS will install the datapath flow w | HIGH | 8.2 | 67%ile | Microsoft | 2023-04-11 |
| CVE-2023-31484 | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. | HIGH | 8.1 | 74%ile | Microsoft | 2023-04-11 |
| CVE-2023-31486 | HTTP::Tiny before 0.083 a Perl core module since 5.13.9 and available standalone on CPAN has an insecure default TLS con | HIGH | 8.1 | 77%ile | Microsoft | 2023-04-11 |
| CVE-2023-28288 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 8.1 | 93%ile | Microsoft | 2023-04-11 |
| CVE-2023-28219 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | HIGH | 8.1 | 97%ile | Microsoft | 2023-04-11 |
| CVE-2023-28220 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | HIGH | 8.1 | 97%ile | Microsoft | 2023-04-11 |
| CVE-2023-28244 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 8.1 | 86%ile | Microsoft | 2023-04-11 |
| CVE-2023-28268 | Netlogon RPC Elevation of Privilege Vulnerability | HIGH | 8.1 | 73%ile | Microsoft | 2023-04-11 |
| CVE-2021-46878 | An issue was discovered in Treasure Data Fluent Bit 1.7.1 erroneous parsing in flb_pack_msgpack_to_json_format leads to | HIGH | 7.8 | 29%ile | Microsoft | 2023-04-11 |
| CVE-2021-46879 | An issue was discovered in Treasure Data Fluent Bit 1.7.1 a wrong variable is used to get the msgpack data resulting in | HIGH | 7.8 | 32%ile | Microsoft | 2023-04-11 |
| CVE-2023-1829 | Use-after-free in tcindex (traffic control index filter) in the Linux Kernel | HIGH | 7.8 | 62%ile | Microsoft | 2023-04-11 |
| CVE-2023-2007 | The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when pe | HIGH | 7.8 | 22%ile | Microsoft | 2023-04-11 |
| CVE-2023-2008 | A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue | HIGH | 7.8 | 62%ile | Microsoft | 2023-04-11 |
| CVE-2023-21100 | In inflate of inflate.c there is a possible out of bounds write due to a heap buffer overflow. This could lead to local | HIGH | 7.8 | 1%ile | Microsoft | 2023-04-11 |
| CVE-2023-29491 | ncurses before 6.4 20230408 when used by a setuid application allows local users to trigger security-relevant memory cor | HIGH | 7.8 | 59%ile | Microsoft | 2023-04-11 |
| CVE-2023-31436 | qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can | HIGH | 7.8 | 47%ile | Microsoft | 2023-04-11 |
| CVE-2023-23375 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | HIGH | 7.8 | 52%ile | Microsoft | 2023-04-11 |
| CVE-2023-24912 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 89%ile | Microsoft | 2023-04-11 |
| CVE-2023-28285 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 87%ile | Microsoft | 2023-04-11 |
| CVE-2023-28287 | Microsoft Publisher Remote Code Execution Vulnerability | HIGH | 7.8 | 53%ile | Microsoft | 2023-04-11 |
| CVE-2023-28292 | Raw Image Extension Remote Code Execution Vulnerability | HIGH | 7.8 | 47%ile | Microsoft | 2023-04-11 |
| CVE-2023-28295 | Microsoft Publisher Remote Code Execution Vulnerability | HIGH | 7.8 | 53%ile | Microsoft | 2023-04-11 |
| CVE-2023-24893 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 7.8 | 64%ile | Microsoft | 2023-04-11 |
| CVE-2023-28225 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2023-04-11 |
| CVE-2023-28236 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2023-04-11 |
| CVE-2023-28237 | Windows Kernel Remote Code Execution Vulnerability | HIGH | 7.8 | 47%ile | Microsoft | 2023-04-11 |
| CVE-2023-28246 | Windows Registry Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2023-04-11 |
| CVE-2023-28248 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 53%ile | Microsoft | 2023-04-11 |
| CVE-2023-28272 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2023-04-11 |
| CVE-2023-28274 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 94%ile | Microsoft | 2023-04-11 |
| CVE-2023-28252 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 99%ile | Microsoft | 2023-04-11 |
| CVE-2023-28260 | .NET DLL Hijacking Remote Code Execution Vulnerability | HIGH | 7.8 | 74%ile | Microsoft | 2023-04-11 |
| CVE-2023-28262 | Visual Studio Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2023-04-11 |
| CVE-2023-28293 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 86%ile | Microsoft | 2023-04-11 |
| CVE-2023-28296 | Visual Studio Remote Code Execution Vulnerability | HIGH | 7.8 | 51%ile | Microsoft | 2023-04-11 |
| CVE-2023-28304 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | HIGH | 7.8 | 56%ile | Microsoft | 2023-04-11 |
| CVE-2023-28311 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 85%ile | Microsoft | 2023-04-11 |
| CVE-2023-28642 | CVE-2023-28642 | HIGH | 7.8 | 28%ile | Microsoft | 2023-04-11 |
| CVE-2023-1281 | CVE-2023-1281 | HIGH | 7.8 | 23%ile | Microsoft | 2023-04-11 |
| CVE-2022-48424 | CVE-2022-48424 | HIGH | 7.8 | 19%ile | Microsoft | 2023-04-11 |
| CVE-2022-48423 | CVE-2022-48423 | HIGH | 7.8 | 19%ile | Microsoft | 2023-04-11 |
| CVE-2023-26604 | CVE-2023-26604 | HIGH | 7.8 | 63%ile | Microsoft | 2023-04-11 |
| CVE-2023-28309 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | HIGH | 7.6 | 53%ile | Microsoft | 2023-04-11 |
| CVE-2023-24534 | Excessive memory allocation in net/http and net/textproto | HIGH | 7.5 | 79%ile | Microsoft | 2023-04-11 |
| CVE-2023-24536 | Excessive resource consumption in net/http, net/textproto and mime/multipart | HIGH | 7.5 | 73%ile | Microsoft | 2023-04-11 |
| CVE-2023-24537 | Infinite loop in parsing in go/scanner | HIGH | 7.5 | 72%ile | Microsoft | 2023-04-11 |
| CVE-2023-24607 | Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of | HIGH | 7.5 | 70%ile | Microsoft | 2023-04-11 |
| CVE-2023-26917 | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validat | HIGH | 7.5 | 58%ile | Microsoft | 2023-04-11 |
| CVE-2023-26964 | An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STRE | HIGH | 7.5 | 65%ile | Microsoft | 2023-04-11 |
| CVE-2023-28625 | mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied | HIGH | 7.5 | 70%ile | Microsoft | 2023-04-11 |
| CVE-2023-21769 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH | 7.5 | 100%ile | Microsoft | 2023-04-11 |
| CVE-2023-24860 | Microsoft Defender Denial of Service Vulnerability | HIGH | 7.5 | 87%ile | Microsoft | 2023-04-11 |
| CVE-2023-24931 | Windows Secure Channel Denial of Service Vulnerability | HIGH | 7.5 | 80%ile | Microsoft | 2023-04-11 |
| CVE-2023-28217 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | HIGH | 7.5 | 79%ile | Microsoft | 2023-04-11 |
| CVE-2023-28300 | Azure Service Connector Security Feature Bypass Vulnerability | HIGH | 7.5 | 61%ile | Microsoft | 2023-04-11 |
| CVE-2023-28227 | Windows Bluetooth Driver Remote Code Execution Vulnerability | HIGH | 7.5 | 94%ile | Microsoft | 2023-04-11 |
| CVE-2023-28232 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | HIGH | 7.5 | 58%ile | Microsoft | 2023-04-11 |
| CVE-2023-28233 | Windows Secure Channel Denial of Service Vulnerability | HIGH | 7.5 | 77%ile | Microsoft | 2023-04-11 |
| CVE-2023-28234 | Windows Secure Channel Denial of Service Vulnerability | HIGH | 7.5 | 77%ile | Microsoft | 2023-04-11 |
| CVE-2023-28238 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2023-04-11 |
| CVE-2023-28241 | Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | HIGH | 7.5 | 80%ile | Microsoft | 2023-04-11 |
| CVE-2023-28247 | Windows Network File System Information Disclosure Vulnerability | HIGH | 7.5 | 74%ile | Microsoft | 2023-04-11 |
| CVE-2023-28302 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH | 7.5 | 100%ile | Microsoft | 2023-04-11 |
| CVE-2023-28448 | CVE-2023-28448 | HIGH | 7.5 | 45%ile | Microsoft | 2023-04-11 |
| CVE-2022-25882 | CVE-2022-25882 | HIGH | 7.5 | 75%ile | Microsoft | 2023-04-11 |
| CVE-2022-4899 | CVE-2022-4899 | HIGH | 7.5 | 74%ile | Microsoft | 2023-04-11 |
| CVE-2023-1390 | CVE-2023-1390 | HIGH | 7.5 | 92%ile | Microsoft | 2023-04-11 |
| CVE-2023-23384 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 7.3 | 57%ile | Microsoft | 2023-04-11 |
| CVE-2023-28254 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.2 | 72%ile | Microsoft | 2023-04-11 |
| CVE-2023-1838 | A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Li | HIGH | 7.1 | 17%ile | Microsoft | 2023-04-11 |
| CVE-2023-21980 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are aff | HIGH | 7.1 | 56%ile | Microsoft | 2023-04-11 |
| CVE-2023-30630 | Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because for example executi | HIGH | 7.1 | 43%ile | Microsoft | 2023-04-11 |
| CVE-2023-28222 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.1 | 51%ile | Microsoft | 2023-04-11 |
| CVE-2023-28224 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | HIGH | 7.1 | 33%ile | Microsoft | 2023-04-11 |
| CVE-2023-1872 | Use-after-free in Linux kernel's io_uring subsystem | HIGH | 7.0 | 21%ile | Microsoft | 2023-04-11 |
| CVE-2023-1989 | A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw a call | HIGH | 7.0 | 33%ile | Microsoft | 2023-04-11 |
| CVE-2023-2006 | A race condition was found in the Linux kernel's RxRPC network protocol within the processing of RxRPC bundles. This iss | HIGH | 7.0 | 30%ile | Microsoft | 2023-04-11 |
| CVE-2023-24914 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 26%ile | Microsoft | 2023-04-11 |
| CVE-2023-28216 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | HIGH | 7.0 | 31%ile | Microsoft | 2023-04-11 |
| CVE-2023-28218 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 96%ile | Microsoft | 2023-04-11 |
| CVE-2023-28221 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 41%ile | Microsoft | 2023-04-11 |
| CVE-2023-28229 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 76%ile | Microsoft | 2023-04-11 |
| CVE-2023-28273 | Windows Clip Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2023-04-11 |
| CVE-2023-27561 | CVE-2023-27561 | HIGH | 7.0 | 38%ile | Microsoft | 2023-04-11 |
| CVE-2023-28235 | Windows Lock Screen Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 44%ile | Microsoft | 2023-04-11 |
| CVE-2023-28270 | Windows Lock Screen Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 41%ile | Microsoft | 2023-04-11 |
| CVE-2023-1079 | CVE-2023-1079 | MEDIUM | 6.8 | 39%ile | Microsoft | 2023-04-11 |
| CVE-2023-2194 | An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->blo | MEDIUM | 6.7 | 16%ile | Microsoft | 2023-04-11 |
| CVE-2023-28305 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.6 | 57%ile | Microsoft | 2023-04-11 |
| CVE-2023-28223 | Windows Domain Name Service Remote Code Execution Vulnerability | MEDIUM | 6.6 | 65%ile | Microsoft | 2023-04-11 |
| CVE-2023-28255 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.6 | 56%ile | Microsoft | 2023-04-11 |
| CVE-2023-28278 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.6 | 57%ile | Microsoft | 2023-04-11 |
| CVE-2023-28256 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.6 | 56%ile | Microsoft | 2023-04-11 |
| CVE-2023-28306 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.6 | 57%ile | Microsoft | 2023-04-11 |
| CVE-2023-28307 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.6 | 57%ile | Microsoft | 2023-04-11 |
| CVE-2023-28308 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.6 | 57%ile | Microsoft | 2023-04-11 |
| CVE-2020-27545 | libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line | MEDIUM | 6.5 | 56%ile | Microsoft | 2023-04-11 |
| CVE-2020-28163 | libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-t | MEDIUM | 6.5 | 55%ile | Microsoft | 2023-04-11 |
| CVE-2023-0614 | The fix in 4.6.16 4.7.9 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insuffi | MEDIUM | 6.5 | 46%ile | Microsoft | 2023-04-11 |
| CVE-2023-24626 | socket.c in GNU Screen through 4.9.0 when installed setuid or setgid (the default on platforms such as Arch Linux and Fr | MEDIUM | 6.5 | 44%ile | Microsoft | 2023-04-11 |
| CVE-2023-28484 | In libxml2 before 2.10.4 parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently | MEDIUM | 6.5 | 64%ile | Microsoft | 2023-04-11 |
| CVE-2023-28856 | `HINCRBYFLOAT` can be used to crash a redis-server process | MEDIUM | 6.5 | 68%ile | Microsoft | 2023-04-11 |
| CVE-2023-29469 | An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document xmlDictCompu | MEDIUM | 6.5 | 61%ile | Microsoft | 2023-04-11 |
| CVE-2023-30456 | An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency | MEDIUM | 6.5 | 40%ile | Microsoft | 2023-04-11 |
| CVE-2023-24883 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | MEDIUM | 6.5 | 72%ile | Microsoft | 2023-04-11 |
| CVE-2023-28267 | Remote Desktop Protocol Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 81%ile | Microsoft | 2023-04-11 |
| CVE-2023-28312 | Azure Machine Learning Information Disclosure Vulnerability | MEDIUM | 6.5 | 73%ile | Microsoft | 2023-04-11 |
| CVE-2023-30772 | The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c | MEDIUM | 6.4 | 40%ile | Microsoft | 2023-04-11 |
| CVE-2023-1855 | A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Ke | MEDIUM | 6.3 | 14%ile | Microsoft | 2023-04-11 |
| CVE-2023-25809 | CVE-2023-25809 | MEDIUM | 6.3 | 25%ile | Microsoft | 2023-04-11 |
| CVE-2023-29583 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note | MEDIUM | 6.2 | 22%ile | Microsoft | 2023-04-11 |
| CVE-2023-28269 | Windows Boot Manager Security Feature Bypass Vulnerability | MEDIUM | 6.2 | 48%ile | Microsoft | 2023-04-11 |
| CVE-2023-28249 | Windows Boot Manager Security Feature Bypass Vulnerability | MEDIUM | 6.2 | 46%ile | Microsoft | 2023-04-11 |
| CVE-2023-24934 | Microsoft Defender Security Feature Bypass Vulnerability | MEDIUM | 6.2 | 45%ile | Microsoft | 2023-04-11 |
| CVE-2023-1916 | A flaw was found in tiffcrop a program distributed by the libtiff package. A specially crafted tiff file can lead to an | MEDIUM | 6.1 | 30%ile | Microsoft | 2023-04-11 |
| CVE-2023-28313 | Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | MEDIUM | 6.1 | 51%ile | Microsoft | 2023-04-11 |
| CVE-2023-28314 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | MEDIUM | 6.1 | 51%ile | Microsoft | 2023-04-11 |
| CVE-2023-24935 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.1 | 60%ile | Microsoft | 2023-04-11 |
| CVE-2023-0922 | The Samba AD DC administration tool when operating against a remote LDAP server will by default send new or reset passwo | MEDIUM | 5.9 | 41%ile | Microsoft | 2023-04-11 |
| CVE-2022-46176 | CVE-2022-46176 | MEDIUM | 5.9 | 50%ile | Microsoft | 2023-04-11 |
| CVE-2023-1998 | Spectre v2 SMT mitigations problem in Linux kernel | MEDIUM | 5.6 | 71%ile | Microsoft | 2023-04-11 |
| CVE-2022-2084 | sensitive data exposure in cloud-init logs | MEDIUM | 5.5 | 15%ile | Microsoft | 2023-04-11 |
| CVE-2022-48468 | protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member. | MEDIUM | 5.5 | 31%ile | Microsoft | 2023-04-11 |
| CVE-2023-1786 | sensitive data exposure in cloud-init logs | MEDIUM | 5.5 | 19%ile | Microsoft | 2023-04-11 |
| CVE-2023-2162 | A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-componen | MEDIUM | 5.5 | 17%ile | Microsoft | 2023-04-11 |
| CVE-2023-2166 | A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may no | MEDIUM | 5.5 | 10%ile | Microsoft | 2023-04-11 |
| CVE-2023-2177 | A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If s | MEDIUM | 5.5 | 11%ile | Microsoft | 2023-04-11 |
| CVE-2023-2426 | Use of Out-of-range Pointer Offset in vim/vim | MEDIUM | 5.5 | 35%ile | Microsoft | 2023-04-11 |
| CVE-2023-28327 | A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Ke | MEDIUM | 5.5 | 9%ile | Microsoft | 2023-04-11 |
| CVE-2023-28328 | A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel | MEDIUM | 5.5 | 13%ile | Microsoft | 2023-04-11 |
| CVE-2023-31084 | An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation | MEDIUM | 5.5 | 35%ile | Microsoft | 2023-04-11 |
| CVE-2023-29580 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/e | MEDIUM | 5.5 | 24%ile | Microsoft | 2023-04-11 |
| CVE-2023-29582 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note | MEDIUM | 5.5 | 28%ile | Microsoft | 2023-04-11 |
| CVE-2023-29581 | yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: | MEDIUM | 5.5 | 28%ile | Microsoft | 2023-04-11 |
| CVE-2023-30402 | YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: Th | MEDIUM | 5.5 | 22%ile | Microsoft | 2023-04-11 |
| CVE-2023-28298 | Windows Kernel Denial of Service Vulnerability | MEDIUM | 5.5 | 46%ile | Microsoft | 2023-04-11 |
| CVE-2023-28228 | Windows Spoofing Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2023-04-11 |
| CVE-2023-28266 | Windows Common Log File System Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 91%ile | Microsoft | 2023-04-11 |
| CVE-2023-28271 | Windows Kernel Memory Information Disclosure Vulnerability | MEDIUM | 5.5 | 66%ile | Microsoft | 2023-04-11 |
| CVE-2023-28253 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 45%ile | Microsoft | 2023-04-11 |
| CVE-2023-28263 | Visual Studio Information Disclosure Vulnerability | MEDIUM | 5.5 | 45%ile | Microsoft | 2023-04-11 |
| CVE-2023-28299 | Visual Studio Spoofing Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2023-04-11 |
| CVE-2022-40133 | CVE-2022-40133 | MEDIUM | 5.5 | 48%ile | Microsoft | 2023-04-11 |
| CVE-2023-23006 | CVE-2023-23006 | MEDIUM | 5.5 | 17%ile | Microsoft | 2023-04-11 |
| CVE-2023-1355 | CVE-2023-1355 | MEDIUM | 5.5 | 39%ile | Microsoft | 2023-04-11 |
| CVE-2022-2869 | CVE-2022-2869 | MEDIUM | 5.5 | 25%ile | Microsoft | 2023-04-11 |
| CVE-2023-28425 | CVE-2023-28425 | MEDIUM | 5.5 | 99%ile | Microsoft | 2023-04-11 |
| CVE-2023-22997 | CVE-2023-22997 | MEDIUM | 5.5 | 19%ile | Microsoft | 2023-04-11 |
| CVE-2023-23005 | CVE-2023-23005 | MEDIUM | 5.5 | 19%ile | Microsoft | 2023-04-11 |
| CVE-2022-2867 | CVE-2022-2867 | MEDIUM | 5.5 | 25%ile | Microsoft | 2023-04-11 |
| CVE-2022-2868 | CVE-2022-2868 | MEDIUM | 5.5 | 25%ile | Microsoft | 2023-04-11 |
| CVE-2021-45985 | Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-read | MEDIUM | 5.5 | 72%ile | Microsoft | 2023-04-11 |
| CVE-2023-26916 | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at | MEDIUM | 5.3 | 61%ile | Microsoft | 2023-04-11 |
| CVE-2023-27043 | The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wron | MEDIUM | 5.3 | 84%ile | Microsoft | 2023-04-11 |
| CVE-2023-28226 | Windows Enroll Engine Security Feature Bypass Vulnerability | MEDIUM | 5.3 | 50%ile | Microsoft | 2023-04-11 |
| CVE-2023-28486 | CVE-2023-28486 | MEDIUM | 5.3 | 59%ile | Microsoft | 2023-04-11 |
| CVE-2023-28487 | CVE-2023-28487 | MEDIUM | 5.3 | 60%ile | Microsoft | 2023-04-11 |
| CVE-2023-21972 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte | MEDIUM | 4.9 | 65%ile | Microsoft | 2023-04-11 |
| CVE-2023-21976 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 65%ile | Microsoft | 2023-04-11 |
| CVE-2023-21977 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 65%ile | Microsoft | 2023-04-11 |
| CVE-2023-21982 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 65%ile | Microsoft | 2023-04-11 |
| CVE-2023-30612 | Malicious HTTP requests could close arbitrary opening file descriptors in cloud-hypervisor | MEDIUM | 4.9 | 30%ile | Microsoft | 2023-04-11 |
| CVE-2023-28277 | Windows DNS Server Information Disclosure Vulnerability | MEDIUM | 4.9 | 71%ile | Microsoft | 2023-04-11 |
| CVE-2023-0458 | Spectre V1 Gadget in do_prlimit in the Linux Kernel | MEDIUM | 4.7 | 52%ile | Microsoft | 2023-04-11 |
| CVE-2023-1382 | A data race flaw was found in the Linux kernel between where con is allocated and con->sock is set. This issue leads to | MEDIUM | 4.7 | 8%ile | Microsoft | 2023-04-11 |
| CVE-2023-1990 | A use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow a | MEDIUM | 4.7 | 14%ile | Microsoft | 2023-04-11 |
| CVE-2023-2019 | A flaw was found in the Linux kernel's netdevsim device driver within the scheduling of events. This issue results from | MEDIUM | 4.4 | 28%ile | Microsoft | 2023-04-11 |
| CVE-2023-28276 | Windows Group Policy Security Feature Bypass Vulnerability | MEDIUM | 4.4 | 39%ile | Microsoft | 2023-04-11 |
| CVE-2023-0225 | A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged use | MEDIUM | 4.3 | 52%ile | Microsoft | 2023-04-11 |
| CVE-2023-21729 | Remote Procedure Call Runtime Information Disclosure Vulnerability | MEDIUM | 4.3 | 70%ile | Microsoft | 2023-04-11 |
| CVE-2023-29334 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 64%ile | Microsoft | 2023-04-11 |
| CVE-2023-28301 | Microsoft Edge (Chromium-based) Tampering Vulnerability | LOW | 3.7 | 57%ile | Microsoft | 2023-04-11 |
| CVE-2023-29383 | In Shadow 4.13 it is possible to inject control characters into fields provided to the SUID program chfn (change finger) | LOW | 3.3 | 37%ile | Microsoft | 2023-04-11 |
| CVE-2023-1513 | CVE-2023-1513 | LOW | 3.3 | 14%ile | Microsoft | 2023-04-11 |
| CVE-2020-8908 | CVE-2020-8908 | LOW | 3.3 | 61%ile | Microsoft | 2023-04-11 |
| CVE-2023-29194 | vitess allows users to create keyspaces that can deny access to already existing keyspaces | LOW | 2.7 | 54%ile | Microsoft | 2023-04-11 |
| CVE-2023-1255 | Input buffer over-read in AES-XTS implementation on 64 bit ARM | UNKNOWN | — | 60%ile | Microsoft | 2023-04-11 |
| CVE-2023-2004 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu | UNKNOWN | — | — | Microsoft | 2023-04-11 |
| CVE-2023-2033 | Chromium: CVE-2023-2033 Type Confusion in V8 | UNKNOWN | — | 99%ile | Microsoft | 2023-04-11 |
| CVE-2023-2136 | Chromium: CVE-2023-2136 Integer overflow in Skia | UNKNOWN | — | 93%ile | Microsoft | 2023-04-11 |
| CVE-2023-1810 | Chromium: CVE-2023-1810 Heap buffer overflow in Visuals | UNKNOWN | — | 64%ile | Microsoft | 2023-04-11 |
| CVE-2023-1811 | Chromium: CVE-2023-1811 Use after free in Frames | UNKNOWN | — | 60%ile | Microsoft | 2023-04-11 |
| CVE-2023-1812 | Chromium: CVE-2023-1812 Out of bounds memory access in DOM Bindings | UNKNOWN | — | 59%ile | Microsoft | 2023-04-11 |
| CVE-2023-1813 | Chromium: CVE-2023-1813 Inappropriate implementation in Extensions | UNKNOWN | — | 52%ile | Microsoft | 2023-04-11 |
| CVE-2023-1814 | Chromium: CVE-2023-1814 Insufficient validation of untrusted input in Safe Browsing | UNKNOWN | — | 58%ile | Microsoft | 2023-04-11 |
| CVE-2023-1815 | Chromium: CVE-2023-1815 Use after free in Networking APIs | UNKNOWN | — | 58%ile | Microsoft | 2023-04-11 |
| CVE-2023-1816 | Chromium: CVE-2023-1816 Incorrect security UI in Picture In Picture | UNKNOWN | — | 56%ile | Microsoft | 2023-04-11 |
| CVE-2023-1817 | Chromium: CVE-2023-1817 Insufficient policy enforcement in Intents | UNKNOWN | — | 60%ile | Microsoft | 2023-04-11 |
| CVE-2023-1818 | Chromium: CVE-2023-1818 Use after free in Vulkan | UNKNOWN | — | 57%ile | Microsoft | 2023-04-11 |
| CVE-2023-1819 | Chromium: CVE-2023-1819 Out of bounds read in Accessibility | UNKNOWN | — | 58%ile | Microsoft | 2023-04-11 |
| CVE-2023-1820 | Chromium: CVE-2023-1820 Heap buffer overflow in Browser History | UNKNOWN | — | 60%ile | Microsoft | 2023-04-11 |
| CVE-2023-1821 | Chromium: CVE-2023-1821 Inappropriate implementation in WebShare | UNKNOWN | — | 56%ile | Microsoft | 2023-04-11 |
| CVE-2023-1822 | Chromium: CVE-2023-1822 Incorrect security UI in Navigation | UNKNOWN | — | 59%ile | Microsoft | 2023-04-11 |
| CVE-2023-1823 | Chromium: CVE-2023-1823 Inappropriate implementation in FedCM | UNKNOWN | — | 58%ile | Microsoft | 2023-04-11 |
| CVE-2023-2133 | Chromium: CVE-2023-2133 Out of bounds memory access in Service Worker API | UNKNOWN | — | 63%ile | Microsoft | 2023-04-11 |
| CVE-2023-2134 | Chromium: CVE-2023-2134 Out of bounds memory access in Service Worker API | UNKNOWN | — | 63%ile | Microsoft | 2023-04-11 |
| CVE-2023-2135 | Chromium: CVE-2023-2135 Use after free in DevTools | UNKNOWN | — | 61%ile | Microsoft | 2023-04-11 |
| CVE-2023-2137 | Chromium: CVE-2023-2137 Heap buffer overflow in sqlite | UNKNOWN | — | 65%ile | Microsoft | 2023-04-11 |
| CVE-2015-7504 | Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cau | HIGH | 8.8 | 49%ile | Microsoft | 2017-10-10 |
| CVE-2017-1000256 | libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvi | HIGH | 8.1 | 76%ile | Microsoft | 2017-10-10 |
| CVE-2017-11762 | Microsoft Graphics Remote Code Execution Vulnerability | HIGH | 8.1 | 97%ile | Microsoft | 2017-10-10 |
| CVE-2017-11763 | Microsoft Graphics Remote Code Execution Vulnerability | HIGH | 8.1 | 97%ile | Microsoft | 2017-10-10 |
| CVE-2017-11771 | Windows Search Remote Code Execution Vulnerability | HIGH | 8.1 | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-11779 | Windows DNSAPI Remote Code Execution Vulnerability | HIGH | 8.1 | 98%ile | Microsoft | 2017-10-10 |
| CVE-2017-11780 | Windows SMB Remote Code Execution Vulnerability | HIGH | 8.1 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2014-0047 | Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage. | HIGH | 7.8 | 33%ile | Microsoft | 2017-10-10 |
| CVE-2015-2158 | Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers t | HIGH | 7.8 | 86%ile | Microsoft | 2017-10-10 |
| CVE-2017-1000098 | The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size su | HIGH | 7.5 | 81%ile | Microsoft | 2017-10-10 |
| CVE-2017-1000118 | Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service | HIGH | 7.5 | 64%ile | Microsoft | 2017-10-10 |
| CVE-2017-11822 | Internet Explorer Memory Corruption Vulnerability | HIGH | 7.5 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-8727 | Internet Explorer Memory Corruption Vulnerability | HIGH | 7.5 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11782 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2017-10-10 |
| CVE-2017-11810 | Scripting Engine Memory Corruption Vulnerability | HIGH | 7.5 | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-11813 | Internet Explorer Memory Corruption Vulnerability | HIGH | 7.5 | 94%ile | Microsoft | 2017-10-10 |
| CVE-2017-11819 | Windows Shell Remote Code Execution Vulnerability | HIGH | 7.5 | 96%ile | Microsoft | 2017-10-10 |
| CVE-2017-1000097 | On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in | HIGH | 7.4 | 69%ile | Microsoft | 2017-10-10 |
| CVE-2017-12613 | When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Ru | HIGH | 7.1 | 77%ile | Microsoft | 2017-10-10 |
| CVE-2017-8717 | Microsoft JET Database Engine Remote Code Execution Vulnerability | HIGH | 7.1 | 98%ile | Microsoft | 2017-10-10 |
| CVE-2017-8718 | Microsoft JET Database Engine Remote Code Execution Vulnerability | HIGH | 7.1 | 98%ile | Microsoft | 2017-10-10 |
| CVE-2017-8689 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 65%ile | Microsoft | 2017-10-10 |
| CVE-2017-8694 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 65%ile | Microsoft | 2017-10-10 |
| CVE-2017-11783 | Windows ALPC Elevation of Privilege Vulnerability | HIGH | 7.0 | 84%ile | Microsoft | 2017-10-10 |
| CVE-2017-11824 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 67%ile | Microsoft | 2017-10-10 |
| CVE-2017-11815 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 6.4 | 96%ile | Microsoft | 2017-10-10 |
| CVE-2017-11823 | Device Guard Code Integrity Policy Security Feature Bypass Vulnerability | MEDIUM | 6.3 | 84%ile | Microsoft | 2017-10-10 |
| CVE-2017-15042 | An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x before 1.9.1. RFC 4954 requires that, during SMTP, the | MEDIUM | 5.9 | 64%ile | Microsoft | 2017-10-10 |
| CVE-2017-11772 | Microsoft Search Information Disclosure Vulnerability | MEDIUM | 5.9 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11781 | W - SMB - DOS Authenticated | MEDIUM | 5.9 | 96%ile | Microsoft | 2017-10-10 |
| CVE-2017-15370 | There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted i | MEDIUM | 5.5 | 76%ile | Microsoft | 2017-10-10 |
| CVE-2017-15371 | There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A | MEDIUM | 5.5 | 75%ile | Microsoft | 2017-10-10 |
| CVE-2017-8693 | Microsoft Graphics Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 83%ile | Microsoft | 2017-10-10 |
| CVE-2017-11765 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 83%ile | Microsoft | 2017-10-10 |
| CVE-2017-11814 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 83%ile | Microsoft | 2017-10-10 |
| CVE-2017-11816 | Windows GDI Information Disclosure Vulnerability | MEDIUM | 5.5 | 97%ile | Microsoft | 2017-10-10 |
| CVE-2017-11829 | Windows Update Delivery Optimization Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 90%ile | Microsoft | 2017-10-10 |
| CVE-2017-8715 | Device Guard Code Integrity Policy Security Feature Bypass Vulnerability | MEDIUM | 5.3 | 76%ile | Microsoft | 2017-10-10 |
| CVE-2017-8703 | Windows Subsystem for Linux Denial of Service Vulnerability | MEDIUM | 5.0 | 76%ile | Microsoft | 2017-10-10 |
| CVE-2017-11784 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 4.7 | 83%ile | Microsoft | 2017-10-10 |
| CVE-2017-11785 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 4.7 | 87%ile | Microsoft | 2017-10-10 |
| CVE-2017-11817 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 4.7 | 81%ile | Microsoft | 2017-10-10 |
| CVE-2017-11818 | Windows Storage Security Feature Bypass Vulnerability | MEDIUM | 4.5 | 66%ile | Microsoft | 2017-10-10 |
| CVE-2017-8726 | Microsoft Edge based on Edge HTML Information Disclosure Vulnerability | MEDIUM | 4.3 | 94%ile | Microsoft | 2017-10-10 |
| CVE-2017-11794 | Microsoft Edge based on Edge HTML Information Disclosure Vulnerability | MEDIUM | 4.3 | 92%ile | Microsoft | 2017-10-10 |
| CVE-2017-11821 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11769 | TRIE Remote Code Execution Vulnerability | MEDIUM | 4.2 | 97%ile | Microsoft | 2017-10-10 |
| CVE-2017-11792 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11793 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-11796 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11797 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 93%ile | Microsoft | 2017-10-10 |
| CVE-2017-11798 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11799 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-11800 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11801 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 93%ile | Microsoft | 2017-10-10 |
| CVE-2017-11802 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-11804 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11805 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11806 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11807 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11808 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11809 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-11811 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-11812 | Scripting Engine Memory Corruption Vulnerability | MEDIUM | 4.2 | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-13080 | Windows Wireless WPA Group Key Reinstallation Vulnerability | MEDIUM | 4.2 | 82%ile | Microsoft | 2017-10-10 |
| CVE-2017-11790 | Internet Explorer Information Disclosure Vulnerability | LOW | 3.1 | 92%ile | Microsoft | 2017-10-10 |
| CVE-2017-11786 | Skype for Business Elevation of Privilege Vulnerability | UNKNOWN | — | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11774 | Microsoft Outlook Security Feature Bypass Vulnerability | UNKNOWN | — | 99%ile | Microsoft | 2017-10-10 |
| CVE-2017-11775 | Microsoft SharePoint Elevation of Privilege Vulnerability | UNKNOWN | — | 82%ile | Microsoft | 2017-10-10 |
| CVE-2017-11776 | Microsoft Outlook Information Disclosure Vulnerability | UNKNOWN | — | 95%ile | Microsoft | 2017-10-10 |
| CVE-2017-11777 | Microsoft SharePoint Elevation of Privilege Vulnerability | UNKNOWN | — | 82%ile | Microsoft | 2017-10-10 |
| CVE-2017-11820 | Microsoft SharePoint Elevation of Privilege Vulnerability | UNKNOWN | — | 82%ile | Microsoft | 2017-10-10 |
| CVE-2017-11825 | Microsoft Office Remote Code Execution Vulnerability | UNKNOWN | — | 98%ile | Microsoft | 2017-10-10 |
| CVE-2017-11826 | Microsoft Office Remote Code Execution Vulnerability | UNKNOWN | — | 100%ile | Microsoft | 2017-10-10 |