7002 entries matching microsoft — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-62870 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | HIGH | 8.8 | 54%ile | NVD | 2026-08-04 |
| CVE-2026-66318 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over | HIGH | 8.1 | 30%ile | NVD | 2026-08-04 |
| CVE-2026-66310 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat | HIGH | 7.7 | 33%ile | NVD | 2026-08-04 |
| CVE-2026-66315 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | HIGH | 7.5 | 46%ile | NVD | 2026-08-04 |
| CVE-2026-65802 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat | HIGH | 7.4 | 58%ile | NVD | 2026-08-04 |
| CVE-2026-66321 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized | HIGH | 7.4 | 58%ile | NVD | 2026-08-04 |
| CVE-2026-66322 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne | HIGH | 7.1 | 18%ile | NVD | 2026-08-04 |
| CVE-2026-66313 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | MEDIUM | 6.8 | 15%ile | NVD | 2026-08-04 |
| CVE-2026-66312 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | MEDIUM | 6.5 | 59%ile | NVD | 2026-08-04 |
| CVE-2026-66314 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to | MEDIUM | 6.5 | 50%ile | NVD | 2026-08-04 |
| CVE-2026-66326 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | MEDIUM | 6.5 | 48%ile | NVD | 2026-08-04 |
| CVE-2026-66311 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | MEDIUM | 6.2 | 34%ile | NVD | 2026-08-04 |
| CVE-2026-65804 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized atta | MEDIUM | 6.1 | 35%ile | NVD | 2026-08-04 |
| CVE-2026-66325 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin | MEDIUM | 6.1 | 33%ile | NVD | 2026-08-04 |
| CVE-2026-66316 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne | MEDIUM | 5.4 | 12%ile | NVD | 2026-08-04 |
| CVE-2026-66317 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n | MEDIUM | 5.4 | 12%ile | NVD | 2026-08-04 |
| CVE-2026-18215 | Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization | MEDIUM | 6.8 | 9%ile | NVD | 2026-07-31 |
| CVE-2026-17691 | Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially | CRITICAL | 9.6 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-17692 | Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had comp | CRITICAL | 9.6 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-17862 | Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-leve | HIGH | 7.8 | 2%ile | NVD | 2026-07-30 |
| CVE-2026-17863 | Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to p | HIGH | 7.8 | 1%ile | NVD | 2026-07-30 |
| CVE-2026-17811 | Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perf | HIGH | 7.1 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-15929 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics Sma | HIGH | 7.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-17707 | Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromi | MEDIUM | 6.5 | 31%ile | NVD | 2026-07-30 |
| CVE-2026-17846 | Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who h | MEDIUM | 6.5 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-17992 | Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potenti | MEDIUM | 6.5 | 18%ile | NVD | 2026-07-30 |
| CVE-2026-17908 | Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remo | MEDIUM | 5.8 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-17932 | Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain pot | MEDIUM | 5.5 | 1%ile | NVD | 2026-07-30 |
| CVE-2026-17790 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potent | MEDIUM | 4.3 | 18%ile | NVD | 2026-07-30 |
| CVE-2026-17858 | Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-or | MEDIUM | 4.3 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-17900 | Inappropriate implementation in Enterprise in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 4.3 | 5%ile | NVD | 2026-07-30 |
| CVE-2026-18018 | Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to p | MEDIUM | 4.0 | 0%ile | NVD | 2026-07-30 |
| CVE-2026-32203 | Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability | HIGH | 7.5 | 78%ile | GitHub | 2026-07-28 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-45499 | Azure OpenAI Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-57100 | Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-54120 | Microsoft Surface Remote Code Execution Vulnerability | CRITICAL | 9.9 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-57092 | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 65%ile | Microsoft | 2026-07-14 |
| CVE-2026-50517 | Microsoft M365 Copilot Remote Code Execution Vulnerability | CRITICAL | 9.9 | 66%ile | Microsoft | 2026-07-14 |
| CVE-2026-56165 | Microsoft Account Remote Code Execution Vulnerability | CRITICAL | 9.8 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-42990 | SQL Server ODBC driver Elevation of Privilege Vulnerability | CRITICAL | 9.8 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-49172 | Windows FTP Service Remote Code Execution Vulnerability | CRITICAL | 9.8 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-54990 | Remote Desktop Client Remote Code Execution Vulnerability | CRITICAL | 9.8 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100%ile | Microsoft | 2026-07-14 |
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 93%ile | Microsoft | 2026-07-14 |
| CVE-2026-50447 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-50518 | Windows DHCP Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 96%ile | Microsoft | 2026-07-14 |
| CVE-2026-55010 | Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-55944 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 67%ile | Microsoft | 2026-07-14 |
| CVE-2026-56159 | DHCP Server Service Remote Code Execution Vulnerability | CRITICAL | 9.8 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-56190 | Remote Desktop Protocol Remote Code Execution Vulnerability | CRITICAL | 9.8 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-56188 | Windows Server Network driver Remote Code Execution Vulnerability | CRITICAL | 9.8 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-38968 | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ide | CRITICAL | 9.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-53386 | iio: adc: ti-ads1298: add bounds check to pga_settings index | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53374 | drm/amdgpu: zero-initialize GART table on allocation | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53376 | drm/amdkfd: Add upper bound check for num_of_nodes | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63833 | ntfs3: reject direct userspace writes to reserved $LX* xattrs | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63822 | wifi: ath11k: fix warning when unbinding | CRITICAL | 9.8 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63828 | apparmor: mediate the implicit connect of TCP fast open sendmsg | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63882 | drm/amdkfd: fix NULL pointer bug in svm_range_set_attr | CRITICAL | 9.8 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64017 | blk-mq: pop cached request if it is usable | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-57433 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record | CRITICAL | 9.8 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15043 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text | CRITICAL | 9.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-63816 | f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53403 | fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63818 | f2fs: validate orphan inode entry count | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53387 | iio: light: veml6075: add bounds check to veml6075_it_ms index | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53384 | serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails | CRITICAL | 9.8 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-63824 | KEYS: fix overflow in keyctl_pkey_params_get_2() | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63800 | pNFS: Fix use-after-free in pnfs_update_layout() | CRITICAL | 9.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-63797 | rpmsg: char: Fix use-after-free on probe error path | CRITICAL | 9.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-63814 | f2fs: validate ACL entry sizes in f2fs_acl_from_disk() | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63827 | apparmor: fix use-after-free in rawdata dedup loop | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64079 | netfilter: x_tables: allocate hook ops while under mutex | CRITICAL | 9.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64138 | ksmbd: validate SID in parent security descriptor during ACL inheritance | CRITICAL | 9.8 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-63959 | usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT | CRITICAL | 9.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-64070 | powerpc/hv-gpci: fix preempt count leak in sysfs show paths | CRITICAL | 9.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-63958 | usb: typec: ucsi: validate connector number in ucsi_connector_change() | CRITICAL | 9.8 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64078 | netfilter: x_tables: add and use xtables_unregister_table_exit | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63983 | net/sched: fix packet loop on netem when duplicate is on | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-63881 | drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger | CRITICAL | 9.8 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64111 | lsm: hold cred_guard_mutex for lsm_set_self_attr() | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64076 | netfilter: bridge: eb_tables: close module init race | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63979 | net/handshake: hand off the pinned file reference to accept_doit | CRITICAL | 9.8 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-63999 | ethtool: rss: fix indir_table and hkey leak on get_rxfh failure | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-63974 | Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close | CRITICAL | 9.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-55008 | Microsoft Exchange Server Spoofing Vulnerability | CRITICAL | 9.6 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-50380 | Windows GDI+ Remote Code Execution Vulnerability | CRITICAL | 9.6 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-41106 | Microsoft 365 Copilot Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-49798 | Windows Kernel Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 82%ile | Microsoft | 2026-07-14 |
| CVE-2026-62835 | Azure Portal Information Disclosure Vulnerability | CRITICAL | 9.3 | 59%ile | Microsoft | 2026-07-14 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | CRITICAL | 9.1 | 74%ile | Microsoft | 2026-07-14 |
| CVE-2026-9547 | SSH improper host validation | CRITICAL | 9.1 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-8924 | trailing dot domain super cookie | CRITICAL | 9.1 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-8926 | password leak with netrc and user in URL | CRITICAL | 9.1 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-14740 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment | CRITICAL | 9.1 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-60082 | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row | CRITICAL | 9.1 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-64319 | nvmet-auth: validate reply message payload bounds against transfer length | CRITICAL | 9.1 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-58289 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | CRITICAL | 9.0 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-54998 | Microsoft Exchange Online Elevation of Privilege Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-47300 | ASP.NET Core Elevation of Privilege Vulnerability | HIGH | 8.8 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-47303 | ASP.NET Core Elevation of Privilege Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-50663 | Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability | HIGH | 8.8 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-54107 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-54982 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | HIGH | 8.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-54999 | Windows TCP/IP Remote Code Execution Vulnerability | HIGH | 8.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-55005 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-54117 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 67%ile | Microsoft | 2026-07-14 |
| CVE-2026-54118 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 67%ile | Microsoft | 2026-07-14 |
| CVE-2026-55002 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-57969 | Azure CycleCloud Elevation of Privilege Vulnerability | HIGH | 8.8 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-57981 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-56645 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-58608 | Windows Print Spooler Remote Code Execution Vulnerability | HIGH | 8.8 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-47301 | Configuration Manager Elevation of Privilege Vulnerability | HIGH | 8.8 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-47632 | Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-48564 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-49178 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-49795 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 78%ile | Microsoft | 2026-07-14 |
| CVE-2026-50342 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 8.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50360 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50370 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 8.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50398 | Windows Media Elevation of Privilege Vulnerability | HIGH | 8.8 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-50382 | DirectX Graphics Kernel Remote Code Execution Vulnerability | HIGH | 8.8 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50369 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 8.8 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-50385 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 8.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-50413 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 8.8 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-50438 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 8.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50474 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-50444 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-50477 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-50489 | Win32k Elevation of Privilege Vulnerability | HIGH | 8.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-47295 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-50666 | Windows Remote Access Elevation of Privilege Vulnerability | HIGH | 8.8 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-50670 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-54121 | Active Directory Certificate Services Elevation of Privilege Vulnerability | HIGH | 8.8 | 61%ile | Microsoft | 2026-07-14 |
| CVE-2026-50687 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-50692 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-55052 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-41109 | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-56196 | Windows Admin Center (WAC) Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-56197 | Windows Admin Center (WAC) Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-56642 | Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-56194 | Windows NFS Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-56647 | Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-57090 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-57094 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-57087 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-57102 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-57974 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-58277 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-58534 | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-58594 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-58626 | Windows Remote Desktop Services Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-14380 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile | HIGH | 8.8 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-58253 | NATS Server: Route API Auth Bypass | HIGH | 8.8 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-66032 | libssh2 Double-Free Heap Corruption via sftp_open() | HIGH | 8.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-64475 | vfio/pci: Release the VGA arbiter client on register_device() failure | HIGH | 8.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-63807 | KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level | HIGH | 8.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-57983 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | HIGH | 8.7 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-14739 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho | HIGH | 8.6 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13321 | DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field | HIGH | 8.6 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-56167 | Azure AI Search Elevation of Privilege Vulnerability | HIGH | 8.5 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-50340 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 8.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-56002 | libXfont2 PCF Font Parsing Heap Buffer Overflow | HIGH | 8.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-53366 | ipv4: account for fraggap on the paged allocation path | HIGH | 8.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-56001 | libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow | HIGH | 8.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-56003 | libXfont2 computeProps Property Buffer Heap Buffer Overflow | HIGH | 8.5 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55999 | xorg-server / xwayland glamor font atlas Heap Buffer Overflow | HIGH | 8.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-54992 | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability | HIGH | 8.4 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-54122 | Windows GDI+ Remote Code Execution Vulnerability | HIGH | 8.4 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50520 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 8.4 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-49184 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 8.4 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-54128 | Windows DHCP Client Remote Code Execution Vulnerability | HIGH | 8.4 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-55045 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-63803 | hdlc_ppp: sync per-proto timers before freeing hdlc state | HIGH | 8.4 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64254 | NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR | HIGH | 8.4 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64252 | MIPS: DEC: Prevent initial console buffer from landing in XKPHYS | HIGH | 8.4 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64456 | hwrng: virtio: clamp device-reported used.len at copy_data() | HIGH | 8.4 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64513 | KVM: x86: Unconditionally recompute CR8 intercept on PPR update | HIGH | 8.4 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63823 | keys: Pin request_key_auth payload in instantiate paths | HIGH | 8.4 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64249 | fpga: region: fix use-after-free in child_regions_with_firmware() | HIGH | 8.4 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64246 | power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() | HIGH | 8.4 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64320 | nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page | HIGH | 8.4 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-58281 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-58284 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-58285 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-58287 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-58288 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-58295 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | HIGH | 8.3 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-58596 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | HIGH | 8.3 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-56181 | Windows Network Address Translation (NAT) Spoofing Vulnerability | HIGH | 8.3 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50338 | Azure Spring Apps Elevation of Privilege Vulnerability | HIGH | 8.2 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50429 | Windows Kernel Information Disclosure Vulnerability | HIGH | 8.2 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50528 | .NET Security Feature Bypass Vulnerability | HIGH | 8.2 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-50680 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 8.2 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58525 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | HIGH | 8.2 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-63829 | net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink | HIGH | 8.2 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-60005 | NGINX ngx_http_slice_module vulnerability | HIGH | 8.2 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-64380 | smb: client: harden POSIX SID length parsing | HIGH | 8.2 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-42900 | Microsoft Windows App Store Elevation of Privilege Vulnerability | HIGH | 8.1 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-49164 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.1 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-54995 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | HIGH | 8.1 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-56169 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 8.1 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50694 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | HIGH | 8.1 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-58595 | Microsoft Bing App for IOS Spoofing Vulnerability | HIGH | 8.1 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-47304 | .NET Security Feature Bypass Vulnerability | HIGH | 8.1 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50460 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 8.1 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50439 | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability | HIGH | 8.1 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50487 | Windows DNS Client Elevation of Privilege Vulnerability | HIGH | 8.1 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-50686 | Windows OLE Remote Code Execution Vulnerability | HIGH | 8.1 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-56186 | Windows Secure Channel Information Disclosure Vulnerability | HIGH | 8.1 | 61%ile | Microsoft | 2026-07-14 |
| CVE-2026-58282 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 8.1 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-58283 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 8.1 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58286 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 8.1 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-58293 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.1 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-58617 | M365 Copilot for iOS Elevation of Privilege Vulnerability | HIGH | 8.1 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-50721 | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload | HIGH | 8.1 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-50722 | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload | HIGH | 8.1 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-8286 | wrong STARTTLS connection reuse | HIGH | 8.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-42533 | NGINX Map directive and Regex matching vulnerability | HIGH | 8.1 | 88%ile | Microsoft | 2026-07-14 |
| CVE-2026-53381 | virtiofs: fix UAF on submount umount | HIGH | 8.1 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64442 | staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() | HIGH | 8.1 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-64448 | smb: client: restrict implied bcc[0] exemption to responses without data area | HIGH | 8.1 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-42975 | Windows Bluetooth Port Driver Remote Code Execution | HIGH | 8.0 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-49169 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 8.0 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-58647 | Microsoft PowerBI Report Server Spoofing Vulnerability | HIGH | 8.0 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-40400 | Windows PowerShell Remote Code Execution Vulnerability | HIGH | 8.0 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-50365 | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | HIGH | 8.0 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50502 | Windows Event Logging Service Remote Code Execution Vulnerability | HIGH | 8.0 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-50683 | Windows DHCP Client Elevation of Privilege Vulnerability | HIGH | 8.0 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-35425 | Azure API Management (APIM) Remote Code Execution Vulnerability | HIGH | 8.0 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64600 | xfs: resample the data fork mapping after cycling ILOCK | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-42982 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-49166 | Windows Print Configuration Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-49170 | Windows StateRepository API Server file Elevation of Privilege Vulnerability | HIGH | 7.8 | 85%ile | Microsoft | 2026-07-14 |
| CVE-2026-49176 | Windows WalletService Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-49175 | Windows DNS Client Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-49173 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-54987 | Windows Overlay Filter Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50697 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-54991 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-54986 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-07-14 |
| CVE-2026-54993 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-55001 | Active Directory Domain Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-54112 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-55004 | Windows Print Configuration Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-54109 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-54114 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-07-14 |
| CVE-2026-55006 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-55009 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 74%ile | Microsoft | 2026-07-14 |
| CVE-2026-55011 | Microsoft Defender Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55012 | Microsoft Defender Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-50675 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-55899 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55948 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 82%ile | Microsoft | 2026-07-14 |
| CVE-2026-57107 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-55014 | Windows Remote Help Defense Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-58601 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | HIGH | 7.8 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-58602 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-58609 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-58610 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-58618 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-58631 | Windows Admin Center (WAC) Remote Code Execution Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-58635 | Windows Narrator Braille Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-58636 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-44800 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-48581 | Surface Broker SDMA Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-49783 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-49792 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-49793 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-49796 | Windows GDI+ Remote Code Execution Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-49797 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-49800 | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability | HIGH | 7.8 | 80%ile | Microsoft | 2026-07-14 |
| CVE-2026-50308 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-50311 | Windows Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50333 | Windows Spaceport.sys Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50318 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-50351 | Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability | HIGH | 7.8 | 85%ile | Microsoft | 2026-07-14 |
| CVE-2026-49808 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50293 | Windows Internal Task Bar Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-50332 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50305 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-50329 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-07-14 |
| CVE-2026-50363 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50306 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50412 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50337 | Windows Notification Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50386 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50400 | Windows App Package Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50309 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50326 | Windows Unified Consent System Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50313 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-50440 | Windows Audio Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50327 | Windows Media Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50407 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50331 | Windows Application Model Core API Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50343 | Microsoft Install Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2026-07-14 |
| CVE-2026-50347 | Windows Data.dll Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-50321 | Windows USB Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50425 | Windows Internal System User Profile Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50315 | Windows Image Acquisition Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50357 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50335 | Windows Operating Systems Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50361 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-50317 | Windows Operating Systems Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50373 | Windows Search Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50353 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50388 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-50336 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50433 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-07-14 |
| CVE-2026-50391 | Windows Group Policy Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50423 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 84%ile | Microsoft | 2026-07-14 |
| CVE-2026-50378 | Windows Key Guard Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50346 | Netlogon RPC Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50405 | Windows Filtering Platform Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50448 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50387 | Windows GDI Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-07-14 |
| CVE-2026-50344 | Windows OLE Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50436 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 76%ile | Microsoft | 2026-07-14 |
| CVE-2026-50471 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50469 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-50454 | Windows User Interface Core Elevation of Privilege Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-50427 | Content Delivery Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-50422 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50421 | Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50367 | Windows Sensor Data Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50466 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50402 | NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50435 | Windows Overlay Filter Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50441 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50462 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-50457 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-50399 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50461 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50417 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50362 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50458 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-50476 | Windows Network Connections Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 74%ile | Microsoft | 2026-07-14 |
| CVE-2026-50450 | Windows Network Connections Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50478 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-50479 | Windows USB Hub Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50480 | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50484 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-50486 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50488 | Clipboard User Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-50499 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50494 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50498 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50501 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50509 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | HIGH | 7.8 | 87%ile | Microsoft | 2026-07-14 |
| CVE-2026-50510 | GitHub Copilot Remote Code Execution Vulnerability | HIGH | 7.8 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-50646 | .NET Framework Remote Code Execution Vulnerability | HIGH | 7.8 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-50649 | .NET Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-50650 | .NET Framework Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50655 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50667 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 79%ile | Microsoft | 2026-07-14 |
| CVE-2026-50673 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50676 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50677 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-54115 | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50679 | Windows Search Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50688 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 75%ile | Microsoft | 2026-07-14 |
| CVE-2026-50689 | Windows Clipboard Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-54125 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-47290 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-47642 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-50301 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50314 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-50467 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55017 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55024 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-55018 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55022 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55025 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55125 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55031 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-55048 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55029 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55039 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55049 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55032 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55033 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-55041 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55127 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-55136 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55141 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55129 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55036 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55044 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55055 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55037 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55058 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55038 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-55132 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-55137 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55053 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55131 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55134 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55056 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55140 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55128 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55130 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-55043 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55133 | Microsoft OneNote Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55123 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55120 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-54131 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55947 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55949 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-56156 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-56176 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-56175 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-56182 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-56189 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-50665 | Microsoft Office Information Disclosure Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-56643 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-56644 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-54124 | Windows Terminal Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-56650 | Windows Network File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-57091 | Windows File History Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-57088 | Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-57096 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-57968 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-58527 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-58530 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-58538 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-58540 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-58532 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-58537 | Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-58536 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-07-14 |
| CVE-2026-58542 | Windows Media Remote Code Execution Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58541 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-47305 | Visual Studio Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-58613 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-58628 | Windows Wireless Network Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-58632 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-58633 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-58634 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-59856 | Vim: Arbitrary Code Execution via PHP Omni-Completion | HIGH | 7.8 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-39822 | Root escape via symlink plus trailing slash in os | HIGH | 7.8 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-3842 | Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64192 | bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-16493 | Ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332) | HIGH | 7.8 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-64402 | coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64313 | crypto: ecc - Fix carry overflow in vli multiplication | HIGH | 7.8 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-64455 | USB: chaoskey: Fix slab-use-after-free in chaoskey_release() | HIGH | 7.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64382 | smb: client: fix double-free in SMB2_open() replay | HIGH | 7.8 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-64298 | NFSv4: include MAY_WRITE in open permission mask for O_TRUNC | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64463 | usb: typec: tcpci_rt1711h: unregister TCPCI port with devres | HIGH | 7.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64423 | ipv4: igmp: remove multicast group from hash table on device destruction | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64340 | USB: legousbtower: fix use-after-free on disconnect race | HIGH | 7.8 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64358 | media: mtk-jpeg: cancel workqueue on release for supported platforms only | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64341 | USB: iowarrior: fix use-after-free on disconnect race | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64446 | staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() | HIGH | 7.8 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-64504 | iio: accel: bmc150: clamp the device-reported FIFO frame count | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64304 | crypto: qat - validate RSA CRT component lengths | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64483 | ALSA: firewire: isight: bound the sample count to the packet payload | HIGH | 7.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64449 | staging: vme_user: bound slave read/write to the kern_buf size | HIGH | 7.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64508 | bpf: Support for hardening against JIT spraying | HIGH | 7.8 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64391 | ksmbd: use opener credentials for ADS I/O | HIGH | 7.8 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-64481 | ALSA: hda/cs35l41: Fix firmware load work teardown | HIGH | 7.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14191 | WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader | HIGH | 7.8 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-63853 | drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-63858 | netfilter: nf_tables: add hook transactions for device deletions | HIGH | 7.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-63832 | wifi: mt76: add wcid publish check in mt76_sta_add | HIGH | 7.8 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-53388 | fuse: re-lock request before replacing page cache folio | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63794 | KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path | HIGH | 7.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-63804 | gfs2: fix use-after-free in gfs2_qd_dealloc | HIGH | 7.8 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-63831 | mac802154: llsec: add skb_cow_data() before in-place crypto | HIGH | 7.8 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-63802 | blk-cgroup: fix UAF in __blkcg_rstat_flush() | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64191 | i2c: stub: Reject I2C block transfers with invalid length | HIGH | 7.8 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64344 | USB: idmouse: fix use-after-free on disconnect race | HIGH | 7.8 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64266 | fuse: re-lock request before returning from fuse_ref_folio() | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64305 | crypto: qat - protect service table iterations with service_lock | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64343 | USB: ldusb: fix use-after-free on disconnect race | HIGH | 7.8 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64437 | ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL | HIGH | 7.8 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-64389 | ksmbd: validate NTLMv2 response before updating session key | HIGH | 7.8 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-64342 | USB: iowarrior: fix use-after-free on disconnect | HIGH | 7.8 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64393 | ksmbd: run set info with opener credentials | HIGH | 7.8 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64322 | udf: validate sparing table length as an entry count, not a byte count | HIGH | 7.8 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64274 | Input: goodix - clamp the device-reported contact count | HIGH | 7.8 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-50493 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-60002 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This | HIGH | 7.7 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-58207 | NATS Server: Remote crash via integer overflow in Connz pagination | HIGH | 7.7 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-63940 | KVM: SEV: Ignore Port I/O requests of length '0' | HIGH | 7.7 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-15392 | DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location | HIGH | 7.7 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-57985 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.6 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-47296 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-59117 | Windows Terminal Remote Code Execution Vulnerability | HIGH | 7.5 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-47302 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-49171 | Windows Speech Runtime Elevation of Privilege Vulnerability | HIGH | 7.5 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50506 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-54983 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50695 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-50696 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-54119 | Windows Active Directory Denial of Service Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50524 | .NET Framework Denial of Service Vulnerability | HIGH | 7.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-56170 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 60%ile | Microsoft | 2026-07-14 |
| CVE-2026-57984 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-57986 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-57992 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-58276 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-50652 | Azure Active Directory Denial of Service Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-07-14 |
| CVE-2026-50653 | Azure Active Directory Denial of Service Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-40378 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-45646 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-49181 | Windows DHCP Client Elevation of Privilege Vulnerability | HIGH | 7.5 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-49787 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-49788 | HTTP/2 Denial of Service Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50304 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-50328 | Windows Server Update Service (WSUS) Tampering Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-07-14 |
| CVE-2026-50368 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50330 | Windows Remote Desktop Client Elevation of Privilege Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-07-14 |
| CVE-2026-50355 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-50414 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50379 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.5 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-50463 | Windows Kernel Information Disclosure Vulnerability | HIGH | 7.5 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-50411 | Windows Active Directory Federation Services Denial of Service Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50424 | Windows Domain Controller Denial of Service Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50470 | Windows Network Policy Server SNMP Information Disclosure Vulnerability | HIGH | 7.5 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-50500 | Windows Netlogon Elevation of Privilege Vulnerability | HIGH | 7.5 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-50505 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-50496 | Windows Network Policy Server SNMP Information Disclosure Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-07-14 |
| CVE-2026-50525 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-50527 | .NET Framework Denial of Service Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50647 | Active Directory Federation Server Denial of Service Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-07-14 |
| CVE-2026-50648 | .NET Framework Denial of Service Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50651 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50685 | Windows DHCP Server Remote Code Execution Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-56648 | Windows NFS Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-57089 | Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-57108 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-07-14 |
| CVE-2026-57975 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-58290 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-58292 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-58294 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58299 | Microsoft Edge for Android Remote Code Execution Vulnerability | HIGH | 7.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-58531 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 7.5 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-58627 | Windows DHCP Server Denial of Service Vulnerability | HIGH | 7.5 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-9545 | exposing HTTP/3 early data | HIGH | 7.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-12413 | IKEv2 Denial of Service via malformed fragmentation | HIGH | 7.5 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-8932 | incomplete mTLS config matching in conn reuse | HIGH | 7.5 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-38969 | ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smugg | HIGH | 7.5 | — | Microsoft | 2026-07-14 |
| CVE-2026-20214 | ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability | HIGH | 7.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-20215 | ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-20216 | ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-20217 | ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-20244 | ClamAV DMG File Processing Denial of Service Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-59925 | inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-57432 | Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack | HIGH | 7.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-57219 | RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth | HIGH | 7.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-48863 | Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service | HIGH | 7.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-60081 | DBI::ProfileData versions before 1.651 for Perl do not limit the path index | HIGH | 7.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-59884 | pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs | HIGH | 7.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-59886 | pyasn1: Uncontrolled resource consumption when converting decoded REAL values | HIGH | 7.5 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-62309 | CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS | HIGH | 7.5 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-38754 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv | HIGH | 7.5 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-53375 | drm/amdgpu/vce: Prevent partial address patches | HIGH | 7.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-63836 | batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd | HIGH | 7.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-55973 | 'dns-error-reporting: yes' leads to stack buffer overflow | HIGH | 7.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-40691 | Packet of death for DNSCrypt over TCP | HIGH | 7.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-32665 | Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass | HIGH | 7.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-56852 | Infinite loop on invalid input in golang.org/x/text | HIGH | 7.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-13204 | Unexpected exit in certain situations with NSEC and NSEC3 both present | HIGH | 7.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-11605 | Unnecessary validation of DNSSEC signed records | HIGH | 7.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-11331 | Potential wildcard CNAME RPZ policy bypass | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-11721 | Cache poisoning possible with label count discrepancy, RRSIG, and wildcards | HIGH | 7.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-12617 | Record ordering based unexpected exit with CNAME or DNAME | HIGH | 7.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-46600 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | HIGH | 7.5 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-66034 | libssh2 Heap Out-of-Bounds Read via publickey subsystem | HIGH | 7.5 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-64383 | smb: client: fix double-free in SMB2_flush() replay | HIGH | 7.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-12064 | proto-default skips SSH verification | HIGH | 7.5 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-20213 | ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability | HIGH | 7.5 | 44%ile | Microsoft | 2026-07-14 |
| CVE-2026-20243 | ClamAV ALZ Archive Processing Denial of Service Vulnerability | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-59928 | Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-59922 | Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-59869 | js-yaml: YAML merge-key chains can force quadratic CPU consumption | HIGH | 7.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-58250 | NATS Server: Pre-auth server crash via double INFO in leafnode handshake | HIGH | 7.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-15308 | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations | HIGH | 7.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-59873 | node-tar: Decompression/parse DoS via unlimited input | HIGH | 7.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-59874 | node-tar: Negative tar entry size causes infinite loop in archive replace | HIGH | 7.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-57220 | RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-ex | HIGH | 7.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-15711 | Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol viola | HIGH | 7.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-15709 | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of s | HIGH | 7.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-59885 | pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service | HIGH | 7.5 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-38755 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser | HIGH | 7.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-62389 | ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS | HIGH | 7.5 | — | Microsoft | 2026-07-14 |
| CVE-2026-63793 | ntfs: serialize volume label accesses | HIGH | 7.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53400 | i2c: core: fix adapter registration race | HIGH | 7.5 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-63872 | esp: fix page frag reference leak on skb_to_sgvec failure | HIGH | 7.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-44690 | Cross-zone wildcard cache poisoning via RRSIG.labels manipulation | HIGH | 7.5 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-11622 | Potential memory usage beyond configured limits | HIGH | 7.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-47063 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE | HIGH | 7.5 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-66035 | libssh2 Heap Buffer Overflow via ETM Cipher Negotiation | HIGH | 7.5 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-66033 | libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation | HIGH | 7.5 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-66373 | Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio | HIGH | 7.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-54127 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.4 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-57991 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 51%ile | Microsoft | 2026-07-14 |
| CVE-2026-57990 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 57%ile | Microsoft | 2026-07-14 |
| CVE-2026-57993 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 7.4 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-57989 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-64112 | rbd: eliminate a race in lock_dwork draining on unmap | HIGH | 7.4 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-58640 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.3 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-49789 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.3 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-49790 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.3 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-50364 | Windows Backup Service Elevation of Privilege Vulnerability | HIGH | 7.3 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-50482 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.3 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-55021 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-55034 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-55126 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-53362 | ipv6: account for fraggap on the paged allocation path | HIGH | 7.3 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-63806 | KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() | HIGH | 7.3 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-12080 | Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys | HIGH | 7.3 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-58298 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 7.2 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-49165 | Microsoft Windows App Store Information Disclosure Vulnerability | HIGH | 7.1 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-55144 | Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-56193 | Microsoft Office Information Disclosure Vulnerability | HIGH | 7.1 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-57988 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.1 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-49791 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.1 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50354 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.1 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50428 | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability | HIGH | 7.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50451 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.1 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-50465 | Windows DNS Client Tampering Vulnerability | HIGH | 7.1 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50682 | Active Directory Denial of Service Vulnerability | HIGH | 7.1 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-55122 | Microsoft Excel Information Disclosure Vulnerability | HIGH | 7.1 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-57101 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.1 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-57977 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | HIGH | 7.1 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-58296 | Microsoft Edge for Android Information Disclosure Vulnerability | HIGH | 7.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-58297 | Microsoft Edge for Android Information Disclosure Vulnerability | HIGH | 7.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-58529 | Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability | HIGH | 7.1 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-56171 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | HIGH | 7.1 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-53343 | ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53329 | drm/amd/display: Use krealloc_array() in dal_vector_reserve() | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63810 | block: Avoid mounting the bdev pseudo-filesystem in userspace | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63826 | fbdev: fix use-after-free in store_modes() | HIGH | 7.1 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-63796 | ocfs2: reject oversized group bitmap descriptors | HIGH | 7.1 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-63801 | tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done | HIGH | 7.1 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-63808 | exfat: fix potential use-after-free in exfat_find_dir_entry() | HIGH | 7.1 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-64133 | ALSA: asihpi: Fix potential OOB array access at reading cache | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63879 | drm/amdgpu: fix amdgpu_hmm_range_get_pages | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64146 | erofs: fix metabuf leak in inode xattr initialization | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64189 | netfilter: ipset: fix race between dump and ip_set_list resize | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64219 | drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64294 | mm: do file ownership checks with the proper mount idmap | HIGH | 7.1 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-64379 | smb: client: mask server-provided mode to 07777 in modefromsid | HIGH | 7.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-64210 | net/mlx5e: xsk: Fix unlocked writing to ICOSQ | HIGH | 7.1 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-64212 | wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64334 | USB: serial: digi_acceleport: fix hard lockup on disconnect | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64227 | ACPI: driver: Check ACPI_COMPANION() against NULL during probe | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64245 | fbdev: modedb: fix a possible UAF in fb_find_mode() | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64286 | KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64312 | crypto: pcrypt - restore callback for non-parallel fallback | HIGH | 7.1 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-64510 | ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64470 | Bluetooth: btusb: fix use-after-free on marvell probe failure | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64355 | bpf: Reject fragmented frames in devmap | HIGH | 7.1 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-64496 | iio: event: Fix event FIFO reset race | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64301 | regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() | HIGH | 7.1 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64471 | Bluetooth: btusb: fix use-after-free on registration failure | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64469 | binder: fix UAF in binder_thread_release() | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64405 | Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64411 | netfilter: ebtables: terminate table name before find_table_lock() | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64273 | Input: iforce - bound the device-reported force-feedback effect index | HIGH | 7.1 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64333 | USB: serial: digi_acceleport: fix write buffer corruption | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64268 | RDMA/siw: bound Read Response placement to the RREAD length | HIGH | 7.1 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-64316 | crypto: caam - use print_hex_dump_devel to guard key hex dumps | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64386 | smb: client: fix query_info() replay double-free | HIGH | 7.1 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-64505 | usb: gadget: function: rndis: add length check for header | HIGH | 7.1 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-64399 | ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE | HIGH | 7.1 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-64361 | hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64419 | mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64445 | staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() | HIGH | 7.1 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-64503 | iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64392 | ksmbd: use opener credentials for delete-on-close | HIGH | 7.1 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-64440 | staging: rtl8723bs: fix OOB write in HT_caps_handler() | HIGH | 7.1 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-64435 | audit: Fix data races of skb_queue_len() readers on audit_queue | HIGH | 7.1 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-64296 | exfat: bound uniname advance in exfat_find_dir_entry() | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64329 | usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64479 | ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64436 | net: af_key: initialize alg_key_len for IPComp states | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64385 | smb: client: fix double-free in SMB2_ioctl() replay | HIGH | 7.1 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-64514 | userfaultfd: gate must_wait writability check on pte_present() | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64421 | media: nxp: imx8-isi: Fix use-after-free on remove | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64401 | smb: client: resolve SWN tcon from live registrations | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64315 | crypto: caam - use print_hex_dump_devel to guard key hex dumps | HIGH | 7.1 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-64497 | iio: chemical: scd30: Cleanup initializations and fix sign-extension bug | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64335 | USB: serial: digi_acceleport: fix broken rx after throttle | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64384 | smb: client: fix change notify replay double-free | HIGH | 7.1 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-64375 | proc: protect ptrace_may_access() with exec_update_lock (FD links) | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53354 | arm64: errata: Mitigate TLBI errata on various Arm CPUs | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53356 | drm/i915/gem: Fix phys BO pread/pwrite with offset | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-63805 | crypto: nx - fix nx_crypto_ctx_exit argument | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53402 | fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53368 | f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage | HIGH | 7.1 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-63817 | f2fs: validate compress cache inode only when enabled | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53390 | ksmbd: fix out-of-bounds read in smb_check_perm_dacl() | HIGH | 7.1 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-53383 | ksmbd: reject non-VALID session in compound request branch | HIGH | 7.1 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-64015 | security/keys: fix missed RCU read section on lookup | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64117 | wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb | HIGH | 7.1 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-63961 | usb: typec: altmodes/displayport: validate count before reading Status Update VDO | HIGH | 7.1 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-63963 | usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers | HIGH | 7.1 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-64154 | drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-63978 | net/handshake: Drain pending requests at net namespace exit | HIGH | 7.1 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-39879 | SQL injection in syslog-ng SQL destionation driver | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64303 | spi: fsl-lpspi: terminate the RX channel on TX prepare failure path | HIGH | 7.1 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-64213 | hwmon: (lm90) Add lock protection to lm90_alert | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64255 | wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers | HIGH | 7.1 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-64330 | usb: typec: tcpm: Validate SVID index in svdm_consume_modes() | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64403 | Bluetooth: L2CAP: validate option length before reading conf opt value | HIGH | 7.1 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-64454 | usb: dwc3: run gadget disconnect from sleepable suspend context | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64407 | Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64336 | USB: serial: keyspan_pda: fix information leak | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64495 | iio: gyro: bmg160: bail out when bandwidth/filter is not in table | HIGH | 7.1 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-64362 | HID: lg-g15: cancel pending work on remove to fix a use-after-free | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64395 | ksmbd: require source read access for duplicate extents | HIGH | 7.1 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-64476 | vfio/pci: Latch disable_idle_d3 per device | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64376 | firmware_loader: fix device reference leak in firmware_upload_register() | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64337 | usb: mtu3: unmap request DMA on queue failure | HIGH | 7.1 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64359 | nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64365 | HID: letsketch: fix UAF on inrange_timer at driver unbind | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64280 | fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() | HIGH | 7.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64347 | usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64270 | Input: mms114 - reject an oversized device packet size | HIGH | 7.1 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-64372 | cpufreq: pcc: fix use-after-free and double free in _OSC evaluation | HIGH | 7.1 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64428 | gpio: sch: use raw_spinlock_t in the irq startup path | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64494 | iio: light: gp2ap002: fix runtime PM leak on read error | HIGH | 7.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64472 | vfio/mlx5: Fix racy bitfields and tighten struct layout | HIGH | 7.1 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-48572 | Windows App Package Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-48571 | Windows App Package Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-49162 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-49784 | Microsoft Windows App Store Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-54129 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-54989 | Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-54111 | Universal Print Management Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-54996 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-58526 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.0 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-58598 | Windows Backup Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-49183 | Windows Clipboard Server Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-49802 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-49806 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-49805 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 87%ile | Microsoft | 2026-07-14 |
| CVE-2026-49803 | Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50323 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50296 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50297 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50325 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50356 | Microsoft Windows App Store Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50384 | Windows Clip Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50372 | Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-50392 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50393 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50307 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50396 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50390 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50452 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50348 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50345 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-50322 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-50404 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50358 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50410 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50449 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50371 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-50403 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50397 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50406 | Windows Backup Engine Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50459 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50490 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50491 | Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50503 | Windows Runtime Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-50526 | .NET Tampering Vulnerability | HIGH | 7.0 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50658 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-50669 | Windows Telephony Server Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50672 | Windows NTFS Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50674 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-50359 | Microsoft XML Core Services Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-56173 | Windows WebView Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-56183 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-56187 | Windows MIDI Service Module Elevation of Privileges Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-57093 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-58544 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-58619 | Windows Sensor Data Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-58629 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-58637 | Windows Client-Side Caching Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-53359 | KVM: x86: Fix shadow paging use-after-free due to unexpected role | HIGH | 7.0 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-64530 | net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle | HIGH | 7.0 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-53401 | fbdev: omap2: fix use-after-free in omapfb_mmap | HIGH | 7.0 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64377 | cpufreq: qcom-cpufreq-hw: Fix possible double free | HIGH | 7.0 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-49168 | Storage Spaces Direct Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-54132 | Windows Kernel Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50299 | Windows Storage Spaces Direct Remote Code Execution Vulnerability | MEDIUM | 6.8 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-50298 | Windows Spaceport.sys Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-50426 | Windows DNS Server Remote Code Execution Vulnerability | MEDIUM | 6.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-50492 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | MEDIUM | 6.8 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-50668 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-58522 | Microsoft Edge for Android Information Disclosure Vulnerability | MEDIUM | 6.8 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-58528 | Windows USB Audio Class Driver Information Disclosure Vulnerability | MEDIUM | 6.8 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-58208 | NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled | MEDIUM | 6.8 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-10723 | Incorrect acceptance of NSEC3 records | MEDIUM | 6.8 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-16615 | Librest: weak random number generation in pkce implementation | MEDIUM | 6.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-57216 | RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-a | MEDIUM | 6.8 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-6390 | Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in | MEDIUM | 6.8 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-53397 | nfsd: fix posix_acl leak on SETACL decode failure | MEDIUM | 6.7 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50678 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.6 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-49804 | Windows USB Video Driver Elevation of Privilege Vulnerability | MEDIUM | 6.6 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-45489 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-47282 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55003 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-54108 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-56185 | Windows Admin Center Information Disclosure Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-57976 | Windows Active Directory Domain Services Denial of Service Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-57979 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-57987 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-58279 | Azure CycleCloud Elevation of Privilege Vulnerability | MEDIUM | 6.5 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-56646 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-34348 | Windows Event Logging Service Information Disclosure Vulnerability | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-49799 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-50366 | Windows Active Directory Domain Services Denial of Service Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-50376 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-50445 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-50497 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-50504 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-50659 | .NET Spoofing Vulnerability | MEDIUM | 6.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-54126 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-55054 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-55051 | Microsoft SharePoint Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 47%ile | Microsoft | 2026-07-14 |
| CVE-2026-50468 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-54116 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-56168 | Windows SMB Server Denial of Service Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-07-14 |
| CVE-2026-57982 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | MEDIUM | 6.5 | 58%ile | Microsoft | 2026-07-14 |
| CVE-2026-58523 | Microsoft Edge for Android Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-58533 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-58535 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-58546 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-58539 | Windows Remote Desktop Client Information Disclosure Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-07-14 |
| CVE-2026-49159 | Microsoft Graph Information Disclosure Vulnerability | MEDIUM | 6.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-14258 | Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling | MEDIUM | 6.5 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-8458 | wrong reuse for different services | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-60001 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. | MEDIUM | 6.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-58251 | NATS Server: Queue Subscribe Authz Bypass | MEDIUM | 6.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-58252 | NATS Server: Subscribe Authz Bypass via Wildcard-Overlap | MEDIUM | 6.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-15714 | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversi | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-47729 | Squid: Memory disclosure in FTP gateway | MEDIUM | 6.5 | 72%ile | Microsoft | 2026-07-14 |
| CVE-2026-56434 | NGINX ngx_http_ssi_module vulnerability | MEDIUM | 6.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-56145 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service | MEDIUM | 6.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-63140 | Reachable Assertion in Elasticsearch Leading to Denial of Service | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-63136 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-50248 | BOGUS configured primary hostname accepted for XFR in auth/rpz zones | MEDIUM | 6.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-16277 | Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-10822 | Key Record using PRIVATEDNS algorithm may lead to unexpected exit | MEDIUM | 6.5 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-59843 | Libssh: libssh: denial of service via zero advertised channel packet size | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-60147 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE | MEDIUM | 6.5 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-53345 | KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying | MEDIUM | 6.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-49090 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service | MEDIUM | 6.5 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-59818 | etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-57217 | RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass | MEDIUM | 6.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-57211 | RabbitMQ: UNC SSRF affecting the management UI on Windows | MEDIUM | 6.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-54171 | Excon: redact additional sensitive/risky headers when following redirects | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-63263 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service | MEDIUM | 6.5 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-59844 | Libssh: libssh: denial of service via oversized sftp read length | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-16461 | Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-64381 | smb: client: Fix next buffer leak in receive_encrypted_standard() | MEDIUM | 6.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-55000 | Windows USB Print Driver Elevation of Privilege Vulnerability | MEDIUM | 6.4 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-57097 | Microsoft XML Security Feature Bypass Vulnerability | MEDIUM | 6.4 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-44510 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a | MEDIUM | 6.4 | — | Microsoft | 2026-07-14 |
| CVE-2026-50375 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | MEDIUM | 6.3 | 76%ile | Microsoft | 2026-07-14 |
| CVE-2026-50374 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | MEDIUM | 6.3 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-55145 | Outlook Copilot Tampering Vulnerability | MEDIUM | 6.3 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-57973 | Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability | MEDIUM | 6.3 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-58543 | Universal Print Management Service Elevation of Privilege Vulnerability | MEDIUM | 6.3 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64434 | Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref | MEDIUM | 6.3 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-63871 | Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls | MEDIUM | 6.3 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-50294 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 6.2 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-49807 | Windows DirectX Information Disclosure Vulnerability | MEDIUM | 6.2 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-50420 | HTTP.sys Information Disclosure Vulnerability | MEDIUM | 6.2 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-55026 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 6.2 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-57095 | Win32k Elevation of Privilege Vulnerability | MEDIUM | 6.2 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-58300 | Microsoft Edge for Android Information Disclosure Vulnerability | MEDIUM | 6.2 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-64271 | Input: touchwin - reset the packet index on every complete packet | MEDIUM | 6.2 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-49174 | DNS Client Tampering Vulnerability | MEDIUM | 6.1 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-54988 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.1 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-50383 | Windows Print Spooler Information Disclosure Vulnerability | MEDIUM | 6.1 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50453 | Windows USB Audio Class Driver Information Disclosure Vulnerability | MEDIUM | 6.1 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-50495 | DNS Client Tampering Vulnerability | MEDIUM | 6.1 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-50661 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.1 | 50%ile | Microsoft | 2026-07-14 |
| CVE-2026-55898 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 6.1 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-58291 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | MEDIUM | 6.1 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-59926 | Mistune: XSS via unescaped class option in Admonition directive | MEDIUM | 6.1 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-59890 | setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+ | MEDIUM | 6.1 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-64450 | tipc: fix out-of-bounds read in broadcast Gap ACK blocks | MEDIUM | 6.1 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-64287 | KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU | MEDIUM | 6.1 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64001 | ALSA: pcm: oss: Fix setup list UAF on proc write error | MEDIUM | 6.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-58638 | Windows Boot Loader Security Feature Bypass Vulnerability | MEDIUM | 6.0 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-50324 | Windows Active Directory Federation Services Denial of Service Vulnerability | MEDIUM | 5.9 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-56649 | Windows Network File System Remote Code Execution Vulnerability | MEDIUM | 5.9 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-8925 | SASL double-free | MEDIUM | 5.9 | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-59999 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not | MEDIUM | 5.9 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-15713 | Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak | MEDIUM | 5.9 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15712 | Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-terminati | MEDIUM | 5.9 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-53393 | nfsd: reset write verifier on deferred writeback errors | MEDIUM | 5.9 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-44621 | Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated | MEDIUM | 5.9 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-55717 | 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash | MEDIUM | 5.9 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-50046 | Possible heap use-after-free in an error path when a DoT forwarded query is jostled out | MEDIUM | 5.9 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-55990 | Packet of death for a DNSCrypt misconfigured Unbound | MEDIUM | 5.9 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-55991 | Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 | MEDIUM | 5.9 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-59847 | Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification | MEDIUM | 5.9 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-53357 | Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() | MEDIUM | 5.9 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-52863 | Memory corruption could lead to crash and denial of service | MEDIUM | 5.9 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-56444 | Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual conf | MEDIUM | 5.9 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14586 | Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments | MEDIUM | 5.9 | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-64160 | netfs: Fix potential for tearing in ->remote_i_size and ->zero_point | MEDIUM | 5.8 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-64269 | RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg | MEDIUM | 5.7 | 49%ile | Microsoft | 2026-07-14 |
| CVE-2026-14355 | ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | MEDIUM | 5.6 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-34349 | Windows Media Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-34346 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-49177 | Windows TCP/IP Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-45496 | Visual Studio Code Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-54997 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-58614 | Windows Kernel Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-33842 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-34328 | Windows Audio Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-40422 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-41087 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-49180 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | MEDIUM | 5.5 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-49801 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50316 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50295 | Windows Zero Trust DNS Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-50350 | Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50381 | Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-50300 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50303 | Windows Key Guard Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-50434 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50339 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50430 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50377 | Windows Kernel Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-50401 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50334 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50352 | Windows Cryptographic Services Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50437 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50455 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50409 | Windows Overlay Filter Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50473 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50442 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50389 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50456 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50431 | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50394 | Windows Media Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-50475 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-50483 | Windows Graphics Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50681 | Windows Secure Channel Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50690 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-48580 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-50408 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55046 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-55023 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-55027 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-55028 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-55047 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-55050 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-55138 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55124 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-55035 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-07-14 |
| CVE-2026-55057 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-55142 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-55042 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-55139 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-56184 | Win32k Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-56192 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-56195 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-56178 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-57083 | Windows Media Photo Codec Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-57084 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-57085 | Windows Print Spooler Information Disclosure Vulnerability | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-58547 | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-58545 | Windows Kernel Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-55121 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-53355 | net: rds: clear i_sends on setup unwind | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-53347 | drm/virtio: Fix driver removal with disabled KMS | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53352 | signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-53349 | netfilter: nf_conntrack: destroy stale expectfn expectations on unregister | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-10536 | HTTP/2 stream-dependency tree UAF | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-12480 | Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53392 | NFSv4/flexfiles: reject zero filehandle version count | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-63809 | bpf: use kvfree() for replaced sysctl write buffer | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-63834 | batman-adv: tp_meter: restrict number of unacked list entries | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-53391 | NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-63812 | f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53382 | media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63795 | 9p: avoid putting oldfid in p9_client_walk() error path | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64097 | drm/amd/display: Validate GPIO pin LUT table size before iterating | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64077 | netfilter: ebtables: move to two-stage removal scheme | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64188 | net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64237 | Input: elan_i2c - validate firmware size before use | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64480 | ALSA: ice1712: check snd_ctl_new1() return value | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64244 | drivers/base/memory: set mem->altmap after successful device registration | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64248 | MIPS: smp: report dying CPU to RCU in stop_this_cpu() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64441 | staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() | MEDIUM | 5.5 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-64429 | gpio: eic-sprd: use raw_spinlock_t in the irq startup path | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64351 | net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64430 | NTB: epf: Avoid calling pci_irq_vector() from hardirq context | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-64299 | tracing: Prevent out-of-bounds read in glob matching | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64323 | udf: validate VAT header length against the VAT inode size | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64317 | isofs: bound Rock Ridge symlink components to the SL record | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64318 | partitions: aix: bound the pp_count scan to the ppe array | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64523 | net/handshake: Take a long-lived file reference at submit | MEDIUM | 5.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-64500 | iio: adc: lpc32xx: Initialize completion before requesting IRQ | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64400 | ksmbd: prevent path traversal bypass by restricting caseless retry | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-64277 | Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64408 | Bluetooth: bnep: pin L2CAP connection during netdev registration | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-64360 | hfs/hfsplus: zero-initialize buffer in hfs_bnode_read | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64348 | usb: free iso schedules on failed submit | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64462 | PCI: altera: Fix resource leaks on probe failure | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64374 | sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-07-14 |
| CVE-2026-64425 | io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64525 | xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64387 | smb: client: fix query directory replay double-free | MEDIUM | 5.5 | 37%ile | Microsoft | 2026-07-14 |
| CVE-2026-64397 | ksmbd: serialize QUERY_DIRECTORY requests per file | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-64409 | Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64412 | netfilter: ebtables: module names must be null-terminated | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64345 | usb: gadget: f_printer: take kref only for successful open | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64390 | ksmbd: track the connection owning a byte-range lock | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-64406 | Bluetooth: fix UAF in bt_accept_dequeue() | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-64487 | ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64364 | HID: multitouch: fix out-of-bounds bit access on mt_io_flags | MEDIUM | 5.5 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-64511 | ACPI: NFIT: core: Fix possible NULL pointer dereference | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64458 | mm/damon/ops-common: handle extreme intervals in damon_hot_score() | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64422 | net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64465 | usb: xhci: Fix sleep in atomic context in xhci_free_streams() | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64468 | binder: fix UAF in binder_free_transaction() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64331 | usbip: vudc: fix NULL deref in vep_dequeue() | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64413 | netfilter: ebtables: zero chainstack array | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-64493 | iio: pressure: mpl115: fix runtime PM leak on read error | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64452 | 6lowpan: fix NHC entry use-after-free on error path | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-64486 | ALSA: cmipci: check snd_ctl_new1() return value | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2024-14040 | net: nexthop: Increase weight to u16 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53332 | slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53336 | nvmem: layouts: onie-tlv: fix hang on unknown types | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53327 | debugobjects: Do not fill_pool() if pi_blocked_on | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53337 | net: bonding: fix NULL pointer dereference in bond_do_ioctl() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53353 | hsr: Remove WARN_ONCE() in hsr_addr_is_self(). | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53339 | i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-50012 | Squid: Memory corruption in cache_digest reply handling | MEDIUM | 5.5 | 69%ile | Microsoft | 2026-07-14 |
| CVE-2026-63825 | gcov: use atomic counter updates to fix concurrent access crashes | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-63811 | f2fs: read COW data with the original inode during atomic write | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-53377 | drm/msm: always recover the gpu | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-53399 | nfsd: release layout stid on setlease failure | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-63821 | wifi: rtw88: usb: fix memory leaks on USB write failures | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-63798 | irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53385 | vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-53398 | NFSD: Fix SECINFO_NO_NAME decode error cleanup | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-07-14 |
| CVE-2026-64038 | hwmon: (lm90) Stop work before releasing hwmon device | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64036 | cgroup/rstat: validate cpu before css_rstat_cpu() access | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63962 | usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-63954 | hpfs: fix a crash if hpfs_map_dnode_bitmap fails | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-63964 | usb: typec: ucsi: ccg: reject firmware images without a ':' record header | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-63960 | usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64060 | netfs: Fix leak of request in netfs_write_begin() error handling | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64187 | xfs: fail recovery on a committed log item with no regions | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64205 | i2c: i801: fix hardware state machine corruption in error path | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64190 | net: team: fix NULL pointer dereference in team_xmit during mode change | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64206 | Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-64529 | crypto: qat - remove unused character device and IOCTLs | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64433 | Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64396 | ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-64241 | gpio: rockchip: teardown bugs and resource leaks | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64250 | LoongArch: Report dying CPU to RCU in stop_this_cpu() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64272 | Input: mms114 - fix touch indexing for MMS134S and MMS136 | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-64488 | ALSA: aoa: check snd_ctl_new1() return value | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64444 | staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-64484 | ALSA: es1938: check snd_ctl_new1() return value | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64398 | ksmbd: add a permission check for FSCTL_SET_ZERO_DATA | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-64346 | usb: gadget: udc: Fix use-after-free in gadget_match_driver | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64350 | usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64482 | ALSA: gus: check snd_ctl_new1() return value | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64324 | udf: validate free block extents against the partition length | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64326 | block: skip sync_blockdev() on surprise removal in bdev_mark_dead() | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-64474 | vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64368 | mm/slab: do not limit zeroing to orig_size when only red zoning is enabled | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-64489 | ALSA: ymfpci: check snd_ctl_new1() return value | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-64507 | x86/bugs: Enable IBPB flush on BPF JIT allocation | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64338 | USB: misc: uss720: unregister parport on probe failure | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64306 | crypto: drbg - Fix returning success on failure in CTR_DRBG | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64363 | HID: appleir: fix UAF on pending key_up_timer in remove() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64370 | posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64332 | USB: ulpi: fix memory leak on registration failure | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64275 | Input: elan_i2c - prevent division by zero and arithmetic underflow | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64438 | crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64443 | staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-64352 | bpf: Allow LPM map access from sleepable BPF programs | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64276 | Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64297 | module: decompress: check return value of module_extend_max_pages() | MEDIUM | 5.5 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-50341 | Windows NTFS Information Disclosure Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-45488 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-58278 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-57980 | Microsoft Edge (Chromium-based) Tampering Vulnerability | MEDIUM | 5.4 | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-57978 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-56157 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-58524 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-62828 | Microsoft Edge for Android (Chromium-based) Tampering Vulnerability | MEDIUM | 5.4 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | MEDIUM | 5.3 | 98%ile | Microsoft | 2026-07-14 |
| CVE-2026-44806 | Windows Secure Channel Denial of Service Vulnerability | MEDIUM | 5.3 | 54%ile | Microsoft | 2026-07-14 |
| CVE-2026-50432 | Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability | MEDIUM | 5.3 | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-50415 | Windows Media Information Disclosure Vulnerability | MEDIUM | 5.3 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-11856 | cross-origin Digest auth state leak | MEDIUM | 5.3 | 46%ile | Microsoft | 2026-07-14 |
| CVE-2026-42505 | Invoking Encrypted Client Hello privacy leak in crypto/tls | MEDIUM | 5.3 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-62299 | CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response | MEDIUM | 5.3 | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-50251 | Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush | MEDIUM | 5.3 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-15588 | Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering | MEDIUM | 5.3 | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-44508 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a | MEDIUM | 5.3 | — | Microsoft | 2026-07-14 |
| CVE-2026-59848 | Libssh: libssh: denial of service via sftp responses with unknown request ids | MEDIUM | 5.3 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-59845 | Libssh: libssh: denial of service via unchecked proxycommand fork() failure | MEDIUM | 5.3 | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-16768 | Gdk-pixbuf: out-of-bounds read in ico parser | MEDIUM | 5.3 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-8927 | env-set cross-proxy Digest auth state leak | MEDIUM | 5.3 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-59871 | node-tar: Process crash via PAX numeric path type confusion | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-59875 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records | MEDIUM | 5.3 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-64082 | riscv: Fix register corruption from uninitialized cregs on error | MEDIUM | 5.3 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-50045 | 'max-global-quota' reset by DNSSEC validation restarts | MEDIUM | 5.3 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-46917 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE | MEDIUM | 5.3 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-64478 | ALSA: usb-audio: avoid kobject path lookup in DualSense match | MEDIUM | 5.2 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-50418 | Windows System Secure Feature Bypass Vulnerability | MEDIUM | 5.1 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-47143 | Capstone has a NULL Pointer Dereference with 3DNow! opcodes | MEDIUM | 5.1 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-63815 | f2fs: bound i_inline_xattr_size for non-inline-xattr inodes | MEDIUM | 5.0 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-63819 | f2fs: fix to do sanity check on f2fs_get_node_folio_ra() | MEDIUM | 5.0 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-56149 | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-38753 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv | MEDIUM | 4.9 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-26145 | Microsoft Azure Synapse Elevation of Privilege Vulnerability | MEDIUM | 4.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-50684 | Active Directory Federation Server Spoofing Vulnerability | MEDIUM | 4.8 | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-59998 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th | MEDIUM | 4.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-26081 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise | MEDIUM | 4.8 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-57213 | RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering | MEDIUM | 4.8 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-56416 | Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name | MEDIUM | 4.8 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-49167 | Windows Kernel Elevation of Privilege Vulnerability | MEDIUM | 4.7 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-50310 | Windows Human Interface Device Information Disclosure Vulnerability | MEDIUM | 4.7 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-50312 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | MEDIUM | 4.7 | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-50657 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability | MEDIUM | 4.7 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-64378 | writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-64279 | i2c: core: fix adapter deregistration race | MEDIUM | 4.7 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-64373 | cpufreq: Fix hotplug-suspend race during reboot | MEDIUM | 4.7 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-64371 | proc: protect ptrace_may_access() with exec_update_lock (part 1) | MEDIUM | 4.7 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-49794 | Windows USB Audio Class Driver Information Disclosure Vulnerability | MEDIUM | 4.6 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-55016 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-55019 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-55020 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-55030 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-55135 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-62826 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-50485 | Windows Hyper-V Denial of Service Vulnerability | MEDIUM | 4.5 | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-53361 | af_unix: Set gc_in_progress to true in unix_gc(). | MEDIUM | 4.5 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-59831 | GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace | MEDIUM | 4.4 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-63835 | batman-adv: v: prevent OGM aggregation on disabled hardif | MEDIUM | 4.4 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-63830 | net: skmsg: preserve sg.copy across SG transforms | MEDIUM | 4.4 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-64388 | smb/client: fix chown/chgrp with SMB3 POSIX Extensions | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-58597 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-14647 | onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds | MEDIUM | 4.3 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-59930 | Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing c | MEDIUM | 4.3 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-58209 | NATS Server: MQTT retained and QoS replay bypass subscribe deny filters | MEDIUM | 4.3 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-63308 | Helm Files.Lines Denial of Service via Empty Chart Files | MEDIUM | 4.3 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-59850 | Libssh: libssh: use-after-free via data callbacks on closed channels | MEDIUM | 4.3 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-55945 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | MEDIUM | 4.2 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-50302 | Windows Cryptographic Services Security Feature Bypass Vulnerability | MEDIUM | 4.2 | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-59997 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important | MEDIUM | 4.2 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-59996 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee | MEDIUM | 4.2 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-59995 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u | MEDIUM | 4.2 | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-64424 | netpoll: fix a use-after-free on shutdown path | MEDIUM | 4.1 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13221 | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 6553 | MEDIUM | 4.0 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-15028 | Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header | LOW | 3.9 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-59846 | Libssh: libssh: information disclosure via proxycommand %r username expansion | LOW | 3.9 | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-9080 | UAF after pause in socket callback | LOW | 3.7 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-60000 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au | LOW | 3.7 | 36%ile | Microsoft | 2026-07-14 |
| CVE-2026-44687 | Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN | LOW | 3.7 | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-46582 | A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path | LOW | 3.7 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-42955 | Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation re | LOW | 3.7 | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-26080 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro | LOW | 3.7 | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-47059 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE | LOW | 3.7 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-62994 | CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin | LOW | 3.7 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-54478 | DNS Cookie bypass when combined with proxy-protocol use | LOW | 3.7 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-41637 | Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries | LOW | 3.7 | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-12547 | Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch | LOW | 3.4 | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-50419 | Windows Kernel Information Disclosure Vulnerability | LOW | 3.3 | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-41579 | runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations | LOW | 3.3 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-50416 | Win32k Information Disclosure Vulnerability | LOW | 3.3 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-55708 | Privacy/configuration issue when adding local data in views through 'unbound-control' | LOW | 3.1 | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-16517 | Libarchive: libarchive: signed integer overflow in archive_write_zip_header | LOW | 2.9 | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-38752 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial | LOW | 2.9 | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-64512 | ACPI: CPPC: Suppress UBSAN warning caused by field misuse | LOW | 1.9 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-48561 | Microsoft Edge Copilot Remote Code Execution Vulnerability | UNKNOWN | — | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-56160 | Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability | UNKNOWN | — | 48%ile | Microsoft | 2026-07-14 |
| CVE-2026-16419 | Chromium: CVE-2026-16419 Out of bounds read and write in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-16415 | Chromium: CVE-2026-16415 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-16418 | Chromium: CVE-2026-16418 Stack buffer overflow in V8 | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-16417 | Chromium: CVE-2026-16417 Uninitialized Use in Skia | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-16413 | Chromium: CVE-2026-16413 Out of bounds write in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-16414 | Chromium: CVE-2026-16414 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-16416 | Chromium: CVE-2026-16416 Integer overflow in Chromecast | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-16424 | Chromium: CVE-2026-16424 Use after free in GPU | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-16421 | Chromium: CVE-2026-16421 Inappropriate implementation in WebAudio | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-16422 | Chromium: CVE-2026-16422 Insufficient validation of untrusted input in Certificate | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-16423 | Chromium: CVE-2026-16423 Use after free in UI | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-16804 | Chromium: CVE-2026-16804 Use after free in Input | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-16805 | Chromium: CVE-2026-16805 Use after free in Blink | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-16806 | Chromium: CVE-2026-16806 Use after free in WebMCP | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-15767 | Chromium: CVE-2026-15767 Heap buffer overflow in libyuv | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13775 | Chromium: CVE-2026-13775 Use after free in GPU | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13776 | Chromium: CVE-2026-13776 Type Confusion in Dawn | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13779 | Chromium: CVE-2026-13779 Use after free in Chromoting | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-13780 | Chromium: CVE-2026-13780 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13781 | Chromium: CVE-2026-13781 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13782 | Chromium: CVE-2026-13782 Use after free in Browser | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13783 | Chromium: CVE-2026-13783 Use after free in Views | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13784 | Chromium: CVE-2026-13784 Use after free in Views | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13786 | Chromium: CVE-2026-13786 Use after free in Ozone | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13787 | Chromium: CVE-2026-13787 Use after free in Chromoting | UNKNOWN | — | 35%ile | Microsoft | 2026-07-14 |
| CVE-2026-13790 | Chromium: CVE-2026-13790 Side-channel information leakage in Scroll | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13793 | Chromium: CVE-2026-13793 Insufficient policy enforcement in SVG | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13794 | Chromium: CVE-2026-13794 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-13797 | Chromium: CVE-2026-13797 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13798 | Chromium: CVE-2026-13798 Heap buffer overflow in Chromecast | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13801 | Chromium: CVE-2026-13801 Integer overflow in Chromecast | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13802 | Chromium: CVE-2026-13802 Use after free in Views | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13803 | Chromium: CVE-2026-13803 Type Confusion in Chrome Tabs | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13804 | Chromium: CVE-2026-13804 Use after free in Chromecast | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13848 | Chromium: CVE-2026-13848 Use after free in Forms | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-13849 | Chromium: CVE-2026-13849 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-13853 | Chromium: CVE-2026-13853 Use after free in Journeys | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13855 | Chromium: CVE-2026-13855 Use after free in Ozone | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13857 | Chromium: CVE-2026-13857 Inappropriate implementation in Geometry | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13858 | Chromium: CVE-2026-13858 Out of bounds read in FFmpeg | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13859 | Chromium: CVE-2026-13859 Inappropriate implementation in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13854 | Chromium: CVE-2026-13854 Use after free in Ozone | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13860 | Chromium: CVE-2026-13860 Incorrect security UI in Autofill | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13864 | Chromium: CVE-2026-13864 Insufficient policy enforcement in WebHID | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13861 | Chromium: CVE-2026-13861 Use after free in Core | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13865 | Chromium: CVE-2026-13865 Insufficient validation of untrusted input in Enterprise | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13867 | Chromium: CVE-2026-13867 Inappropriate implementation in Geolocation | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13869 | Chromium: CVE-2026-13869 Use after free in Device | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13871 | Chromium: CVE-2026-13871 Insufficient data validation in GuestView | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13873 | Chromium: CVE-2026-13873 Out of bounds memory access in Layout | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13874 | Chromium: CVE-2026-13874 Inappropriate implementation in DataTransfer | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-13876 | Chromium: CVE-2026-13876 Inappropriate implementation in Network | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13877 | Chromium: CVE-2026-13877 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13875 | Chromium: CVE-2026-13875 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13879 | Chromium: CVE-2026-13879 Use after free in Bluetooth | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13882 | Chromium: CVE-2026-13882 Inappropriate implementation in USB | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13881 | Chromium: CVE-2026-13881 Insufficient data validation in WebAppInstalls | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13883 | Chromium: CVE-2026-13883 Type Confusion in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13886 | Chromium: CVE-2026-13886 Policy bypass in Isolated Web Apps | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13888 | Chromium: CVE-2026-13888 Use after free in Extensions | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-13884 | Chromium: CVE-2026-13884 Heap buffer overflow in Chromecast | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13890 | Chromium: CVE-2026-13890 Out of bounds read in Chromecast | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13891 | Chromium: CVE-2026-13891 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13893 | Chromium: CVE-2026-13893 Insufficient validation of untrusted input in WebUI | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13894 | Chromium: CVE-2026-13894 Insufficient policy enforcement in Network | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13895 | Chromium: CVE-2026-13895 Inappropriate implementation in Autofill | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13896 | Chromium: CVE-2026-13896 Insufficient policy enforcement in Glic | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13897 | Chromium: CVE-2026-13897 Insufficient policy enforcement in Chromecast | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13898 | Chromium: CVE-2026-13898 Use after free in Cast Receiver | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-13901 | Chromium: CVE-2026-13901 Insufficient validation of untrusted input in Serial | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13900 | Chromium: CVE-2026-13900 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13899 | Chromium: CVE-2026-13899 Use after free in HTML | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-13903 | Chromium: CVE-2026-13903 Insufficient policy enforcement in Bluetooth | UNKNOWN | — | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-13906 | Chromium: CVE-2026-13906 Out of bounds read in Codecs | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13909 | Chromium: CVE-2026-13909 Insufficient policy enforcement in DevTools | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13911 | Chromium: CVE-2026-13911 Insufficient data validation in Spellcheck | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13921 | Chromium: CVE-2026-13921 Insufficient validation of untrusted input in DeviceBoundSessionCredentials | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13922 | Chromium: CVE-2026-13922 Side-channel information leakage in Paint | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13920 | Chromium: CVE-2026-13920 Insufficient validation of untrusted input in Media | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13919 | Chromium: CVE-2026-13919 Insufficient data validation in Extensions | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13925 | Chromium: CVE-2026-13925 Inappropriate implementation in Downloads | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-13928 | Chromium: CVE-2026-13928 Insufficient validation of untrusted input in Enterprise | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13931 | Chromium: CVE-2026-13931 Inappropriate implementation in Media | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-13934 | Chromium: CVE-2026-13934 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13933 | Chromium: CVE-2026-13933 Insufficient policy enforcement in Passwords | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13930 | Chromium: CVE-2026-13930 Insufficient policy enforcement in Actor | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13935 | Chromium: CVE-2026-13935 Side-channel information leakage in ComputePressure | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13937 | Chromium: CVE-2026-13937 Insufficient policy enforcement in Passwords | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13938 | Chromium: CVE-2026-13938 Integer overflow in Fonts | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13940 | Chromium: CVE-2026-13940 Uninitialized Use in Cast | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13942 | Chromium: CVE-2026-13942 Insufficient validation of untrusted input in Video Capture | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13941 | Chromium: CVE-2026-13941 Inappropriate implementation in SiteSettings | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13945 | Chromium: CVE-2026-13945 Insufficient policy enforcement in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13947 | Chromium: CVE-2026-13947 Uninitialized Use in XR | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13948 | Chromium: CVE-2026-13948 Insufficient policy enforcement in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13950 | Chromium: CVE-2026-13950 Uninitialized Use in GPU | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13951 | Chromium: CVE-2026-13951 Policy bypass in USB | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13952 | Chromium: CVE-2026-13952 Inappropriate implementation in PerformanceAPIs | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13953 | Chromium: CVE-2026-13953 Inappropriate implementation in SplitView | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13956 | Chromium: CVE-2026-13956 Incorrect security UI in PageInfo | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13958 | Chromium: CVE-2026-13958 Uninitialized Use in Codecs | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13957 | Chromium: CVE-2026-13957 Incorrect security UI in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-13959 | Chromium: CVE-2026-13959 Insufficient validation of untrusted input in Blink | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13960 | Chromium: CVE-2026-13960 Inappropriate implementation in Passwords | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13962 | Chromium: CVE-2026-13962 Insufficient data validation in PDF | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13963 | Chromium: CVE-2026-13963 Inappropriate implementation in DevTools | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13965 | Chromium: CVE-2026-13965 Use after free in Oilpan | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-13967 | Chromium: CVE-2026-13967 Type Confusion in V8 | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-13966 | Chromium: CVE-2026-13966 Inappropriate implementation in History | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13968 | Chromium: CVE-2026-13968 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-13970 | Chromium: CVE-2026-13970 Uninitialized Use in Media | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13972 | Chromium: CVE-2026-13972 Inappropriate implementation in Paint | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13971 | Chromium: CVE-2026-13971 Uninitialized Use in Skia | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13973 | Chromium: CVE-2026-13973 Inappropriate implementation in UI | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-13976 | Chromium: CVE-2026-13976 Heap buffer overflow in Storage | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-13977 | Chromium: CVE-2026-13977 Inappropriate implementation in HTMLParser | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-13978 | Chromium: CVE-2026-13978 Insufficient policy enforcement in PageInfo | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13979 | Chromium: CVE-2026-13979 Inappropriate implementation in Paint | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13982 | Chromium: CVE-2026-13982 Incorrect security UI in Passwords | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-13984 | Chromium: CVE-2026-13984 Incorrect security UI in TabStrip | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-13985 | Chromium: CVE-2026-13985 Inappropriate implementation in MediaCapture | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-13986 | Chromium: CVE-2026-13986 Inappropriate implementation in Media UI | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-13989 | Chromium: CVE-2026-13989 Insufficient policy enforcement in PageInfo | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-13988 | Chromium: CVE-2026-13988 Inappropriate implementation in Paint | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13993 | Chromium: CVE-2026-13993 Incorrect security UI in WebAppInstalls | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-13990 | Chromium: CVE-2026-13990 Insufficient validation of untrusted input in DataTransfer | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-13996 | Chromium: CVE-2026-13996 Incorrect security UI in Permissions | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13999 | Chromium: CVE-2026-13999 Inappropriate implementation in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14000 | Chromium: CVE-2026-14000 Inappropriate implementation in XML | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14001 | Chromium: CVE-2026-14001 Inappropriate implementation in Network | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14002 | Chromium: CVE-2026-14002 Inappropriate implementation in Geolocation | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14003 | Chromium: CVE-2026-14003 Insufficient policy enforcement in Extensions | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14004 | Chromium: CVE-2026-14004 Inappropriate implementation in CSS | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14006 | Chromium: CVE-2026-14006 Use after free in Navigation | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14007 | Chromium: CVE-2026-14007 Insufficient policy enforcement in PermissionsPolicy | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14008 | Chromium: CVE-2026-14008 Uninitialized Use in WebXR | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14009 | Chromium: CVE-2026-14009 Insufficient data validation in Passwords | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14010 | Chromium: CVE-2026-14010 Uninitialized Use in Codecs | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14011 | Chromium: CVE-2026-14011 Out of bounds read in SurfaceCapture | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14012 | Chromium: CVE-2026-14012 Side-channel information leakage in CSS | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-14013 | Chromium: CVE-2026-14013 Inappropriate implementation in SVG | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14014 | Chromium: CVE-2026-14014 Inappropriate implementation in Paint | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14015 | Chromium: CVE-2026-14015 Inappropriate implementation in WebRTC | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-14018 | Chromium: CVE-2026-14018 Use after free in Updater | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-14016 | Chromium: CVE-2026-14016 Insufficient policy enforcement in SVG | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14017 | Chromium: CVE-2026-14017 Inappropriate implementation in Navigation | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14019 | Chromium: CVE-2026-14019 Inappropriate implementation in Passwords | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14020 | Chromium: CVE-2026-14020 Insufficient validation of untrusted input in WebXR | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14021 | Chromium: CVE-2026-14021 Insufficient validation of untrusted input in StorageAccessAPI | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14022 | Chromium: CVE-2026-14022 Insufficient validation of untrusted input in Network | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-14023 | Chromium: CVE-2026-14023 Insufficient validation of untrusted input in SanitizerAPI | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14025 | Chromium: CVE-2026-14025 Use after free in Views | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14024 | Chromium: CVE-2026-14024 Use after free in Ozone | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14027 | Chromium: CVE-2026-14027 Use after free in SignIn | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14031 | Chromium: CVE-2026-14031 Incorrect security UI in File Input | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14032 | Chromium: CVE-2026-14032 Use after free in Bluetooth | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-14030 | Chromium: CVE-2026-14030 Incorrect security UI in SplitView | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-14034 | Chromium: CVE-2026-14034 Inappropriate implementation in WebXR | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14033 | Chromium: CVE-2026-14033 Insufficient policy enforcement in Media | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-14035 | Chromium: CVE-2026-14035 Insufficient policy enforcement in Bluetooth | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14036 | Chromium: CVE-2026-14036 Insufficient policy enforcement in Bluetooth | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14038 | Chromium: CVE-2026-14038 Insufficient validation of untrusted input in New Tab Page | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14039 | Chromium: CVE-2026-14039 Insufficient policy enforcement in GetUserMedia | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-14037 | Chromium: CVE-2026-14037 Insufficient policy enforcement in GPU | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14040 | Chromium: CVE-2026-14040 Use after free in BrowserTag | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14042 | Chromium: CVE-2026-14042 Inappropriate implementation in Isolated Web Apps | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14041 | Chromium: CVE-2026-14041 Insufficient policy enforcement in Serial | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14043 | Chromium: CVE-2026-14043 Use after free in GetUserMedia | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14044 | Chromium: CVE-2026-14044 Use after free in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14045 | Chromium: CVE-2026-14045 Insufficient validation of untrusted input in Network | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14046 | Chromium: CVE-2026-14046 Inappropriate implementation in CustomTabs | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14047 | Chromium: CVE-2026-14047 Insufficient policy enforcement in Extensions | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14048 | Chromium: CVE-2026-14048 Use after free in Chromecast | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-14049 | Chromium: CVE-2026-14049 Inappropriate implementation in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14050 | Chromium: CVE-2026-14050 Insufficient policy enforcement in Passwords | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14051 | Chromium: CVE-2026-14051 Uninitialized Use in GamepadAPI | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14052 | Chromium: CVE-2026-14052 Insufficient policy enforcement in FileSystem | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14055 | Chromium: CVE-2026-14055 Insufficient validation of untrusted input in Device Trust | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14053 | Chromium: CVE-2026-14053 Insufficient policy enforcement in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14056 | Chromium: CVE-2026-14056 Insufficient validation of untrusted input in Media | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14054 | Chromium: CVE-2026-14054 Insufficient policy enforcement in Network | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14057 | Chromium: CVE-2026-14057 Insufficient policy enforcement in FedCM | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14058 | Chromium: CVE-2026-14058 Policy bypass in Parser | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14060 | Chromium: CVE-2026-14060 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-14062 | Chromium: CVE-2026-14062 Inappropriate implementation in Views | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14059 | Chromium: CVE-2026-14059 Insufficient policy enforcement in Related-Website-Sets | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14061 | Chromium: CVE-2026-14061 Inappropriate implementation in Dawn | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14063 | Chromium: CVE-2026-14063 Out of bounds memory access in Chromecast | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14064 | Chromium: CVE-2026-14064 Use after free in PageInfo | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-14065 | Chromium: CVE-2026-14065 Insufficient validation of untrusted input in PageInfo | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14068 | Chromium: CVE-2026-14068 Inappropriate implementation in Omnibox | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14026 | Chromium: CVE-2026-14026 Incorrect security UI in SplitView | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-14069 | Chromium: CVE-2026-14069 Integer overflow in WebNN | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14070 | Chromium: CVE-2026-14070 Uninitialized Use in WebNN | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14072 | Chromium: CVE-2026-14072 Incorrect security UI in SplitView | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14071 | Chromium: CVE-2026-14071 Side-channel information leakage in WebAudio | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14073 | Chromium: CVE-2026-14073 Insufficient policy enforcement in WebXR | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14076 | Chromium: CVE-2026-14076 Policy bypass in Network | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14077 | Chromium: CVE-2026-14077 Incorrect security UI in Select | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14078 | Chromium: CVE-2026-14078 Policy bypass in WebRTC | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14079 | Chromium: CVE-2026-14079 Policy bypass in Network | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14081 | Chromium: CVE-2026-14081 Insufficient policy enforcement in DevTools | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14080 | Chromium: CVE-2026-14080 Insufficient validation of untrusted input in TabSwitcher | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14082 | Chromium: CVE-2026-14082 Race in Storage | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14074 | Chromium: CVE-2026-14074 Side-channel information leakage in WebAuthentication | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14083 | Chromium: CVE-2026-14083 Insufficient validation of untrusted input in HTML | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14084 | Chromium: CVE-2026-14084 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14085 | Chromium: CVE-2026-14085 Side-channel information leakage in CSS | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14086 | Chromium: CVE-2026-14086 Insufficient policy enforcement in HID | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14087 | Chromium: CVE-2026-14087 Insufficient validation of untrusted input in WebNN | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14089 | Chromium: CVE-2026-14089 Insufficient validation of untrusted input in PopupBlocker | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14088 | Chromium: CVE-2026-14088 Uninitialized Use in Canvas | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14090 | Chromium: CVE-2026-14090 Out of bounds read in CameraCapture | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14092 | Chromium: CVE-2026-14092 Insufficient policy enforcement in Privacy | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14095 | Chromium: CVE-2026-14095 Insufficient validation of untrusted input in Browser | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14093 | Chromium: CVE-2026-14093 Use after free in Cast | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14094 | Chromium: CVE-2026-14094 Use after free in Installer | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-14097 | Chromium: CVE-2026-14097 Inappropriate implementation in WebAppInstalls | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14100 | Chromium: CVE-2026-14100 Insufficient data validation in NetworkCache | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14102 | Chromium: CVE-2026-14102 Use after free in Passwords | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14104 | Chromium: CVE-2026-14104 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 33%ile | Microsoft | 2026-07-14 |
| CVE-2026-14103 | Chromium: CVE-2026-14103 Use after free in SSL | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14098 | Chromium: CVE-2026-14098 Inappropriate implementation in CSS | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14105 | Chromium: CVE-2026-14105 Insufficient policy enforcement in Speech | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14106 | Chromium: CVE-2026-14106 Insufficient validation of untrusted input in Text | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14091 | Chromium: CVE-2026-14091 Use after free in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14107 | Chromium: CVE-2026-14107 Use after free in Scheduling | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14108 | Chromium: CVE-2026-14108 Use after free in PDFium | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-14109 | Chromium: CVE-2026-14109 Insufficient policy enforcement in Mojo | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14110 | Chromium: CVE-2026-14110 Inappropriate implementation in DarkMode | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14111 | Chromium: CVE-2026-14111 Use after free in WebProtect | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14113 | Chromium: CVE-2026-14113 Use after free in Updater | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14115 | Chromium: CVE-2026-14115 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14112 | Chromium: CVE-2026-14112 Inappropriate implementation in Enterprise | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14117 | Chromium: CVE-2026-14117 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14118 | Chromium: CVE-2026-14118 Insufficient data validation in DevTools | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14119 | Chromium: CVE-2026-14119 Type Confusion in Bluetooth | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-14120 | Chromium: CVE-2026-14120 Inappropriate implementation in DevTools | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14116 | Chromium: CVE-2026-14116 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-14121 | Chromium: CVE-2026-14121 Use after free in Chromoting | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-14124 | Chromium: CVE-2026-14124 Inappropriate implementation in CredentialProvider | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-14125 | Chromium: CVE-2026-14125 Uninitialized Use in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14122 | Chromium: CVE-2026-14122 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14127 | Chromium: CVE-2026-14127 Inappropriate implementation in Printing | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14129 | Chromium: CVE-2026-14129 Incorrect security UI in PreviewTab | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-14130 | Chromium: CVE-2026-14130 Incorrect security UI in Omnibox | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14133 | Chromium: CVE-2026-14133 Race in History Embeddings | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-14131 | Chromium: CVE-2026-14131 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14132 | Chromium: CVE-2026-14132 Inappropriate implementation in WebXR | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14134 | Chromium: CVE-2026-14134 Inappropriate implementation in Autofill | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14139 | Chromium: CVE-2026-14139 Inappropriate implementation in TabStrip | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-14140 | Chromium: CVE-2026-14140 Insufficient validation of untrusted input in Input | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14141 | Chromium: CVE-2026-14141 Incorrect security UI in Document Picture-in-Picture | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14142 | Chromium: CVE-2026-14142 Inappropriate implementation in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14135 | Chromium: CVE-2026-14135 Insufficient validation of untrusted input in Network | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14138 | Chromium: CVE-2026-14138 Inappropriate implementation in WebAppInstalls | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-14144 | Chromium: CVE-2026-14144 Incorrect security UI in Views | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14143 | Chromium: CVE-2026-14143 Incorrect security UI in Passwords | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14145 | Chromium: CVE-2026-14145 Inappropriate implementation in CSS | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14146 | Chromium: CVE-2026-14146 Inappropriate implementation in CSS | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14148 | Chromium: CVE-2026-14148 Type Confusion in CSS | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14147 | Chromium: CVE-2026-14147 Inappropriate implementation in CSS | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-14152 | Chromium: CVE-2026-14152 Out of bounds write in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14150 | Chromium: CVE-2026-14150 Insufficient validation of untrusted input in Speech | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-14149 | Chromium: CVE-2026-14149 Use after free in Audio | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14151 | Chromium: CVE-2026-14151 Inappropriate implementation in AI | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14155 | Chromium: CVE-2026-14155 Insufficient policy enforcement in StorageAccessAPI | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-14153 | Chromium: CVE-2026-14153 Inappropriate implementation in Glic | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14154 | Chromium: CVE-2026-14154 Inappropriate implementation in DevTools | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-14156 | Chromium: CVE-2026-14156 Policy bypass in StorageAccessAPI | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13961 | Chromium: CVE-2026-13961 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13774 | Chromium: CVE-2026-13774 Use after free in Extensions | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-13777 | Chromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWeb | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13778 | Chromium: CVE-2026-13778 Use after free in WebUSB | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13788 | Chromium: CVE-2026-13788 Use after free in Fullscreen | UNKNOWN | — | 34%ile | Microsoft | 2026-07-14 |
| CVE-2026-13791 | Chromium: CVE-2026-13791 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-13795 | Chromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOS | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-13785 | Chromium: CVE-2026-13785 Use after free in Bluetooth | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13805 | Chromium: CVE-2026-13805 Use after free in GFX | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-13807 | Chromium: CVE-2026-13807 Use after free in Import | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13812 | Chromium: CVE-2026-13812 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-13809 | Chromium: CVE-2026-13809 Side-channel information leakage in Safe Browsing | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13808 | Chromium: CVE-2026-13808 Insufficient data validation in Chrome for iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-13816 | Chromium: CVE-2026-13816 Insufficient validation of untrusted input in File Input | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13813 | Chromium: CVE-2026-13813 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13825 | Chromium: CVE-2026-13825 Uninitialized Use in Dawn | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13819 | Chromium: CVE-2026-13819 Out of bounds read in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13822 | Chromium: CVE-2026-13822 Inappropriate implementation in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13826 | Chromium: CVE-2026-13826 Inappropriate implementation in Autofill | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13827 | Chromium: CVE-2026-13827 Use after free in Updater | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-13833 | Chromium: CVE-2026-13833 Uninitialized Use in ANGLE | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13843 | Chromium: CVE-2026-13843 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13842 | Chromium: CVE-2026-13842 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13846 | Chromium: CVE-2026-13846 Use after free in USB | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13847 | Chromium: CVE-2026-13847 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13792 | Chromium: CVE-2026-13792 Use after free in Touchbar | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13851 | Chromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13852 | Chromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13850 | Chromium: CVE-2026-13850 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13856 | Chromium: CVE-2026-13856 Insufficient validation of untrusted input in Speech | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13862 | CVE-2026-13862 | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-13863 | Chromium: CVE-2026-13863 Insufficient validation of untrusted input in CustomTabs | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13866 | Chromium: CVE-2026-13866 Insufficient validation of untrusted input in Input | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13868 | Chromium: CVE-2026-13868 Inappropriate implementation in Network | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13870 | Chromium: CVE-2026-13870 Use after free in WebView | UNKNOWN | — | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-13878 | Chromium: CVE-2026-13878 Use after free in Bluetooth | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13872 | Chromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13880 | Chromium: CVE-2026-13880 Use after free in USB | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13885 | Chromium: CVE-2026-13885 Use after free in Skia | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-13887 | Chromium: CVE-2026-13887 Insufficient policy enforcement in NFC | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13889 | Chromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthentication | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13904 | Chromium: CVE-2026-13904 Incorrect security UI in Safe Browsing | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-13892 | Chromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13902 | Chromium: CVE-2026-13902 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13905 | Chromium: CVE-2026-13905 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-13914 | Chromium: CVE-2026-13914 Inappropriate implementation in Passwords | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13907 | Chromium: CVE-2026-13907 Inappropriate implementation in iOSWeb | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-13912 | Chromium: CVE-2026-13912 Incorrect security UI in Safe Browsing | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13910 | Chromium: CVE-2026-13910 Insufficient policy enforcement in WebXR | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13913 | Chromium: CVE-2026-13913 Insufficient policy enforcement in Autofill | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13908 | Chromium: CVE-2026-13908 Insufficient validation of untrusted input in Omnibox | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13916 | Chromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13915 | Chromium: CVE-2026-13915 Use after free in Chrome for iOS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13917 | Chromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13923 | Chromium: CVE-2026-13923 Uninitialized Use in GPU | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13926 | Chromium: CVE-2026-13926 Insufficient validation of untrusted input in Network | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13918 | Chromium: CVE-2026-13918 Use after free in Chrome for iOS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13924 | Chromium: CVE-2026-13924 Insufficient validation of untrusted input in WebView | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13929 | Chromium: CVE-2026-13929 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-13932 | Chromium: CVE-2026-13932 Inappropriate implementation in Sharing | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13936 | Chromium: CVE-2026-13936 Inappropriate implementation in Passwords | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13943 | Chromium: CVE-2026-13943 Uninitialized Use in CSS | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13939 | Chromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShare | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13944 | Chromium: CVE-2026-13944 Inappropriate implementation in DataTransfer | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-13946 | Chromium: CVE-2026-13946 Inappropriate implementation in ScriptInjections | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13949 | Chromium: CVE-2026-13949 Insufficient policy enforcement in Payments | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13955 | Chromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabs | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-13927 | Chromium: CVE-2026-13927 Insufficient validation of untrusted input in UI | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13964 | Chromium: CVE-2026-13964 Insufficient policy enforcement in WebView | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13969 | Chromium: CVE-2026-13969 Uninitialized Use in UI | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-13975 | Chromium: CVE-2026-13975 Out of bounds read in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-13974 | Chromium: CVE-2026-13974 Integer overflow in Safe Browsing | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13981 | Chromium: CVE-2026-13981 Inappropriate implementation in Chrome for iOS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13980 | Chromium: CVE-2026-13980 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13987 | Chromium: CVE-2026-13987 Incorrect security UI in Mobile | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-13991 | Chromium: CVE-2026-13991 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13992 | Chromium: CVE-2026-13992 Inappropriate implementation in UI | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-13994 | Chromium: CVE-2026-13994 Inappropriate implementation in Credential Management | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-13995 | Chromium: CVE-2026-13995 Insufficient validation of untrusted input in Autofill | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13983 | Chromium: CVE-2026-13983 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-13997 | Chromium: CVE-2026-13997 Incorrect security UI in Extensions | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-13998 | Chromium: CVE-2026-13998 Incorrect security UI in File Input | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-14005 | Chromium: CVE-2026-14005 Use after free in Omnibox | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14028 | Chromium: CVE-2026-14028 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-14066 | Chromium: CVE-2026-14066 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14067 | Chromium: CVE-2026-14067 Use after free in Chrome for iOS | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-14075 | Chromium: CVE-2026-14075 Policy bypass in Chrome for iOS | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14096 | Chromium: CVE-2026-14096 Object lifecycle issue in Input | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14099 | Chromium: CVE-2026-14099 Use after free in Chrome for iOS | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14101 | Chromium: CVE-2026-14101 Insufficient policy enforcement in Sandbox | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14114 | Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-14123 | Chromium: CVE-2026-14123 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14126 | Chromium: CVE-2026-14126 Incorrect security UI in UI | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14128 | Chromium: CVE-2026-14128 Insufficient data validation in Chrome for iOS | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14136 | Chromium: CVE-2026-14136 Incorrect security UI in Chrome for iOS | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14385 | Chromium: CVE-2026-14385 Heap buffer overflow in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-14137 | Chromium: CVE-2026-14137 Insufficient validation of untrusted input in Chrome for iOS | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14382 | Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14386 | Chromium: CVE-2026-14386 Out of bounds read in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14388 | Chromium: CVE-2026-14388 Out of bounds read in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14390 | Chromium: CVE-2026-14390 Use after free in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14392 | Chromium: CVE-2026-14392 Out of bounds write in Tint | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-14393 | Chromium: CVE-2026-14393 Use after free in V8 | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-14391 | Chromium: CVE-2026-14391 Integer overflow in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14395 | Chromium: CVE-2026-14395 Out of bounds write in V8 | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14396 | Chromium: CVE-2026-14396 Out of bounds read in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14394 | Chromium: CVE-2026-14394 Use after free in V8 | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14398 | Chromium: CVE-2026-14398 Use after free in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14397 | Chromium: CVE-2026-14397 Out of bounds write in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14399 | Chromium: CVE-2026-14399 Uninitialized Use in Dawn | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14401 | Chromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14400 | Chromium: CVE-2026-14400 Out of bounds write in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14403 | Chromium: CVE-2026-14403 Use after free in V8 | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14406 | Chromium: CVE-2026-14406 Out of bounds read in V8 | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14404 | Chromium: CVE-2026-14404 Inappropriate implementation in PDFium | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14402 | Chromium: CVE-2026-14402 Uninitialized Use in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14405 | Chromium: CVE-2026-14405 Uninitialized Use in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-14407 | Chromium: CVE-2026-14407 Inappropriate implementation in V8 | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-14409 | Chromium: CVE-2026-14409 Inappropriate implementation in V8 | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-14408 | Chromium: CVE-2026-14408 Uninitialized Use in Dawn | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14411 | Chromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14410 | Chromium: CVE-2026-14410 Inappropriate implementation in Skia | UNKNOWN | — | 9%ile | Microsoft | 2026-07-14 |
| CVE-2026-14412 | Chromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-14413 | Chromium: CVE-2026-14413 Uninitialized Use in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-14414 | Chromium: CVE-2026-14414 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14415 | Chromium: CVE-2026-14415 Inappropriate implementation in V8 | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14416 | Chromium: CVE-2026-14416 Out of bounds read in Dawn | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14417 | Chromium: CVE-2026-14417 Use after free in Dawn | UNKNOWN | — | 11%ile | Microsoft | 2026-07-14 |
| CVE-2026-14420 | Chromium: CVE-2026-14420 Out of bounds read and write in Dawn | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-14418 | Chromium: CVE-2026-14418 Uninitialized Use in ANGLE | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-14419 | Chromium: CVE-2026-14419 Use after free in Skia | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14422 | Chromium: CVE-2026-14422 Out of bounds read and write in Tint | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-14423 | Chromium: CVE-2026-14423 Type Confusion in Tint | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-14421 | Chromium: CVE-2026-14421 Uninitialized Use in Dawn | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14424 | Chromium: CVE-2026-14424 Use after free in Dawn | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14425 | Chromium: CVE-2026-14425 Use after free in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14426 | Chromium: CVE-2026-14426 Use after free in V8 | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-14427 | Chromium: CVE-2026-14427 Heap buffer overflow in Skia | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14428 | Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14429 | Chromium: CVE-2026-14429 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-14430 | Chromium: CVE-2026-14430 Integer overflow in V8 | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-14432 | Chromium: CVE-2026-14432 Use after free in V8 | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-14431 | Chromium: CVE-2026-14431 Type Confusion in V8 | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-58643 | Windows Admin Center Spoofing Vulnerability | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-15904 | Chromium: CVE-2026-15904 Use after free in Ozone | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-15903 | Chromium: CVE-2026-15903 Out of bounds read and write in V8 | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-15899 | Chromium: CVE-2026-15899 Use after free in CameraCapture | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-15778 | Chromium: CVE-2026-15778 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-15776 | Chromium: CVE-2026-15776 Type Confusion in V8 | UNKNOWN | — | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-15775 | Chromium: CVE-2026-15775 Insufficient policy enforcement in V8 | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-15774 | Chromium: CVE-2026-15774 Use after free in Skia | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-15773 | Chromium: CVE-2026-15773 Use after free in Core | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-15770 | Chromium: CVE-2026-15770 Uninitialized Use in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-15900 | Chromium: CVE-2026-15900 Use after free in GPU | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-15901 | Chromium: CVE-2026-15901 Use after free in Network | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-15765 | Chromium: CVE-2026-15765 Use after free in Ozone | UNKNOWN | — | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-15107 | Chromium: CVE-2026-15107 Use after free in IndexedDB | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-15108 | Chromium: CVE-2026-15108 Integer overflow in Extensions API | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-15109 | Chromium: CVE-2026-15109 Uninitialized Use in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-15115 | Chromium: CVE-2026-15115 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-15113 | Chromium: CVE-2026-15113 Use after free in Autofill | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-15119 | Chromium: CVE-2026-15119 Inappropriate implementation in GetUserMedia | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-15118 | Chromium: CVE-2026-15118 Use after free in Input | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-15117 | Chromium: CVE-2026-15117 Use after free in Payments | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-15116 | Chromium: CVE-2026-15116 Use after free in Actor | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-15114 | Chromium: CVE-2026-15114 Out of bounds read and write in Codecs | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-15112 | Chromium: CVE-2026-15112 Use after free in Ozone | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-15111 | Chromium: CVE-2026-15111 Use after free in Views | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-15129 | Chromium: CVE-2026-15129 Use after free in Views | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-15128 | Chromium: CVE-2026-15128 Inappropriate implementation in Forms | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-15127 | Chromium: CVE-2026-15127 Inappropriate implementation in WebGL | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-15110 | Chromium: CVE-2026-15110 Use after free in Extensions | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-15126 | Chromium: CVE-2026-15126 Use after free in Forms | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-15124 | Chromium: CVE-2026-15124 Insufficient policy enforcement in Passwords | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-15123 | Chromium: CVE-2026-15123 Insufficient data validation in DOM | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-15121 | Chromium: CVE-2026-15121 Use after free in WebRTC | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-15125 | Chromium: CVE-2026-15125 Inappropriate implementation in Forms | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-15122 | Chromium: CVE-2026-15122 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-15120 | Chromium: CVE-2026-15120 Use after free in Core | UNKNOWN | — | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-15133 | Chromium: CVE-2026-15133 Use after free in InterestGroups | UNKNOWN | — | 16%ile | Microsoft | 2026-07-14 |
| CVE-2026-15132 | Chromium: CVE-2026-15132 Uninitialized Use in V8 | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-15130 | Chromium: CVE-2026-15130 Insufficient policy enforcement in Navigation | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-15131 | Chromium: CVE-2026-15131 Insufficient data validation in Navigation | UNKNOWN | — | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-13954 | Chromium: CVE-2026-13954 Insufficient policy enforcement in XML | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13796 | Chromium: CVE-2026-13796 Integer overflow in Chromecast | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13799 | Chromium: CVE-2026-13799 Use after free in QUIC | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13800 | Chromium: CVE-2026-13800 Inappropriate implementation in Updater | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-13806 | Chromium: CVE-2026-13806 Insufficient validation of untrusted input in Accessibility | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13810 | Chromium: CVE-2026-13810 Inappropriate implementation in Input | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-13811 | Chromium: CVE-2026-13811 Use after free in IME | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-13815 | Chromium: CVE-2026-13815 Use after free in Blink | UNKNOWN | — | 32%ile | Microsoft | 2026-07-14 |
| CVE-2026-13818 | Chromium: CVE-2026-13818 Inappropriate implementation in Passwords | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13814 | Chromium: CVE-2026-13814 Use after free in Views | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13817 | Chromium: CVE-2026-13817 Insufficient validation of untrusted input in Glic | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13821 | Chromium: CVE-2026-13821 Use after free in Canvas | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-13820 | Chromium: CVE-2026-13820 Out of bounds read in Skia | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-13823 | Chromium: CVE-2026-13823 Use after free in Glic | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13824 | Chromium: CVE-2026-13824 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13828 | Chromium: CVE-2026-13828 Inappropriate implementation in Enterprise | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-13829 | Chromium: CVE-2026-13829 Insufficient validation of untrusted input in Settings | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13830 | Chromium: CVE-2026-13830 Use after free in Chromoting | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-13831 | Chromium: CVE-2026-13831 Use after free in GPU | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13834 | Chromium: CVE-2026-13834 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-13832 | Chromium: CVE-2026-13832 Use after free in Headless | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13836 | Chromium: CVE-2026-13836 Inappropriate implementation in CSS | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13835 | Chromium: CVE-2026-13835 Inappropriate implementation in XML | UNKNOWN | — | 25%ile | Microsoft | 2026-07-14 |
| CVE-2026-13837 | Chromium: CVE-2026-13837 Inappropriate implementation in CSS | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13838 | Chromium: CVE-2026-13838 Inappropriate implementation in CSS | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13839 | Chromium: CVE-2026-13839 Inappropriate implementation in CSS | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-13840 | Chromium: CVE-2026-13840 Insufficient policy enforcement in Canvas | UNKNOWN | — | 15%ile | Microsoft | 2026-07-14 |
| CVE-2026-13841 | Chromium: CVE-2026-13841 Integer overflow in Skia | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-13844 | Chromium: CVE-2026-13844 Use after free in Updater | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-13845 | Chromium: CVE-2026-13845 Use after free in DOM | UNKNOWN | — | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-15777 | Chromium: CVE-2026-15777 Use after free in UI | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-15772 | Chromium: CVE-2026-15772 Use after free in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-15771 | Chromium: CVE-2026-15771 Insufficient validation of untrusted input in Media | UNKNOWN | — | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-15902 | Chromium: CVE-2026-15902 Use after free in Cast | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-15769 | Chromium: CVE-2026-15769 Insufficient validation of untrusted input in Linux Toolkit Theming | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-15768 | Chromium: CVE-2026-15768 Insufficient policy enforcement in HTML-in-Canvas | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-15766 | Chromium: CVE-2026-15766 Uninitialized Use in Skia | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-15764 | Chromium: CVE-2026-15764 Use after free in Ozone | UNKNOWN | — | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-13283 | Chromium: CVE-2026-13282: Use after free in Payments | UNKNOWN | — | 14%ile | Microsoft | 2026-07-14 |
| CVE-2026-13282 | Chromium: CVE-2026-13282 Use after free in AdFilter | UNKNOWN | — | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-15905 | Chromium: CVE-2026-15905 Use after free in Aura | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-16420 | Chromium: CVE-2026-16420 Type Confusion in WebAudio | UNKNOWN | — | 30%ile | Microsoft | 2026-07-14 |
| CVE-2026-16807 | Chromium: CVE-2026-16807 Out of bounds write in Codecs | UNKNOWN | — | 18%ile | Microsoft | 2026-07-14 |
| CVE-2026-55952 | TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension | UNKNOWN | — | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-54886 | SSH SFTP server denial of service via extended channel data infinite loop | UNKNOWN | — | 26%ile | Microsoft | 2026-07-14 |
| CVE-2026-56000 | xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() | UNKNOWN | — | 13%ile | Microsoft | 2026-07-14 |
| CVE-2026-56288 | NULL Pointer Dereference in GNU patch | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-40468 | Heap buffer overflow in gawk | UNKNOWN | — | 10%ile | Microsoft | 2026-07-14 |
| CVE-2026-26197 | Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c | UNKNOWN | — | 19%ile | Microsoft | 2026-07-14 |
| CVE-2026-53910 | Heap-based Buffer Overflow in GNU diffutils | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-50252 | Possible cache poisoning attack by mapping source port population per thread | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-50243 | 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-15788 | WCOW cache mount source selector resolves NTFS junctions outside of cache root | UNKNOWN | — | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-44509 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a | UNKNOWN | — | — | Microsoft | 2026-07-14 |
| CVE-2026-59676 | Local File Deletion Attack Vector in rm_rf() in seunshare | UNKNOWN | — | 0%ile | Microsoft | 2026-07-14 |
| CVE-2026-59677 | Process Kill Attack Vector in killall() in seunshare | UNKNOWN | — | 1%ile | Microsoft | 2026-07-14 |
| CVE-2026-44210 | Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations | UNKNOWN | — | 24%ile | Microsoft | 2026-07-14 |
| CVE-2026-9079 | stale proxy password leak | UNKNOWN | — | 45%ile | Microsoft | 2026-07-14 |
| CVE-2026-54891 | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-56289 | Loop with Unreachable Exit Condition in GNU patch | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-14461 | Out-of-bound read in mtr | UNKNOWN | — | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-40553 | Stack-based buffer overflow in gawk | UNKNOWN | — | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-40469 | Heap buffer overflow in gawk | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-40467 | Use after free in gawk | UNKNOWN | — | 12%ile | Microsoft | 2026-07-14 |
| CVE-2026-57215 | RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom | UNKNOWN | — | 31%ile | Microsoft | 2026-07-14 |
| CVE-2026-45784 | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-26199 | Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero | UNKNOWN | — | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-56392 | Heap-based Buffer Overflow in GNU coreutils | UNKNOWN | — | 5%ile | Microsoft | 2026-07-14 |
| CVE-2026-64247 | KVM: x86: hyper-v: Bound the bank index when querying sparse banks | UNKNOWN | — | 2%ile | Microsoft | 2026-07-14 |
| CVE-2026-45480 | Azure Active Directory Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 60%ile | Microsoft | 2026-06-09 |
| CVE-2026-47647 | Dynamics 365 Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-48584 | Microsoft Azure Synapse Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-54130 | M365 Copilot Information Disclosure Vulnerability | CRITICAL | 9.8 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability | CRITICAL | 9.8 | 96%ile | Microsoft | 2026-06-09 |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98%ile | Microsoft | 2026-06-09 |
| CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability | CRITICAL | 9.8 | 78%ile | Microsoft | 2026-06-09 |
| CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability | CRITICAL | 9.8 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability | CRITICAL | 9.8 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-52931 | batman-adv: tp_meter: avoid use of uninit sender vars | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-54906 | concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-52934 | batman-adv: tvlv: reject oversized TVLV packets | CRITICAL | 9.8 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-52947 | net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove | CRITICAL | 9.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52919 | batman-adv: fix tp_meter counter underflow during shutdown | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52922 | batman-adv: dat: handle forward allocation error | CRITICAL | 9.8 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-48582 | Microsoft Exchange Online Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-44631 | Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow | CRITICAL | 9.4 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2025-10263 | ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] | CRITICAL | 9.3 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-47646 | Dynamics 365 Customer Voice Spoofing Vulnerability | CRITICAL | 9.3 | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability | CRITICAL | 9.1 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-48579 | Microsoft Exchange Online Information Disclosure Vulnerability | CRITICAL | 9.1 | 60%ile | Microsoft | 2026-06-09 |
| CVE-2026-12087 | Socket versions before 2.041 for Perl have an out-of-bounds heap read | CRITICAL | 9.1 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-34182 | CMS AuthEnvelopedData Processing May Accept Forged Messages | CRITICAL | 9.1 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-53176 | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN | CRITICAL | 9.1 | 51%ile | Microsoft | 2026-06-09 |
| CVE-2026-32208 | Microsoft Entra ID Spoofing Vulnerability | HIGH | 8.8 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | HIGH | 8.8 | 63%ile | Microsoft | 2026-06-09 |
| CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-06-09 |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability | HIGH | 8.8 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability | HIGH | 8.8 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability | HIGH | 8.8 | 98%ile | Microsoft | 2026-06-09 |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 67%ile | Microsoft | 2026-06-09 |
| CVE-2026-47645 | Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-48715 | radvdump's Route Information Option Parser has a Stack Buffer Overflow | HIGH | 8.8 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-6893 | Dracut: dracut: root code execution via dhcp options command injection | HIGH | 8.8 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-9698 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer | HIGH | 8.8 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-10879 | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders | HIGH | 8.6 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-29167 | Apache HTTP Server: mod_ldap per-dir use-after-free | HIGH | 8.6 | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability | HIGH | 8.4 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability | HIGH | 8.4 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.4 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.4 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability | HIGH | 8.4 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability | HIGH | 8.4 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability | HIGH | 8.4 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | HIGH | 8.4 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-50521 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.2 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability | HIGH | 8.2 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability | HIGH | 8.2 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-49759 | Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash | HIGH | 8.2 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-57236 | Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception | HIGH | 8.2 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-57235 | Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` | HIGH | 8.2 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability | HIGH | 8.1 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.1 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability | HIGH | 8.1 | 67%ile | Microsoft | 2026-06-09 |
| CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability | HIGH | 8.1 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability | HIGH | 8.1 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability | HIGH | 8.1 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability | HIGH | 8.1 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution | HIGH | 8.1 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-56123 | socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser | HIGH | 8.1 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-7383 | Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion | HIGH | 8.1 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-11816 | Path Traversal in keras-team/keras | HIGH | 8.1 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.0 | 48%ile | Microsoft | 2026-06-09 |
| CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability | HIGH | 8.0 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 60%ile | Microsoft | 2026-06-09 |
| CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 60%ile | Microsoft | 2026-06-09 |
| CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability | HIGH | 7.9 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-8863 | UEFI Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-50656 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95%ile | Microsoft | 2026-06-09 |
| CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2026-06-09 |
| CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-50511 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-50512 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 79%ile | Microsoft | 2026-06-09 |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 79%ile | Microsoft | 2026-06-09 |
| CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability | HIGH | 7.8 | 81%ile | Microsoft | 2026-06-09 |
| CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-43958 | Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service | HIGH | 7.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-50256 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfo | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-50258 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shif | HIGH | 7.8 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-46301 | spi: topcliff-pch: fix use-after-free on unbind | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-11822 | SQLite before 3.53.2 Memory Corruption in FTS5 Extension | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-12505 | Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-52912 | netfilter: nf_queue: hold bridge skb->dev while queued | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-52943 | net: skbuff: fix missing zerocopy reference in pskb_carve helpers | HIGH | 7.8 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-52926 | batman-adv: clear current gateway during teardown | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-55895 | Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-55693 | Vim: Out-of-bounds Write in Spell File Word Count | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57455 | Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57456 | Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-46243 | smb: client: reject userspace cifs.spnego descriptions | HIGH | 7.8 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-11332 | Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution | HIGH | 7.8 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-50261 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-50259 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths in | HIGH | 7.8 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-46274 | io-wq: check that the predecessor is hashed in io_wq_remove_pending() | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11824 | SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate | HIGH | 7.8 | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-52923 | ipc: limit next_id allocation to the valid ID range | HIGH | 7.8 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53143 | drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 | HIGH | 7.8 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-32174 | Azure Bot Service Elevation of Privilege Vulnerability | HIGH | 7.7 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-45497 | Microsoft M365 Copilot Remote Code Execution Vulnerability | HIGH | 7.7 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-47633 | Microsoft Cost Management Information Disclosure Vulnerability | HIGH | 7.5 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH | 7.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | HIGH | 7.5 | 55%ile | Microsoft | 2026-06-09 |
| CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability | HIGH | 7.5 | 48%ile | Microsoft | 2026-06-09 |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 83%ile | Microsoft | 2026-06-09 |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 99%ile | Microsoft | 2026-06-09 |
| CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | HIGH | 7.5 | 55%ile | Microsoft | 2026-06-09 |
| CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 7.5 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | 98%ile | Microsoft | 2026-06-09 |
| CVE-2026-42536 | Apache HTTP Server: mod_xml2enc heap overflow | HIGH | 7.5 | 59%ile | Microsoft | 2026-06-09 |
| CVE-2026-45445 | AES-OCB IV Ignored on EVP_Cipher() Path | HIGH | 7.5 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-42764 | NULL Pointer Dereference in QUIC Server Initial Packet Handling | HIGH | 7.5 | 64%ile | Microsoft | 2026-06-09 |
| CVE-2026-9675 | undici WebSocket client vulnerable to denial of service via cumulative fragment bypass | HIGH | 7.5 | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-57435 | Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=` | HIGH | 7.5 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-50031 | ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Manag | HIGH | 7.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-37460 | Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all | HIGH | 7.5 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-8829 | HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities | HIGH | 7.5 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-42535 | Apache HTTP Server: mod_dav_fs protected directory access | HIGH | 7.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-34356 | Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow | HIGH | 7.5 | 50%ile | Microsoft | 2026-06-09 |
| CVE-2026-34355 | Apache HTTP Server: mod_proxy_html buffer overflow | HIGH | 7.5 | 63%ile | Microsoft | 2026-06-09 |
| CVE-2026-34183 | Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler | HIGH | 7.5 | 61%ile | Microsoft | 2026-06-09 |
| CVE-2026-9076 | Out-of-Bounds Read in CMS Password-Based Decryption | HIGH | 7.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-34180 | Heap Buffer Over-read in ASN.1 Content Parsing | HIGH | 7.5 | 60%ile | Microsoft | 2026-06-09 |
| CVE-2026-12143 | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection) | HIGH | 7.5 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-57434 | Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes | HIGH | 7.5 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-34181 | PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys | HIGH | 7.4 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-9697 | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | HIGH | 7.4 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-50292 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properti | HIGH | 7.4 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability | HIGH | 7.3 | 49%ile | Microsoft | 2026-06-09 |
| CVE-2026-11463 | USCiLab Cereal Shared Pointer type confusion | HIGH | 7.3 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-48913 | Apache HTTP Server: mod_http2 memory corruption when file handles exhausted | HIGH | 7.3 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-44185 | Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` | HIGH | 7.3 | 50%ile | Microsoft | 2026-06-09 |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability | HIGH | 7.1 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution | HIGH | 7.1 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.1 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-46285 | mtd: docg3: fix use-after-free in docg3_release() | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-46320 | tap: free page on error paths in tap_get_user_xdp() | HIGH | 7.1 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-53689 | CVE-2026-53689 | HIGH | 7.1 | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-53212 | netfilter: nft_tunnel: fix use-after-free on object destroy | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53137 | drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size | HIGH | 7.1 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-53230 | net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52918 | Bluetooth: serialize accept_q access | HIGH | 7.1 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-52942 | netfilter: nf_log: validate MAC header was set before dumping it | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53186 | RDMA/srp: bound SRP_RSP sense copy by the received length | HIGH | 7.1 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-53268 | netfilter: conntrack_irc: fix possible out-of-bounds read | HIGH | 7.1 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-53253 | Bluetooth: bnep: reject short frames before parsing | HIGH | 7.1 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-46293 | clk: microchip: mpfs-ccc: fix out of bounds access during output registration | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53270 | ipvs: clear the svc scheduler ptr early on edit | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52917 | sctp: diag: reject stale associations in dump_one path | HIGH | 7.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53265 | dm cache policy smq: check allocation under invalidate lock | HIGH | 7.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-46244 | netfilter: nft_inner: Fix IPv6 inner_thoff desync | HIGH | 7.0 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-46275 | Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths | HIGH | 7.0 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-46319 | net/sched: act_ct: Only release RCU read lock after ct_ft | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53239 | xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53254 | Bluetooth: RFCOMM: validate skb length in MCC handlers | HIGH | 7.0 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-53267 | netfilter: nft_ct: bail out on template ct in get eval | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53249 | ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53218 | netfilter: nft_exthdr: fix register tracking for F_PRESENT flag | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53228 | ipv6: sit: reload inner IPv6 header after GSO offloads | HIGH | 7.0 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-46306 | flow_dissector: do not dissect PPPoE PFC frames | HIGH | 7.0 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-53242 | ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53236 | tcp: restrict SO_ATTACH_FILTER to priv users | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53264 | net/sched: act_api: use RCU with deferred freeing for action lifecycle | HIGH | 7.0 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-53182 | wifi: nl80211: reject oversized EMA RNR lists | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52924 | sctp: purge outqueue on stale COOKIE-ECHO handling | HIGH | 7.0 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-53150 | thunderbolt: Reject zero-length property entries in validator | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53209 | Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53275 | ipv6: mcast: Fix use-after-free when processing MLD queries | HIGH | 7.0 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-53133 | RDMA/umem: Fix truncation for block sizes >= 4G | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53148 | thunderbolt: Clamp XDomain response data copy to allocation size | HIGH | 7.0 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53168 | fuse: reject fuse_notify() pagecache ops on directories | HIGH | 7.0 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-56411 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. | MEDIUM | 6.9 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-56410 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. | MEDIUM | 6.9 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability | MEDIUM | 6.8 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 91%ile | Microsoft | 2026-06-09 |
| CVE-2026-53266 | netfilter: bridge: make ebt_snat ARP rewrite writable | MEDIUM | 6.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-50260 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() | MEDIUM | 6.6 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-50257 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() | MEDIUM | 6.6 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-46323 | net: gro: don't merge zcopy skbs | MEDIUM | 6.6 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-42014 | Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin | MEDIUM | 6.6 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-57438 | Nokogiri: Possible Use-After-Free in XInclude Processing | MEDIUM | 6.6 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-47644 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-06-09 |
| CVE-2026-47655 | Microsoft Graph Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-42895 | Microsoft Copilot Tampering Vulnerability | MEDIUM | 6.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-47287 | Visual Studio Code Tampering Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2026-06-09 |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability | MEDIUM | 6.5 | 95%ile | Microsoft | 2026-06-09 |
| CVE-2026-50519 | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability | MEDIUM | 6.5 | 74%ile | Microsoft | 2026-06-09 |
| CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-06-09 |
| CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-06-09 |
| CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability | MEDIUM | 6.5 | 54%ile | Microsoft | 2026-06-09 |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability | MEDIUM | 6.5 | 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-56409 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. | MEDIUM | 6.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-9539 | libslirp TCP URG OOB Read Information Leak | MEDIUM | 6.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-57453 | Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction | MEDIUM | 6.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-27145 | Inefficient candidate hostname parsing in crypto/x509 | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-46433 | lldpd: Heap OOB Read in VLAN Decapsulation memmove | MEDIUM | 6.5 | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-43951 | Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash | MEDIUM | 6.5 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-44186 | Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp | MEDIUM | 6.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-48858 | ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks | MEDIUM | 6.5 | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-48856 | httpc leaks Authorization header to cross-origin redirect targets | MEDIUM | 6.5 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-48860 | Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist | MEDIUM | 6.5 | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-48855 | SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-53146 | thunderbolt: Limit XDomain response copy to actual frame size | MEDIUM | 6.5 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-13201 | Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and n | MEDIUM | 6.3 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-45491 | .NET Tampering Vulnerability | MEDIUM | 6.2 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM | 6.1 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-57454 | Vim: Out-of-bounds Read with Text Properties | MEDIUM | 6.1 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46322 | tun: free page on build_skb failure in tun_xdp_one() | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-29170 | Apache HTTP Server: mod_proxy_ftp XSS | MEDIUM | 6.1 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-44889 | WebOb: Location header normalization during redirect leads to open redirect | MEDIUM | 6.1 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-42766 | Possible NULL Dereference in Password-Based CMS Decryption | MEDIUM | 5.9 | 59%ile | Microsoft | 2026-06-09 |
| CVE-2026-42767 | NULL Pointer Dereference in CRMF EncryptedValue Decryption | MEDIUM | 5.9 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-54411 | Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-passwor | MEDIUM | 5.9 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-12725 | Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies | MEDIUM | 5.9 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-44821 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability | MEDIUM | 5.5 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-45647 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-42915 | Microsoft Windows VMSwitch Denial of Service Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-50262 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-50263 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-46280 | lib: test_hmm: evict device pages on file close to avoid use-after-free | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-46312 | media: videobuf2: Set vma_flags in vb2_dma_sg_mmap | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46296 | spi: s3c64xx: fix NULL-deref on driver unbind | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46287 | net: txgbe: fix RTNL assertion warning when remove module | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46299 | hfsplus: fix held lock freed on hfsplus_fill_super() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-46321 | tun: free page on short-frame rejection in tun_xdp_one() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53213 | drm/vc4: fix krealloc() memory leak | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53147 | thunderbolt: Validate XDomain request packet size before type cast | MEDIUM | 5.5 | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-53274 | net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52915 | netfilter: ip6t_hbh: reject oversized option lists | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52916 | batman-adv: frag: disallow unicast fragment in fragment | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-54905 | concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-53177 | bnxt_en: Fix NULL pointer dereference | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53214 | ipv6: Fix a potential NPD in cleanup_prefix_route() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52929 | sctp: stream: fully roll back denied add-stream state | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-53190 | drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52927 | netfilter: ebtables: fix OOB read in compat_mtw_from_user | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53219 | netfilter: x_tables: avoid leaking percpu counter pointers | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57452 | Vim: Out-of-bounds Read with libsodium-encrypted Files | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53221 | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-55892 | Vim: Out-of-bounds Write in Spell File Prefix Dump | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53154 | mm/hugetlb: restore reservation on error in hugetlb folio copy paths | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-52941 | net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53263 | 6lowpan: fix off-by-one in multicast context address compression | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46273 | ibmveth: Disable GSO for packets with small MSS | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-46289 | lib/scatterlist: fix length calculations in extract_kvec_to_sg | MEDIUM | 5.5 | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-46307 | wifi: ath5k: do not access array OOB | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-46292 | pmdomain: core: Fix detach procedure for virtual devices in genpd | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46291 | crypto: caam - guard HMAC key hex dumps in hash_digest_key | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-46304 | nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-46303 | isofs: validate Rock Ridge CE continuation extent against volume size | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-44119 | Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-49760 | Stack Buffer Overflow in ei_s_print_term at Very Large Integer | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-4367 | Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53227 | net: openvswitch: fix possible kfree_skb of ERR_PTR | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53207 | mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-52921 | netfilter: ipset: stop hash:* range iteration at end | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53149 | thunderbolt: Bound root directory content to block size | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53181 | vsock/vmci: fix sk_ack_backlog leak on failed handshake | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53184 | udp: clear skb->dev before running a sockmap verdict | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-52960 | ceph: put folios not suitable for writeback | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-53255 | Bluetooth: MGMT: validate advertising TLV before type checks | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53237 | gpio: mvebu: fix NULL pointer dereference in suspend/resume | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53225 | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-53245 | net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53199 | hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-53183 | mptcp: allow subflow rcv wnd to shrink | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-06-09 |
| CVE-2026-52930 | ipc/shm: serialize orphan cleanup with shm_nattch updates | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53135 | drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53080 | net/sched: cls_fw: fix NULL dereference of "old" filters before change() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-53252 | Bluetooth: fix memory leak in error path of hci_alloc_dev() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-53655 | node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation di | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability | MEDIUM | 5.4 | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 5.4 | 57%ile | Microsoft | 2026-06-09 |
| CVE-2026-40930 | LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body | MEDIUM | 5.4 | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability | MEDIUM | 5.3 | 53%ile | Microsoft | 2026-06-09 |
| CVE-2026-57436 | Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type | MEDIUM | 5.3 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-42507 | Arbitrary inputs are included in errors without any escaping in net/textproto | MEDIUM | 5.3 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-50265 | Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292 | MEDIUM | 5.3 | — | Microsoft | 2026-06-09 |
| CVE-2026-12969 | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation | MEDIUM | 5.3 | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-57437 | Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime | MEDIUM | 5.3 | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-57451 | Vim: Out-of-bounds Read in Text Property Count | MEDIUM | 5.3 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability | MEDIUM | 5.0 | 97%ile | Microsoft | 2026-06-09 |
| CVE-2026-55655 | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client ve | MEDIUM | 5.0 | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-10275 | OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow | MEDIUM | 5.0 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-50219 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars | MEDIUM | 4.9 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-45446 | Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes | MEDIUM | 4.8 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability | MEDIUM | 4.7 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-46250 | MIPS: Work around LLVM bug when gp is used as global register variable | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability | MEDIUM | 4.3 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-55653 | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validati | MEDIUM | 4.3 | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-53238 | netlabel: validate unlabeled address and mask attribute lengths | MEDIUM | 4.3 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-11526 | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments | MEDIUM | 4.2 | 69%ile | Microsoft | 2026-06-09 |
| CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability | LOW | 3.9 | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-46272 | coresight: tmc-etr: Fix race condition between sysfs and perf mode | LOW | 3.9 | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-5419 | Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal | LOW | 3.7 | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-42768 | Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() | LOW | 3.7 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-45485 | Microsoft Office Information Disclosure Vulnerability | LOW | 3.3 | 36%ile | Microsoft | 2026-06-09 |
| CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability | LOW | 3.3 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability | LOW | 3.3 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability | LOW | 3.3 | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10722 | cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow | LOW | 3.3 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-49356 | Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core | LOW | 3.2 | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-57234 | Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247 | LOW | 2.6 | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-10984 | Chromium: CVE-2026-10984 Inappropriate implementation in Accessibility | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11291 | Chromium: CVE-2026-11291 Policy bypass in Android Autofill | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11178 | Chromium: CVE-2026-11178 Policy bypass in WebView | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-12012 | Chromium: CVE-2026-12012 Use after free Network | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-12008 | Chromium: CVE-2026-12008 Use after free DigitalCredentials | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-10881 | Chromium: CVE-2026-10881 Out of bounds read and write in ANGLE | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10884 | Chromium: CVE-2026-10884 Use after free in Chromecast | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10887 | Chromium: CVE-2026-10887 Use after free in Chromoting | UNKNOWN | — | 33%ile | Microsoft | 2026-06-09 |
| CVE-2026-10888 | Chromium: CVE-2026-10888 Use after free in Cast Streaming | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-10889 | Chromium: CVE-2026-10889 Out of bounds read in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10890 | Chromium: CVE-2026-10890 Use after free in Cast | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-10895 | Chromium: CVE-2026-10895 Use after free in Ozone | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10897 | Chromium: CVE-2026-10897 Out of bounds write in GPU | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10898 | Chromium: CVE-2026-10898 Stack buffer overflow in GPU | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10899 | Chromium: CVE-2026-10899 Use after free in Ozone | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10900 | Chromium: CVE-2026-10900 Use after free in Passwords | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10903 | Chromium: CVE-2026-10903 Use after free in WebRTC | UNKNOWN | — | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-10908 | Chromium: CVE-2026-10908 Use after free in FullScreen | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10909 | Chromium: CVE-2026-10909 Use after free in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10910 | Chromium: CVE-2026-10910 Type Confusion in V8 | UNKNOWN | — | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-10911 | Chromium: CVE-2026-10911 Insufficient validation of untrusted input in Media | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10912 | Chromium: CVE-2026-10912 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-10914 | Chromium: CVE-2026-10914 Use after free in ANGLE | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10916 | Chromium: CVE-2026-10916 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-10918 | Chromium: CVE-2026-10918 Use after free in Viz | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10919 | Chromium: CVE-2026-10919 Use after free in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10921 | Chromium: CVE-2026-10921 Integer overflow in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10922 | Chromium: CVE-2026-10922 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10924 | Chromium: CVE-2026-10924 Integer overflow in Chromecast | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10925 | Chromium: CVE-2026-10925 Out of bounds write in Skia | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10927 | Chromium: CVE-2026-10927 Out of bounds read in Dawn | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10928 | Chromium: CVE-2026-10928 Script injection in Headless | UNKNOWN | — | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-10931 | Chromium: CVE-2026-10931 Use after free in FileSystem | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10932 | Chromium: CVE-2026-10932 Use after free in UI | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-10933 | Chromium: CVE-2026-10933 Use after free in Audio | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-10935 | Chromium: CVE-2026-10935 Inappropriate implementation in V8 | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10936 | Chromium: CVE-2026-10936 Type Confusion in V8 | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10939 | Chromium: CVE-2026-10939 Use after free in WebRTC | UNKNOWN | — | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-10940 | Chromium: CVE-2026-10940 Race in Codecs | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-10941 | Chromium: CVE-2026-10941 Out of bounds memory access in Skia | UNKNOWN | — | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-10942 | Chromium: CVE-2026-10942 Insufficient validation of untrusted input in UI | UNKNOWN | — | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-10943 | Chromium: CVE-2026-10943 Use after free in WebRTC | UNKNOWN | — | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-10946 | Chromium: CVE-2026-10946 Heap buffer overflow in Media | UNKNOWN | — | 30%ile | Microsoft | 2026-06-09 |
| CVE-2026-10947 | Chromium: CVE-2026-10947 Use after free in WebRTC | UNKNOWN | — | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-10949 | Chromium: CVE-2026-10949 Heap buffer overflow in Video | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10954 | Chromium: CVE-2026-10954 Use after free in Actor | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10956 | Chromium: CVE-2026-10956 Use after free in MimeHandlerView | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10957 | Chromium: CVE-2026-10957 Use after free in Glic | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10960 | Chromium: CVE-2026-10960 Uninitialized Use in Codecs | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10962 | Chromium: CVE-2026-10962 Type Confusion in Media | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10964 | Chromium: CVE-2026-10964 Integer overflow in V8 | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10965 | Chromium: CVE-2026-10965 Integer overflow in DevTools | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10966 | Chromium: CVE-2026-10966 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-10969 | Chromium: CVE-2026-10969 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10970 | Chromium: CVE-2026-10970 Insufficient validation of untrusted input in InterestGroups | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10971 | Chromium: CVE-2026-10971 Insufficient validation of untrusted input in Printing | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10972 | Chromium: CVE-2026-10972 Use after free in Ozone | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10973 | Chromium: CVE-2026-10973 Uninitialized Use in Dawn | UNKNOWN | — | 59%ile | Microsoft | 2026-06-09 |
| CVE-2026-10974 | Chromium: CVE-2026-10974 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10975 | Chromium: CVE-2026-10975 Use after free in WebRTC | UNKNOWN | — | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-10976 | Chromium: CVE-2026-10976 Uninitialized Use in Dawn | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10977 | Chromium: CVE-2026-10977 Uninitialized Use in Skia | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10978 | Chromium: CVE-2026-10978 Use after free in Chromoting | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10981 | Chromium: CVE-2026-10981 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10982 | Chromium: CVE-2026-10982 Use after free in WebXR | UNKNOWN | — | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-10983 | Chromium: CVE-2026-10983 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10989 | Chromium: CVE-2026-10989 Inappropriate implementation in V8 | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10990 | Chromium: CVE-2026-10990 Use after free in Glic | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10991 | Chromium: CVE-2026-10991 Use after free in V8 | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10992 | Chromium: CVE-2026-10992 Insufficient data validation in Animation | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10993 | Chromium: CVE-2026-10993 Heap buffer overflow in Skia | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10994 | Chromium: CVE-2026-10994 Uninitialized Use in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10995 | Chromium: CVE-2026-10995 Heap buffer overflow in TabStrip | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-10996 | Chromium: CVE-2026-10996 Inappropriate implementation in Workers | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-10997 | Chromium: CVE-2026-10997 Insufficient policy enforcement in Extensions | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-10998 | Chromium: CVE-2026-10998 Out of bounds read in Media | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11000 | Chromium: CVE-2026-11000 Use after free in Fonts | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11006 | Chromium: CVE-2026-11006 Out of bounds read in Dawn | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11008 | Chromium: CVE-2026-11008 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11009 | Chromium: CVE-2026-11009 Use after free in USB | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-11013 | Chromium: CVE-2026-11013 Insufficient validation of untrusted input in Network | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11015 | Chromium: CVE-2026-11015 Out of bounds read in WebGPU | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11016 | Chromium: CVE-2026-11016 Insufficient validation of untrusted input in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11020 | Chromium: CVE-2026-11020 Inappropriate implementation in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11021 | Chromium: CVE-2026-11021 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-11022 | Chromium: CVE-2026-11022 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11024 | Chromium: CVE-2026-11024 Stack buffer overflow in Skia | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-11028 | Chromium: CVE-2026-11028 Use after free in Media | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11033 | Chromium: CVE-2026-11033 Uninitialized Use in WebML | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11036 | Chromium: CVE-2026-11036 Inappropriate implementation in DOM | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11037 | Chromium: CVE-2026-11037 Out of bounds write in Codecs | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11038 | Chromium: CVE-2026-11038 Insufficient validation of untrusted input in Subresource Integrity | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11040 | Chromium: CVE-2026-11040 Use after free in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11041 | Chromium: CVE-2026-11041 Insufficient validation of untrusted input in Media | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11044 | Chromium: CVE-2026-11044 Integer overflow in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11046 | Chromium: CVE-2026-11046 Insufficient validation of untrusted input in Media | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11047 | Chromium: CVE-2026-11047 Insufficient validation of untrusted input in Base | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-11048 | Chromium: CVE-2026-11048 Inappropriate implementation in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11049 | Chromium: CVE-2026-11049 Use after free in Password Manager | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11050 | Chromium: CVE-2026-11050 Use after free in V8 | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11051 | Chromium: CVE-2026-11051 Out of bounds read in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11052 | Chromium: CVE-2026-11052 Type Confusion in GPU | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11053 | Chromium: CVE-2026-11053 VULNERABILITY in WebRTC | UNKNOWN | — | — | Microsoft | 2026-06-09 |
| CVE-2026-11055 | Chromium: CVE-2026-11055 Use after free in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11056 | Chromium: CVE-2026-11056 Insufficient validation of untrusted input in SiteIsolation | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11057 | Chromium: CVE-2026-11057 Uninitialized Use in Skia | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11058 | Chromium: CVE-2026-11058 Integer overflow in CredentialProvider | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11059 | Chromium: CVE-2026-11059 Use after free in Blink | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11060 | Chromium: CVE-2026-11060 Use after free in Media | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11061 | Chromium: CVE-2026-11061 Out of bounds read in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11067 | Chromium: CVE-2026-11067 Uninitialized Use in Dawn | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11069 | Chromium: CVE-2026-11069 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11074 | Chromium: CVE-2026-11074 Use after free in WebRTC | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-11075 | Chromium: CVE-2026-11075 Out of bounds read in V8 | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11076 | Chromium: CVE-2026-11076 Type Confusion in CSS | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11078 | Chromium: CVE-2026-11078 Insufficient validation of untrusted input in FileSystem | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11079 | Chromium: CVE-2026-11079 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11081 | Chromium: CVE-2026-11081 Policy bypass in Canvas | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11084 | Chromium: CVE-2026-11084 Inappropriate implementation in Password Manager | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11086 | Chromium: CVE-2026-11086 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11087 | Chromium: CVE-2026-11087 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11088 | Chromium: CVE-2026-11088 Integer overflow in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11089 | Chromium: CVE-2026-11089 Uninitialized Use in Media | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11090 | Chromium: CVE-2026-11090 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11093 | Chromium: CVE-2026-11093 Insufficient validation of untrusted input in Printing | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11095 | Chromium: CVE-2026-11095 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11096 | Chromium: CVE-2026-11096 Out of bounds read in WebRTC | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11098 | Chromium: CVE-2026-11098 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11099 | Chromium: CVE-2026-11099 Vulnerability in Skia | UNKNOWN | — | — | Microsoft | 2026-06-09 |
| CVE-2026-11100 | Chromium: CVE-2026-11100 Use after free in File Input | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11101 | Chromium: CVE-2026-11101 Uninitialized Use in Dawn | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11102 | Chromium: CVE-2026-11102 Inappropriate implementation in Isolated Web Apps | UNKNOWN | — | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-11103 | Chromium: CVE-2026-11103 Inappropriate implementation in Installer | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11105 | Chromium: CVE-2026-11105 Insufficient validation of untrusted input in WebUI | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11106 | Chromium: CVE-2026-11106 Inappropriate implementation in Media | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11107 | Chromium: CVE-2026-11107 Inappropriate implementation in Downloads | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11109 | Chromium: CVE-2026-11109 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11111 | Chromium: CVE-2026-11111 Out of bounds read in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11113 | Chromium: CVE-2026-11113 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11114 | Chromium: CVE-2026-11114 Use after free in Device Trust | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11122 | Chromium: CVE-2026-11122 Inappropriate implementation in Keyboard | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11123 | Chromium: CVE-2026-11123 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11125 | Chromium: CVE-2026-11125 Use after free in Compositing | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11126 | Chromium: CVE-2026-11126 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11128 | Chromium: CVE-2026-11128 Insufficient validation of untrusted input in Web Share | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11129 | Chromium: CVE-2026-11129 Inappropriate implementation in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11133 | Chromium: CVE-2026-11133 Insufficient policy enforcement in Paint | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11132 | Chromium: CVE-2026-11132 Policy bypass in Paint | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11130 | Chromium: CVE-2026-11130 Use after free in Media | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11134 | Chromium: CVE-2026-11134 Insufficient data validation in Media | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11135 | Chromium: CVE-2026-11135 Insufficient policy enforcement in Autofill | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11136 | Chromium: CVE-2026-11136 Use after free in Canvas | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11137 | Chromium: CVE-2026-11137 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11140 | Chromium: CVE-2026-11140 Insufficient validation of untrusted input in Chromecast | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11139 | Chromium: CVE-2026-11139 Policy bypass in Paint | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11138 | Chromium: CVE-2026-11138 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11146 | Chromium: CVE-2026-11146 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11147 | Chromium: CVE-2026-11147 Use after free in WebML | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-11141 | Chromium: CVE-2026-11141 Uninitialized Use in Audio | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11143 | Chromium: CVE-2026-11143 Heap buffer overflow in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11144 | Chromium: CVE-2026-11144 Use after free in Media | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11142 | Chromium: CVE-2026-11142 Policy bypass in Paint | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11149 | Chromium: CVE-2026-11149 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11150 | Chromium: CVE-2026-11150 Inappropriate implementation in XML | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11151 | Chromium: CVE-2026-11151 Insufficient validation of untrusted input in Password Manager | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11153 | Chromium: CVE-2026-11153 Side-channel information leakage in Forms | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11152 | Chromium: CVE-2026-11152 Object lifecycle issue in Dawn | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11154 | Chromium: CVE-2026-11154 Use after free in Dawn | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11155 | Chromium: CVE-2026-11155 Insufficient policy enforcement in CSS | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11156 | Chromium: CVE-2026-11156 Inappropriate implementation in CSS | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11157 | Chromium: CVE-2026-11157 Script injection in Accessibility | UNKNOWN | — | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-11159 | Chromium: CVE-2026-11159 Uninitialized Use in Skia | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11160 | Chromium: CVE-2026-11160 Out of bounds read in Input | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11158 | Chromium: CVE-2026-11158 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11161 | Chromium: CVE-2026-11161 Insufficient data validation in DataTransfer | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11162 | Chromium: CVE-2026-11162 Insufficient policy enforcement in CSS | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11168 | Chromium: CVE-2026-11168 Insufficient policy enforcement in Extensions | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11169 | Chromium: CVE-2026-11169 Inappropriate implementation in XML | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11164 | Chromium: CVE-2026-11164 Use after free in Blink | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11166 | Chromium: CVE-2026-11166 Inappropriate implementation in SVG | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11170 | Chromium: CVE-2026-11170 Inappropriate implementation in Chromoting | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11171 | Chromium: CVE-2026-11171 Integer overflow in Blink | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11174 | Chromium: CVE-2026-11174 Insufficient policy enforcement in Site Isolation | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11176 | Chromium: CVE-2026-11176 Inappropriate implementation in Media | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11173 | Chromium: CVE-2026-11173 Out of bounds write in V8 | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11177 | Chromium: CVE-2026-11177 Use after free in Omnibox | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11179 | Chromium: CVE-2026-11179 Inappropriate implementation in ORB | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11180 | Chromium: CVE-2026-11180 Policy bypass in SVG | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11182 | Chromium: CVE-2026-11182 Inappropriate implementation in SVG | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11184 | Chromium: CVE-2026-11184 Insufficient policy enforcement in Actor | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11181 | Chromium: CVE-2026-11181 Inappropriate implementation in Media Session | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11185 | Chromium: CVE-2026-11185 Use after free in V8 | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11186 | Chromium: CVE-2026-11186 Inappropriate implementation in CSS | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11187 | Chromium: CVE-2026-11187 Insufficient policy enforcement in Glic | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11192 | Chromium: CVE-2026-11192 Insufficient validation of untrusted input in Password Manager | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11189 | Chromium: CVE-2026-11189 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11191 | Chromium: CVE-2026-11191 Out of bounds memory access in ANGLE | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11190 | Chromium: CVE-2026-11190 Insufficient policy enforcement in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11193 | Chromium: CVE-2026-11193 Insufficient policy enforcement in Password Manager | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11194 | Chromium: CVE-2026-11194 Inappropriate implementation in Network | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11196 | Chromium: CVE-2026-11196 Type Confusion in XML | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11195 | Chromium: CVE-2026-11195 Inappropriate implementation in MHTML | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11197 | Chromium: CVE-2026-11197 Insufficient policy enforcement in Workers | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11198 | Chromium: CVE-2026-11198 Insufficient validation of untrusted input in Codecs | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11199 | Chromium: CVE-2026-11199 Insufficient validation of untrusted input in WebRTC | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11201 | Chromium: CVE-2026-11201 Use after free in ServiceWorker | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11203 | Chromium: CVE-2026-11203 Policy bypass in GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11200 | Chromium: CVE-2026-11200 Inappropriate implementation in WebRTC | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11207 | Chromium: CVE-2026-11207 Insufficient validation of untrusted input in Autofill | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11206 | Chromium: CVE-2026-11206 Policy bypass in ServiceWorker | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11208 | Chromium: CVE-2026-11208 Use after free in Codecs | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11209 | Chromium: CVE-2026-11209 Insufficient policy enforcement in Passwords | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11210 | Chromium: CVE-2026-11210 Insufficient policy enforcement in Safe Browsing | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11211 | Chromium: CVE-2026-11211 Integer overflow in V8 | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11212 | Chromium: CVE-2026-11212 Insufficient policy enforcement in DevTools | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11213 | Chromium: CVE-2026-11213 Insufficient validation of untrusted input in Reading Mode | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11216 | Chromium: CVE-2026-11216 Incorrect security UI in File Input | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11217 | Chromium: CVE-2026-11217 Insufficient policy enforcement in Fenced Frames | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11218 | Chromium: CVE-2026-11218 Inappropriate implementation in PlatformIntegration | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11219 | Chromium: CVE-2026-11219 Insufficient data validation in Navigation | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11221 | Chromium: CVE-2026-11221 Insufficient validation of untrusted input in PointerLock | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11220 | Chromium: CVE-2026-11220 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11222 | Chromium: CVE-2026-11222 Incorrect security UI in Tab Strip | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11223 | Chromium: CVE-2026-11223 Insufficient validation of untrusted input in Network | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11224 | Chromium: CVE-2026-11224 Use after free in Chromoting | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11229 | Chromium: CVE-2026-11229 Insufficient policy enforcement in Enterprise | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11230 | Chromium: CVE-2026-11230 Use after free in Extensions | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11231 | Chromium: CVE-2026-11231 Inappropriate implementation in Safe Browsing | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11225 | Chromium: CVE-2026-11225 Incorrect security UI in WebUI | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11228 | Chromium: CVE-2026-11228 Incorrect security UI in File Input | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11227 | Chromium: CVE-2026-11227 Incorrect security UI in Tab Hover Cards | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11232 | Chromium: CVE-2026-11232 Inappropriate implementation in TabGroups | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11233 | Chromium: CVE-2026-11233 Insufficient validation of untrusted input in FoldableAPIs | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11234 | Chromium: CVE-2026-11234 Insufficient policy enforcement in FoldableAPIs | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11238 | Chromium: CVE-2026-11238 Inappropriate implementation in DevTools | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11235 | Chromium: CVE-2026-11235 Insufficient validation of untrusted input in Compositing | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11237 | Chromium: CVE-2026-11237 Insufficient validation of untrusted input in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11236 | Chromium: CVE-2026-11236 Insufficient policy enforcement in Web Bluetooth | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11239 | Chromium: CVE-2026-11239 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11240 | Chromium: CVE-2026-11240 Insufficient validation of untrusted input in Loader | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11244 | Chromium: CVE-2026-11244 Insufficient validation of untrusted input in WebAuthentication | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11242 | Chromium: CVE-2026-11242 Insufficient validation of untrusted input in Plugins | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11243 | Chromium: CVE-2026-11243 Incorrect security UI in Downloads | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11241 | Chromium: CVE-2026-11241 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-11245 | Chromium: CVE-2026-11245 Inappropriate implementation in Payments | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11249 | Chromium: CVE-2026-11249 Use after free in Network | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11251 | Chromium: CVE-2026-11251 Insufficient validation of untrusted input in Password Manager | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11250 | Chromium: CVE-2026-11250 Inappropriate implementation in DevTools | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11248 | Chromium: CVE-2026-11248 Policy bypass in Google Lens | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11252 | Chromium: CVE-2026-11252 Policy bypass in Content Settings | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11246 | Chromium: CVE-2026-11246 Insufficient validation of untrusted input in IndexedDB | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11253 | Chromium: CVE-2026-11253 Race in Permissions | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11254 | Chromium: CVE-2026-11254 Inappropriate implementation in Permissions | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11255 | Chromium: CVE-2026-11255 Insufficient validation of untrusted input in Storage Access API | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11257 | Chromium: CVE-2026-11257 Inappropriate implementation in Browser | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11256 | Chromium: CVE-2026-11256 Out of bounds read in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11258 | Chromium: CVE-2026-11258 Inappropriate implementation in File System Access | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11259 | Chromium: CVE-2026-11259 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11260 | Chromium: CVE-2026-11260 Policy bypass in Permissions | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11261 | Chromium: CVE-2026-11261 Insufficient validation of untrusted input in PDF | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11262 | Chromium: CVE-2026-11262 Use after free in TabStrip | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11265 | Chromium: CVE-2026-11265 Insufficient data validation in Autofill | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11264 | Chromium: CVE-2026-11264 Policy bypass in Content Security Policy | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11266 | Chromium: CVE-2026-11266 Policy bypass in SafeBrowsing | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11267 | Chromium: CVE-2026-11267 Insufficient policy enforcement in Extensions | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11268 | Chromium: CVE-2026-11268 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11269 | Chromium: CVE-2026-11269 Inappropriate implementation in Extensions | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11271 | Chromium: CVE-2026-11271 Incorrect security UI in Passwords | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11273 | Chromium: CVE-2026-11273 Insufficient validation of untrusted input in Omnibox | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11012 | Chromium: CVE-2026-11012 Use after free in Serial | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11029 | Chromium: CVE-2026-11029 Insufficient validation of untrusted input in Drag and Drop | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11045 | Chromium: CVE-2026-11045 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11065 | Chromium: CVE-2026-11065 Use after free in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-11072 | Chromium: CVE-2026-11072 Use after free in WebView | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11080 | Chromium: CVE-2026-11080 Use after free in WebView | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11082 | Chromium: CVE-2026-11082 Use after free in GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11108 | Chromium: CVE-2026-11108 Inappropriate implementation in NFC | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11119 | Chromium: CVE-2026-11119 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11131 | Chromium: CVE-2026-11131 Use after free in Autofill | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11145 | Chromium: CVE-2026-11145 Race in Geolocation | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11148 | Chromium: CVE-2026-11148 Inappropriate implementation in Payments | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11175 | Chromium: CVE-2026-11175 Incorrect security UI in Messages | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11188 | Chromium: CVE-2026-11188 Use after free in USB | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11226 | Chromium: CVE-2026-11226 Insufficient policy enforcement in PreviewTab | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11263 | Chromium: CVE-2026-11263 Insufficient policy enforcement in WebAuthentication | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11287 | Chromium: CVE-2026-11287 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11295 | Chromium: CVE-2026-11295 Inappropriate implementation in WebView | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-12019 | Chromium: CVE-2026-12019 Out of bounds write Codecs | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-12016 | Chromium: CVE-2026-12016 Insufficient validation of untrusted input DevTools | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-12015 | Chromium: CVE-2026-12015 Use after free Autofill | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11628 | Chromium: CVE-2026-11628 Use after free in Ozone | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11629 | Chromium: CVE-2026-11629 Use after free in Ozone | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11631 | Chromium: CVE-2026-11631 Use after free in Aura | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11630 | Chromium: CVE-2026-11630 Use after free in File Input | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11632 | Chromium: CVE-2026-11632 Use after free in TabStrip | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11633 | Chromium: CVE-2026-11633 Use after free in Bluetooth | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11634 | Chromium: CVE-2026-11634 Use after free in Gamepad | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11635 | Chromium: CVE-2026-11635 Use after free in Bluetooth | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11639 | Chromium: CVE-2026-11639 Use after free in Compositing | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11637 | Chromium: CVE-2026-11637 Use after free in Views | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11636 | Chromium: CVE-2026-11636 Use after free in Autofill | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11638 | Chromium: CVE-2026-11638 Use after free in Printing | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11641 | Chromium: CVE-2026-11641 Use after free in Bluetooth | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11640 | Chromium: CVE-2026-11640 Integer overflow in libyuv | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11642 | Chromium: CVE-2026-11642 Use after free in Web Apps | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11645 | Chromium: CVE-2026-11645 Out of bounds memory access in V8 | UNKNOWN | — | 81%ile | Microsoft | 2026-06-09 |
| CVE-2026-11643 | Chromium: CVE-2026-11643 Use after free in Proxy | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11644 | Chromium: CVE-2026-11644 Use after free in Views | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11646 | Chromium: CVE-2026-11646 Use after free in ViewTransitions | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11658 | Chromium: CVE-2026-11657 Use after free in Payments | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11659 | Chromium: CVE-2026-11658 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11661 | Chromium: CVE-2026-11660 Insufficient validation of untrusted input in New Tab Page | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11662 | Chromium: CVE-2026-11661 Use after free in Views | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-11660 | Chromium: CVE-2026-11659 Insufficient validation of untrusted input in UI | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11664 | Chromium: CVE-2026-11663 Use after free in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11663 | Chromium: CVE-2026-11662 Type Confusion in Bindings | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11665 | Chromium: CVE-2026-11664 Use after free in Payments | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11666 | Chromium: CVE-2026-11665 Out of bounds read in Dawn | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11667 | Chromium: CVE-2026-11666 Insufficient validation of untrusted input in Input | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11669 | Chromium: CVE-2026-11668 Uninitialized Use in Codecs | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11670 | Chromium: CVE-2026-11669 Integer overflow in Media | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11668 | Chromium: CVE-2026-11667 Out of bounds read in WebRTC | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11671 | Chromium: CVE-2026-11670 Use after free in PDF | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11672 | Chromium: CVE-2026-11671 Use after free in Navigation | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11673 | Chromium: CVE-2026-11672 Out of bounds write in GPU | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11674 | Chromium: CVE-2026-11673 Use after free in InterestGroups | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11676 | Chromium: CVE-2026-11675 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11675 | Chromium: CVE-2026-11674 Use after free in Guest View | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11677 | Chromium: CVE-2026-11676 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11678 | Chromium: CVE-2026-11677 Race in Network | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11679 | Chromium: CVE-2026-11678 Integer overflow in libyuv | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11680 | Chromium: CVE-2026-11679 Use after free in Codecs | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11682 | Chromium: CVE-2026-11681 Use after free in Ozone | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11683 | Chromium: CVE-2026-11682 Insufficient validation of untrusted input in Views | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11681 | Chromium: CVE-2026-11680 Use after free in Media | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11684 | Chromium: CVE-2026-11683 Use after free in WebCodecs | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11685 | Chromium: CVE-2026-11684 Insufficient policy enforcement in Network | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11688 | Chromium: CVE-2026-11687 Use after free in Dawn | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11687 | Chromium: CVE-2026-11686 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11689 | Chromium: CVE-2026-11688 Object lifecycle issue in SVG | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11686 | Chromium: CVE-2026-11685 Insufficient data validation in MediaCapture | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11690 | Chromium: CVE-2026-11689 Insufficient validation of untrusted input in Passwords | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11691 | Chromium: CVE-2026-11690 Out of bounds read and write in Media | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11692 | Chromium: CVE-2026-11691 Insufficient validation of untrusted input in New Tab Page | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11693 | Chromium: CVE-2026-11692 Use after free in Read Anything | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11694 | Chromium: CVE-2026-11693 Inappropriate implementation in Plugins | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11695 | Chromium: CVE-2026-11694 Use after free in ServiceWorker | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11696 | Chromium: CVE-2026-11695 Inappropriate implementation in Passwords | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11697 | Chromium: CVE-2026-11696 Uninitialized Use in Video | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11698 | Chromium: CVE-2026-11697 Insufficient validation of untrusted input in UI | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11699 | Chromium: CVE-2026-11698 Use after free in Bluetooth | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11700 | Chromium: CVE-2026-11699 Use after free in Bluetooth | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11701 | Chromium: CVE-2026-11700 Use after free in Tracing | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-13027 | Chromium: CVE-2026-13027 Use after free in FileSystem | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-13026 | Chromium: CVE-2026-13026 Use after free in Digital Credentials | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-13025 | Chromium: CVE-2026-13025 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-13024 | Chromium: CVE-2026-13024 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-13023 | Chromium: CVE-2026-13023 Uninitialized Use in GPU | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-13022 | Chromium: CVE-2026-13022 Inappropriate implementation in Autofill | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-13021 | Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentials | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-10882 | Chromium: CVE-2026-10882 Use after free in Network | UNKNOWN | — | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-10886 | Chromium: CVE-2026-10886 Use after free in FileSystem | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10891 | Chromium: CVE-2026-10891 Use after free in GFX | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10893 | Chromium: CVE-2026-10893 Use after free in Chromoting | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10894 | Chromium: CVE-2026-10894 Use after free in Printing | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10901 | Chromium: CVE-2026-10901 Use after free in Passwords | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10902 | Chromium: CVE-2026-10902 Use after free in Ozone | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10904 | Chromium: CVE-2026-10904 Inappropriate implementation in V8 | UNKNOWN | — | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-10905 | Chromium: CVE-2026-10905 Use after free in Network | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10906 | Chromium: CVE-2026-10906 Use after free in WebAuthentication | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10907 | Chromium: CVE-2026-10907 Out of bounds write in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10913 | Chromium: CVE-2026-10913 Use after free in ANGLE | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10917 | Chromium: CVE-2026-10917 Insufficient validation of untrusted input in Media | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10920 | Chromium: CVE-2026-10920 Insufficient validation of untrusted input in WebShare | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10926 | Chromium: CVE-2026-10926 Use after free in Cast | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-10930 | Chromium: CVE-2026-10930 Out of bounds read in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-10937 | Chromium: CVE-2026-10937 Inappropriate implementation in Passwords | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-10938 | Chromium: CVE-2026-10938 Insufficient validation of untrusted input in Input | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-10945 | Chromium: CVE-2026-10945 Use after free in PDF | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10948 | Chromium: CVE-2026-10948 Use after free in WebRTC | UNKNOWN | — | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-10955 | Chromium: CVE-2026-10955 Type Confusion in ANGLE | UNKNOWN | — | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-10963 | Chromium: CVE-2026-10963 Integer overflow in V8 | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10968 | Chromium: CVE-2026-10968 Insufficient validation of untrusted input in Dawn | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10979 | Chromium: CVE-2026-10979 Out of bounds read in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10980 | Chromium: CVE-2026-10980 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10985 | Chromium: CVE-2026-10985 Out of bounds read in Skia | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10986 | Chromium: CVE-2026-10986 Integer overflow in Media | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10987 | Chromium: CVE-2026-10987 Integer overflow in V8 | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10988 | Chromium: CVE-2026-10988 Use after free in Views | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10999 | Chromium: CVE-2026-10999 Out of bounds memory access in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11001 | Chromium: CVE-2026-11001 Incorrect security UI in Payments | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11002 | Chromium: CVE-2026-11002 Use after free in Autofill | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11003 | Chromium: CVE-2026-11003 Use after free in WebRTC | UNKNOWN | — | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-11004 | Chromium: CVE-2026-11004 Out of bounds read in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11005 | Chromium: CVE-2026-11005 Out of bounds read in ANGLE | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11011 | Chromium: CVE-2026-11011 Insufficient policy enforcement in Password Manager | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11014 | Chromium: CVE-2026-11014 Insufficient policy enforcement in Extensions | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11017 | Chromium: CVE-2026-11017 Inappropriate implementation in Link Preview | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11018 | Chromium: CVE-2026-11018 Insufficient policy enforcement in Actor | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11023 | Chromium: CVE-2026-11023 Insufficient validation of untrusted input in WebAppInstalls | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11025 | Chromium: CVE-2026-11025 Insufficient policy enforcement in Navigation | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11026 | Chromium: CVE-2026-11026 Insufficient policy enforcement in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11027 | Chromium: CVE-2026-11027 Insufficient validation of untrusted input in Glic | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11030 | Chromium: CVE-2026-11030 Use after free in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11031 | Chromium: CVE-2026-11031 Insufficient validation of untrusted input in Password Manager | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11032 | Chromium: CVE-2026-11032 Insufficient data validation in Password Manager | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11039 | Chromium: CVE-2026-11039 Uninitialized Use in Skia | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11042 | Chromium: CVE-2026-11042 Use after free in Views | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-11043 | Chromium: CVE-2026-11043 Out of bounds write in ANGLE | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-11054 | Chromium: CVE-2026-11054 Use after free in WebRTC | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-11062 | Chromium: CVE-2026-11062 Insufficient policy enforcement in Extensions | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-11063 | Chromium: CVE-2026-11063 Insufficient validation of untrusted input in WebNN | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11066 | Chromium: CVE-2026-11066 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11068 | Chromium: CVE-2026-11068 Use after free in WebSockets | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-11070 | Chromium: CVE-2026-11070 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11071 | Chromium: CVE-2026-11071 Use after free in Base | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11073 | Chromium: CVE-2026-11073 Use after free in WebGL | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11083 | Chromium: CVE-2026-11083 Inappropriate implementation in Password Manager | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11085 | Chromium: CVE-2026-11085 Integer overflow in GPU | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11091 | Chromium: CVE-2026-11091 Inappropriate implementation in Dawn | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11092 | Chromium: CVE-2026-11092 Insufficient policy enforcement in DevTools | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11094 | Chromium: CVE-2026-11094 Use after free in Codecs | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11104 | Chromium: CVE-2026-11104 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11110 | Chromium: CVE-2026-11110 Uninitialized Use in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11112 | Chromium: CVE-2026-11112 Insufficient validation of untrusted input in Chromoting | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-11115 | Chromium: CVE-2026-11115 Use after free in Updater | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11116 | Chromium: CVE-2026-11116 Use after free in Chromoting | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11117 | Chromium: CVE-2026-11117 Use after free in Views | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11118 | Chromium: CVE-2026-11118 Use after free in WebRTC | UNKNOWN | — | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-11120 | Chromium: CVE-2026-11120 Insufficient validation of untrusted input in Enterprise Reporting | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11121 | Chromium: CVE-2026-11121 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11124 | Chromium: CVE-2026-11124 Heap buffer overflow in Skia | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11275 | Chromium: CVE-2026-11275 Insufficient policy enforcement in Page Info | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11276 | Chromium: CVE-2026-11276 Inappropriate implementation in Cast | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11283 | Chromium: CVE-2026-11283 Policy bypass in Shortcuts | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11284 | Chromium: CVE-2026-11284 Side-channel information leakage in PerformanceAPIs | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11282 | Chromium: CVE-2026-11282 Policy bypass in Sandbox | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11281 | Chromium: CVE-2026-11281 Integer overflow in Chromoting | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11279 | Chromium: CVE-2026-11279 Out of bounds read in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11286 | Chromium: CVE-2026-11286 Insufficient validation of untrusted input in Wallet | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11288 | Chromium: CVE-2026-11288 Policy bypass in CSS | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11292 | Chromium: CVE-2026-11292 Policy bypass in Blink | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11289 | Chromium: CVE-2026-11289 Side-channel information leakage in Paint | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11294 | Chromium: CVE-2026-11294 Inappropriate implementation in Passwords | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11293 | Chromium: CVE-2026-11293 Use after free in Input | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11296 | Chromium: CVE-2026-11296 Inappropriate implementation in ImageCapture | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-11299 | Chromium: CVE-2026-11299 Out of bounds read in Fonts | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-11300 | Chromium: CVE-2026-11300 Inappropriate implementation in Permissions | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11301 | Chromium: CVE-2026-11301 Out of bounds read in LiveCaption | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-11303 | Chromium: CVE-2026-11303 Use after free in PDFium | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11304 | Chromium: CVE-2026-11304 Use after free in PDFium | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11305 | Chromium: CVE-2026-11305 Use after free in PDFium | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11306 | Chromium: CVE-2026-11306 Use after free in PDFium | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11309 | Chromium: CVE-2026-11309 Insufficient policy enforcement in History | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-11308 | Chromium: CVE-2026-11308 Inappropriate implementation in Extensions | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-11307 | Chromium: CVE-2026-11307 Use after free in PDFium | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11297 | Chromium: CVE-2026-11297 Insufficient validation of untrusted input in Reader Mode | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-10883 | Chromium: CVE-2026-10883 Out of bounds write in ANGLE | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-10892 | Chromium: CVE-2026-10892 Out of bounds write in GPU | UNKNOWN | — | 25%ile | Microsoft | 2026-06-09 |
| CVE-2026-10923 | Chromium: CVE-2026-10923 Use after free in WebAppInstalls | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-10929 | Chromium: CVE-2026-10929 Heap buffer overflow in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-10934 | Chromium: CVE-2026-10934 Use after free in Autofill | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-10953 | Chromium: CVE-2026-10953 Use after free in Core | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-10959 | Chromium: CVE-2026-10959 Use after free in Input | UNKNOWN | — | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-10967 | Chromium: CVE-2026-10967 Use after free in SurfaceCapture | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-11007 | Chromium: CVE-2026-11007 Insufficient validation of untrusted input in WebView | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-11010 | Chromium: CVE-2026-11010 Use after free in WebShare | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-11019 | Chromium: CVE-2026-11019 Inappropriate implementation in Payments | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11034 | Chromium: CVE-2026-11034 Insufficient validation of untrusted input in Tab Group Sync | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11064 | Chromium: CVE-2026-11064 Uninitialized Use in GPU | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11077 | Chromium: CVE-2026-11077 Out of bounds read in Dawn | UNKNOWN | — | 20%ile | Microsoft | 2026-06-09 |
| CVE-2026-11127 | Chromium: CVE-2026-11127 Inappropriate implementation in WebAPKs | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-11163 | Chromium: CVE-2026-11163 Use after free in Messages | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11167 | Chromium: CVE-2026-11167 Inappropriate implementation in WebView | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11172 | Chromium: CVE-2026-11172 Incorrect security UI in Contact Picker | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11215 | Chromium: CVE-2026-11215 Inappropriate implementation in Cronet | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-11247 | Chromium: CVE-2026-11247 Insufficient policy enforcement in CustomTabs | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-11270 | Chromium: CVE-2026-11270 Inappropriate implementation in UI | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-11278 | Chromium: CVE-2026-11278 Inappropriate implementation in CustomTabs | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-11290 | Chromium: CVE-2026-11290 Integer overflow in WebView | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11035 | Chromium: CVE-2026-11035 Insufficient validation of untrusted input in Custom Tabs | UNKNOWN | — | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-11097 | Chromium: CVE-2026-11097 Inappropriate implementation in WebView | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-12018 | Chromium: CVE-2026-12018 Inappropriate implementation Mojo | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-12007 | Chromium: CVE-2026-12007 Use after free Core | UNKNOWN | — | 21%ile | Microsoft | 2026-06-09 |
| CVE-2026-12017 | Chromium: CVE-2026-12017 Insufficient validation of untrusted input Extensions | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-12014 | Chromium: CVE-2026-12014 Use after free Cast | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-12013 | Chromium: CVE-2026-12013 Use after free Media | UNKNOWN | — | — | Microsoft | 2026-06-09 |
| CVE-2026-12010 | Chromium: CVE-2026-12010 Heap buffer overflow GPU | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-12009 | Chromium: CVE-2026-12009 Insufficient validation of untrusted input Accessibility | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-11648 | Chromium: CVE-2026-11647 Use after free in Printing | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-11649 | Chromium: CVE-2026-11648 Use after free in FullScreen | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11652 | Chromium: CVE-2026-11651 Use after free in Network | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11650 | Chromium: CVE-2026-11649 Use after free in V8 | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-11653 | Chromium: CVE-2026-11652 Use after free in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-11651 | Chromium: CVE-2026-11650 Use after free in V8 | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-11654 | Chromium: CVE-2026-11653 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11655 | Chromium: CVE-2026-11654 Use after free in CameraCapture | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-11657 | Chromium: CVE-2026-11656 Use after free in ServiceWorker | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-11656 | Chromium: CVE-2026-11655 Integer overflow in Media | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-12439 | Chromium: CVE-2026-12439 Use after free in Digital Credentials | UNKNOWN | — | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-12440 | Chromium: CVE-2026-12440 Use after free in DigitalCredentials | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-12445 | Chromium: CVE-2026-12445 Use after free in Extensions | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-12446 | Chromium: CVE-2026-12446 Insufficient data validation in Passwords | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-12451 | Chromium: CVE-2026-12451 Use after free in DigitalCredentials | UNKNOWN | — | 7%ile | Microsoft | 2026-06-09 |
| CVE-2026-12441 | Chromium: CVE-2026-12441 Use after free in File Input | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-12447 | Chromium: CVE-2026-12447 Heap buffer overflow in WebRTC | UNKNOWN | — | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-12443 | Chromium: CVE-2026-12443 Use after free in Web Authentication | UNKNOWN | — | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-12452 | Chromium: CVE-2026-12452 Use after free in Downloads | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-12453 | Chromium: CVE-2026-12453 Insufficient validation of untrusted input in Input | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-12455 | Chromium: CVE-2026-12455 Use after free in Tab Strip | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-12456 | Chromium: CVE-2026-12456 Insufficient validation of untrusted input in Extensions | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12458 | Chromium: CVE-2026-12458 Incorrect security UI in Passwords | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-12457 | Chromium: CVE-2026-12457 Insufficient data validation in Extensions | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12459 | Chromium: CVE-2026-12459 Inappropriate implementation in Serial | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-12460 | Chromium: CVE-2026-12460 Insufficient policy enforcement in File System Access | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-12462 | Chromium: CVE-2026-12462 Use after free in Media | UNKNOWN | — | 19%ile | Microsoft | 2026-06-09 |
| CVE-2026-12464 | Chromium: CVE-2026-12464 Use after free in Browser | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-12463 | Chromium: CVE-2026-12463 Inappropriate implementation in Views | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-12465 | Chromium: CVE-2026-12465 Insufficient validation of untrusted input in Metrics | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-12454 | Chromium: CVE-2026-12454 Race in Safe Browsing | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12467 | Chromium: CVE-2026-12467 Use after free in Extensions | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-12468 | Chromium: CVE-2026-12468 Inappropriate implementation in Updater | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12449 | Chromium: CVE-2026-12449 Use after free in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-06-09 |
| CVE-2026-12444 | Chromium: CVE-2026-12444 Out of bounds read in Chromoting | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-12437 | Chromium: CVE-2026-12437 Use after free in WebShare | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-12461 | Chromium: CVE-2026-12461 Out of bounds read in WebRTC | UNKNOWN | — | 15%ile | Microsoft | 2026-06-09 |
| CVE-2026-12466 | Chromium: CVE-2026-12466 Heap buffer overflow in WebRTC | UNKNOWN | — | 35%ile | Microsoft | 2026-06-09 |
| CVE-2026-13036 | Chromium: CVE-2026-13036 Use after free in Blink | UNKNOWN | — | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-13035 | Chromium: CVE-2026-13035 Use after free in Bluetooth | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-13034 | Chromium: CVE-2026-13034 Inappropriate implementation in Passwords | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-13033 | Chromium: CVE-2026-13033 Out of bounds read in Blink>InterestGroups | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-13031 | Chromium: CVE-2026-13031 Use after free in Blink | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-13029 | Chromium: CVE-2026-13029 Use after free in Web Authentication | UNKNOWN | — | 6%ile | Microsoft | 2026-06-09 |
| CVE-2026-12028 | Chromium: CVE-2026-12028 Use after free GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-06-09 |
| CVE-2026-11647 | Chromium: CVE-2026-11647 Use after free in Printing | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-12030 | Chromium: CVE-2026-12031 Inappropriate implementation Views | UNKNOWN | — | 9%ile | Microsoft | 2026-06-09 |
| CVE-2026-12032 | Chromium: CVE-2026-12032 Inappropriate implementation Passwords | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-12438 | Chromium: CVE-2026-12438 Inappropriate implementation in WebView | UNKNOWN | — | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-12469 | Chromium: CVE-2026-12469 Uninitialized Use in GPU | UNKNOWN | — | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-12448 | Chromium: CVE-2026-12448 Inappropriate implementation in WebView | UNKNOWN | — | 17%ile | Microsoft | 2026-06-09 |
| CVE-2026-12442 | Chromium: CVE-2026-12442 Use after free in Passwords | UNKNOWN | — | 32%ile | Microsoft | 2026-06-09 |
| CVE-2026-12011 | Chromium: CVE-2026-12011 Use after free WebMIDI | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-13038 | Chromium: CVE-2026-13038 Use after free in Autofill | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-46643 | Snappy: Binary path is never shell-escaped due to an inverted is_executable check | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-47162 | Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-48854 | Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-9669 | bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow | UNKNOWN | — | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-12003 | CPython >3.11 Insecure Input Validation resulting in privilege escalation | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-47242 | Net::IMAP: Command Injection via ID command argument | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-8643 | pip can extract console_scripts and gui_scripts outside installation directory | UNKNOWN | — | 24%ile | Microsoft | 2026-06-09 |
| CVE-2026-3276 | Potential DoS via quadratic complexity in unicodedata.normalize() | UNKNOWN | — | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-7774 | tarfile.data_filter path traversal bypass allows writing outside the extraction directory | UNKNOWN | — | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-49762 | Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service | UNKNOWN | — | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-10846 | Insufficient verification that responses belong to a query | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-46683 | Snappy: SSRF and local file read via the xsl-style-sheet option | UNKNOWN | — | 16%ile | Microsoft | 2026-06-09 |
| CVE-2026-52860 | Vim: Arbitrary Code Execution via Python Omni-Completion | UNKNOWN | — | 13%ile | Microsoft | 2026-06-09 |
| CVE-2026-52859 | Vim: Out-of-bounds Read in Terminal Screen Snapshot | UNKNOWN | — | 23%ile | Microsoft | 2026-06-09 |
| CVE-2026-47167 | Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-52858 | Vim: Arbitrary Code Execution via Python Omni-Completion | UNKNOWN | — | 10%ile | Microsoft | 2026-06-09 |
| CVE-2026-44705 | tmp: Path Traversal via unsanitized prefix/postfix enables directory escape | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-43973 | gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion | UNKNOWN | — | 31%ile | Microsoft | 2026-06-09 |
| CVE-2026-47240 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | UNKNOWN | — | 40%ile | Microsoft | 2026-06-09 |
| CVE-2026-49851 | Mistune: Potential DoS via quadratic-time parsing in parse_link_text | UNKNOWN | — | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-11979 | Stack-Based Buffer Overflow in libxml2 | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution Vulnerability | CRITICAL | 10.0 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-23652 | Microsoft Power Pages Remote Code Execution Vulnerability | CRITICAL | 10.0 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-47280 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-42826 | Azure DevOps Information Disclosure Vulnerability | CRITICAL | 10.0 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-41104 | Microsoft Planetary Computer Pro Information Disclosure Vulnerability | CRITICAL | 10.0 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-42901 | Microsoft Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-7374 | Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability | CRITICAL | 9.9 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-33109 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 9.9 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-40411 | Azure Virtual Network Gateway Remote Code Execution Vulnerability | CRITICAL | 9.9 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-42898 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | CRITICAL | 9.9 | 65%ile | Microsoft | 2026-05-12 |
| CVE-2026-42823 | Azure Logic Apps Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-31705 | ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment | CRITICAL | 9.8 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-33278 | Possible arbitrary code execution during DNSSEC validation | CRITICAL | 9.8 | 67%ile | Microsoft | 2026-05-12 |
| CVE-2026-39824 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2025-71305 | drm/display/dp_mst: Add protection against 0 vcpi | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-31718 | ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger | CRITICAL | 9.8 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-45899 | ext4: drop extent cache when splitting extent fails | CRITICAL | 9.8 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-41089 | Windows Netlogon Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-41096 | Windows DNS Client Remote Code Execution Vulnerability | CRITICAL | 9.8 | 78%ile | Microsoft | 2026-05-12 |
| CVE-2026-41615 | Microsoft Authenticator Information Disclosure Vulnerability | CRITICAL | 9.6 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-33823 | Microsoft Team Events Portal Information Disclosure Vulnerability | CRITICAL | 9.6 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-35428 | Azure Cloud Shell Spoofing Vulnerability | CRITICAL | 9.6 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-43870 | Apache Thrift: Node.js web_server.js multi-vulnerability | CRITICAL | 9.4 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-40379 | Azure Entra ID Spoofing Vulnerability | CRITICAL | 9.3 | 56%ile | Microsoft | 2026-05-12 |
| CVE-2026-41090 | Microsoft Copilot Tampering Vulnerability | CRITICAL | 9.3 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-40402 | Windows Hyper-V Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-39834 | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-39833 | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent | CRITICAL | 9.1 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-42508 | Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts | CRITICAL | 9.1 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-42496 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dire | CRITICAL | 9.1 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-8450 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() | CRITICAL | 9.1 | 70%ile | Microsoft | 2026-05-12 |
| CVE-2026-39832 | Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent | CRITICAL | 9.1 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-33843 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-33117 | Azure SDK for Java Security Feature Bypass Vulnerability | CRITICAL | 9.1 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-41103 | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 92%ile | Microsoft | 2026-05-12 |
| CVE-2026-42833 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | CRITICAL | 9.1 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-33844 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 9.0 | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-31706 | ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() | HIGH | 8.8 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-31709 | smb: client: validate the whole DACL before rewriting it in cifsacl | HIGH | 8.8 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-43249 | 9p/xen: protect xen_9pfs_front_free against concurrent calls | HIGH | 8.8 | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-6473 | PostgreSQL server undersizes allocations, via integer wraparound | HIGH | 8.8 | 60%ile | Microsoft | 2026-05-12 |
| CVE-2026-6637 | PostgreSQL refint allows stack buffer overflow and SQL injection | HIGH | 8.8 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-6477 | PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory | HIGH | 8.8 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-43490 | ksmbd: validate inherited ACE SID length | HIGH | 8.8 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-43048 | HID: core: Mitigate potential OOB by removing bogus memset() | HIGH | 8.8 | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | HIGH | 8.8 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-24072 | Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr | HIGH | 8.8 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-31717 | ksmbd: validate owner of durable handle on reconnect | HIGH | 8.8 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-6475 | PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice | HIGH | 8.8 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-32207 | Azure Machine Learning Notebook Spoofing Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-35430 | Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability | HIGH | 8.8 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-34329 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 8.8 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-35439 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 79%ile | Microsoft | 2026-05-12 |
| CVE-2026-41094 | Microsoft Data Formulator Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-33110 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 78%ile | Microsoft | 2026-05-12 |
| CVE-2026-33112 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 86%ile | Microsoft | 2026-05-12 |
| CVE-2026-40357 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2026-05-12 |
| CVE-2026-40365 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2026-05-12 |
| CVE-2026-40370 | SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-40403 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 8.8 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-35436 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 8.8 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-40420 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 8.8 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-41613 | Visual Studio Code Elevation of Privilege Vulnerability | HIGH | 8.8 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-45495 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-41086 | Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability | HIGH | 8.8 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-35435 | Azure AI Foundry Elevation of Privilege Vulnerability | HIGH | 8.6 | 64%ile | Microsoft | 2026-05-12 |
| CVE-2026-43493 | crypto: pcrypt - Fix handling of MAY_BACKLOG requests | HIGH | 8.4 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-4892 | CVE-2026-4892 | HIGH | 8.4 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-40363 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-40364 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 90%ile | Microsoft | 2026-05-12 |
| CVE-2026-40366 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-40358 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-40361 | Microsoft Outlook and Word Remote Code Execution Vulnerability | HIGH | 8.4 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-40367 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-31712 | ksmbd: require minimum ACE size in smb_check_perm_dacl() | HIGH | 8.3 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-35438 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 8.3 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-42013 | Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name | HIGH | 8.2 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-5260 | Gnutls: gnutls: information disclosure via heap overread in rsa key exchange | HIGH | 8.2 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-33833 | Azure Machine Learning Notebook Spoofing Vulnerability | HIGH | 8.2 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-34327 | Microsoft Partner Center Spoofing Vulnerability | HIGH | 8.2 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-31771 | Bluetooth: hci_event: move wake reason storage into validated event handlers | HIGH | 8.1 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-43618 | Rsync < 3.4.3 Integer Overflow Information Disclosure | HIGH | 8.1 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-47784 | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because me | HIGH | 8.1 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-47783 | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a | HIGH | 8.1 | 67%ile | Microsoft | 2026-05-12 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-31708 | smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path | HIGH | 8.1 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-6665 | PgBouncer buffer overflow in SCRAM | HIGH | 8.1 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-8711 | NGINX JavaScript vulnerability | HIGH | 8.1 | 56%ile | Microsoft | 2026-05-12 |
| CVE-2026-40415 | Windows TCP/IP Remote Code Execution Vulnerability | HIGH | 8.1 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-45584 | Microsoft Defender Remote Code Execution Vulnerability | HIGH | 8.1 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-41105 | Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability | HIGH | 8.1 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.1 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-40368 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.0 | 78%ile | Microsoft | 2026-05-12 |
| CVE-2026-34332 | Windows Kernel-Mode Driver Remote Code Execution Vulnerability | HIGH | 8.0 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-47294 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.0 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-43284 | xfrm: esp: avoid in-place decrypt on shared skb frags | HIGH | 7.8 | 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-31723 | usb: gadget: f_subset: Fix net_device lifecycle with device_move | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31724 | usb: gadget: f_eem: Fix net_device lifecycle with device_move | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31721 | usb: gadget: f_hid: move list and spinlock inits from bind to alloc | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31694 | fuse: reject oversized dirents in page cache | HIGH | 7.8 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-43033 | crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-31702 | f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31700 | net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() | HIGH | 7.8 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43499 | rtmutex: Use waiter::task instead of current in remove_waiter() | HIGH | 7.8 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-43497 | fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-41054 | Missing exit out of permission check in haveged could lead to root exploit | HIGH | 7.8 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-46300 | net: skbuff: preserve shared-frag marker during coalescing | HIGH | 7.8 | 94%ile | Microsoft | 2026-05-12 |
| CVE-2026-46150 | fanotify: fix false positive on permission events | HIGH | 7.8 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46242 | eventpoll: fix ep_remove struct eventpoll / struct file UAF | HIGH | 7.8 | 87%ile | Microsoft | 2026-05-12 |
| CVE-2026-48864 | Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data | HIGH | 7.8 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-40034 | gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule | HIGH | 7.8 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-43059 | Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31722 | usb: gadget: f_rndis: Fix net_device lifecycle with device_move | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31725 | usb: gadget: f_ecm: Fix net_device lifecycle with device_move | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43019 | Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43009 | bpf: Fix incorrect pruning due to atomic fetch precision tracking | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43125 | dlm: validate length in dlm_search_rsb_tree | HIGH | 7.8 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-43258 | alpha: fix user-space corruption during memory compaction | HIGH | 7.8 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43321 | bpf: Properly mark live registers for indirect jumps | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43298 | drm/amdgpu: Skip vcn poison irq release on VF | HIGH | 7.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43353 | i3c: mipi-i3c-hci: Fix race in DMA ring dequeue | HIGH | 7.8 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43500 | rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present | HIGH | 7.8 | 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-45958 | drm/exynos: vidi: fix to avoid directly dereferencing user pointer | HIGH | 7.8 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-32204 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-33834 | Windows Event Logging Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-34330 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-34333 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-34343 | Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-34344 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-34351 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.8 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-35415 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-35417 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-35418 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-35420 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-35421 | Windows GDI Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-40360 | Microsoft Excel Information Disclosure Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-40377 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-40399 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-40407 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-40408 | Windows WAN ARP Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-40417 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-40419 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-41088 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-41095 | Data Deduplication Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-41611 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-42831 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-42896 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-33835 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 80%ile | Microsoft | 2026-05-12 |
| CVE-2026-33837 | Windows TCP/IP Local Elevation of Privilege Vulnerability | HIGH | 7.8 | 77%ile | Microsoft | 2026-05-12 |
| CVE-2026-33838 | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-34334 | Windows TCP/IP Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-34336 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-34337 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-34338 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-40359 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-40362 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-40369 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 91%ile | Microsoft | 2026-05-12 |
| CVE-2026-40382 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-40397 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-40398 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 82%ile | Microsoft | 2026-05-12 |
| CVE-2026-40418 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-40381 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-42834 | Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-33841 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-33840 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 79%ile | Microsoft | 2026-05-12 |
| CVE-2026-46191 | fbcon: Avoid OOB font access if console rotation fails | HIGH | 7.7 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-9804 | Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read | HIGH | 7.7 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-26147 | Azure Stack HCI Information Disclosure Vulnerability | HIGH | 7.7 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-42832 | Microsoft Office Spoofing Vulnerability | HIGH | 7.7 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-33821 | Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability | HIGH | 7.7 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-31711 | smb: server: fix active_num_conn leak on transport allocation failure | HIGH | 7.5 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-31704 | ksmbd: use check_add_overflow() to prevent u16 DACL size overflow | HIGH | 7.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-37457 | An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of F | HIGH | 7.5 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-42151 | Prometheus Azure AD remote write OAuth client secret exposed via config API | HIGH | 7.5 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-42154 | Prometheus: remote read endpoint allows denial of service via crafted snappy payload | HIGH | 7.5 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-33846 | Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly | HIGH | 7.5 | 67%ile | Microsoft | 2026-05-12 |
| CVE-2026-33814 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | HIGH | 7.5 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-8177 | XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing trunc | HIGH | 7.5 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-5773 | wrong reuse of SMB connection | HIGH | 7.5 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-42304 | Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains | HIGH | 7.5 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-4890 | CVE-2026-4890 | HIGH | 7.5 | 94%ile | Microsoft | 2026-05-12 |
| CVE-2026-44673 | libyang: lyb_read_string() integer overflow → heap buffer overflow | HIGH | 7.5 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-42959 | Crash during DNSSEC validation of malicious content | HIGH | 7.5 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-3039 | BIND 9 server memory exhaustion during GSS-API TKEY negotiation | HIGH | 7.5 | 61%ile | Microsoft | 2026-05-12 |
| CVE-2026-5946 | Invalid handling of CLASS != IN | HIGH | 7.5 | 77%ile | Microsoft | 2026-05-12 |
| CVE-2026-42009 | Gnutls: gnutls: denial of service via dtls packet reordering vulnerability | HIGH | 7.5 | 68%ile | Microsoft | 2026-05-12 |
| CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-46054 | selinux: fix overlayfs mmap() and mprotect() access checks | HIGH | 7.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45850 | ipvs: skip ipv6 extension headers for csum checks | HIGH | 7.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46009 | PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown | HIGH | 7.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-9538 | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar heade | HIGH | 7.5 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-42497 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directo | HIGH | 7.5 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-34059 | Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data() | HIGH | 7.5 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-29169 | Apache HTTP Server: mod_dav_lock indirect lock crash | HIGH | 7.5 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-37459 | An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v | HIGH | 7.5 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-6664 | PgBouncer integer overflow in PgBouncer network packet parsing | HIGH | 7.5 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-33811 | Crash when handling long CNAME response in net | HIGH | 7.5 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-39820 | Quadratic string concatentation in consumeComment in net/mail | HIGH | 7.5 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-39836 | Panic in Dial and LookupPort when handling NUL byte on Windows in net | HIGH | 7.5 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-42499 | Quadratic string concatenation in consumePhrase in net/mail | HIGH | 7.5 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-42501 | Malicious module proxy can bypass checksum database in cmd/go | HIGH | 7.5 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-6276 | stale custom cookie host causes cookie leak | HIGH | 7.5 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-6479 | PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-41292 | Long list of incoming EDNS options degrades performance | HIGH | 7.5 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-42944 | Heap overflow with multiple NSID, COOKIE, PADDING EDNS options | HIGH | 7.5 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-5947 | SIG(0) validation during query flood may lead to undefined behavior | HIGH | 7.5 | 70%ile | Microsoft | 2026-05-12 |
| CVE-2026-48959 | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward | HIGH | 7.5 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-35424 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | HIGH | 7.5 | 65%ile | Microsoft | 2026-05-12 |
| CVE-2026-40405 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2026-05-12 |
| CVE-2026-40406 | Windows TCP/IP Information Disclosure Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-32161 | Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability | HIGH | 7.5 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-42899 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | 83%ile | Microsoft | 2026-05-12 |
| CVE-2026-26129 | M365 Copilot Information Disclosure Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-05-12 |
| CVE-2026-33111 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability | HIGH | 7.5 | 63%ile | Microsoft | 2026-05-12 |
| CVE-2026-26164 | M365 Copilot Information Disclosure Vulnerability | HIGH | 7.5 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-23663 | Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability | HIGH | 7.5 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-42011 | Gnutls: gnutls: security bypass due to incorrect name constraint handling | HIGH | 7.4 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-3593 | Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation | HIGH | 7.4 | 72%ile | Microsoft | 2026-05-12 |
| CVE-2026-48526 | PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed | HIGH | 7.4 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-40414 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.4 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-41107 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-40413 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.4 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-42893 | Microsoft Outlook for iOS Tampering Vulnerability | HIGH | 7.4 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-2291 | CVE-2026-2291 | HIGH | 7.3 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-5172 | CVE-2026-5172 | HIGH | 7.3 | 84%ile | Microsoft | 2026-05-12 |
| CVE-2026-45894 | iommu/vt-d: Clear Present bit before tearing down PASID entry | HIGH | 7.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45932 | bpf: Fix tcx/netkit detach permissions when prog fd isn't given | HIGH | 7.3 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46006 | drm/nouveau: fix u32 overflow in pushbuf reloc bounds check | HIGH | 7.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-48962 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled ou | HIGH | 7.3 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-7598 | libssh2 userauth.c userauth_password integer overflow | HIGH | 7.3 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-29168 | Apache HTTP Server: mod_md unrestricted OCSP response | HIGH | 7.3 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-43869 | Apache Thrift: TSSLTransportFactory.java hostname verification | HIGH | 7.3 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-46033 | crypto: authencesn - reject short ahash digests during instance creation | HIGH | 7.3 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45993 | LoongArch: Add spectre boundry for syscall dispatch table | HIGH | 7.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46145 | RDMA/mana: Validate rx_hash_key_len | HIGH | 7.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46130 | dm-verity-fec: fix reading parity bytes split across blocks (take 3) | HIGH | 7.3 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-35433 | .NET Elevation of Privilege Vulnerability | HIGH | 7.3 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-32177 | .NET Elevation of Privilege Vulnerability | HIGH | 7.3 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-31707 | ksmbd: validate response sizes in ipc_validate_msg() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43042 | mpls: add seqcount to protect the platform_label{,s} pair | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31699 | crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43248 | vhost: move vdpa group bound check to vhost_vdpa | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43245 | ntfs: ->d_compare() must not block | HIGH | 7.1 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-43153 | xfs: remove xfs_attr_leaf_hasname | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43116 | netfilter: ctnetlink: ensure safe access to master conntrack | HIGH | 7.1 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46062 | ntfs3: fix integer overflow in run_unpack() volume boundary check | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46084 | RDMA/mana_ib: Disable RX steering on RSS QP destroy | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46080 | ocfs2: split transactions in dio completion to avoid credit exhaustion | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45991 | udf: fix partition descriptor append bookkeeping | HIGH | 7.1 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-45839 | bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46047 | net: qrtr: ns: Fix use-after-free in driver remove() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46069 | wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45861 | gfs2: Fix slab-use-after-free in qd_put | HIGH | 7.1 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46056 | Bluetooth: hci_event: fix potential UAF in SSP passkey handlers | HIGH | 7.1 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-45956 | drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46226 | spi: fsl: fix controller deregistration | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46197 | drm/amdkfd: validate SVM ioctl nattr against buffer size | HIGH | 7.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46225 | spi: rspi: fix controller deregistration | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46177 | ipmi: Add limits to event and receive message requests | HIGH | 7.1 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46230 | drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46112 | RDMA/hns: Fix unlocked call to hns_roce_qp_remove() | HIGH | 7.1 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46122 | wifi: b43: enforce bounds check on firmware key index in b43_rx() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46146 | ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46227 | sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL | HIGH | 7.1 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-42012 | Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans | HIGH | 7.1 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-31697 | crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-31698 | crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43058 | media: vidtv: fix pass-by-value structs causing MSAN warnings | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43109 | x86: shadow stacks: proper error handling for mmap lock | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43274 | mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-71289 | fs/ntfs3: handle attr_set_size() errors when truncating files | HIGH | 7.1 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-43250 | usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke() | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43219 | net: cpsw_new: Fix potential unregister of netdev that has not been registered yet | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43088 | net: af_key: zero aligned sockaddr tail in PF_KEY exports | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43195 | drm/amdgpu: validate user queue size constraints | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43228 | hfs: Replace BUG_ON with error handling for CNID count checks | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43318 | drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-42010 | Gnutls: gnutls: authentication bypass via nul character in username | HIGH | 7.1 | 61%ile | Microsoft | 2026-05-12 |
| CVE-2026-45912 | ext4: don't cache extent during splitting extent | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46091 | media: rc: igorplugusb: heed coherency rules | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46072 | ntfs3: add buffer boundary checks to run_unpack() | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46099 | net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels | HIGH | 7.1 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-46094 | ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46231 | batman-adv: bla: put backbone reference on failed claim hash insert | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46229 | drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46204 | drm/amdgpu/vcn4: Prevent OOB reads when parsing IB | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46233 | batman-adv: bla: only purge non-released claims | HIGH | 7.1 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46174 | x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46193 | xfrm: ah: account for ESN high bits in async callbacks | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46140 | Bluetooth: btmtk: validate WMT event SKB length before struct access | HIGH | 7.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-41101 | Microsoft Word for Android Spoofing Vulnerability | HIGH | 7.1 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-41102 | Microsoft PowerPoint for Android Spoofing Vulnerability | HIGH | 7.1 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-40401 | Windows TCP/IP Denial of Service Vulnerability | HIGH | 7.1 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-43052 | wifi: mac80211: check tdls flag in ieee80211_tdls_oper | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43037 | ip6_tunnel: clear skb2->cb[] in ip4ip6_err() | HIGH | 7.0 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-43306 | bpf: crypto: Use the correct destructor kfunc type | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43303 | mm/page_alloc: clear page->private in free_pages_prepare() | HIGH | 7.0 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-43501 | ipv6: rpl: reserve mac_len headroom when recompressed SRH grows | HIGH | 7.0 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-43503 | net: skbuff: propagate shared-frag marker through frag-transfer helpers | HIGH | 7.0 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-45840 | openvswitch: cap upcall PID array size and pre-size vport replies | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46053 | net: rds: fix MR cleanup on copy error | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45940 | net: stmmac: fix oops when split header is enabled | HIGH | 7.0 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-46017 | mm: fix deferred split queue races during migration | HIGH | 7.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46052 | ceph: only d_add() negative dentries when they are unhashed | HIGH | 7.0 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46043 | RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv | HIGH | 7.0 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-45859 | netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation | HIGH | 7.0 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-46032 | KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46086 | net: bridge: use a stable FDB dst snapshot in RCU readers | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45998 | rxrpc: Fix potential UAF after skb_unshare() failure | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45892 | ext4: drop extent cache after doing PARTIAL_VALID1 zeroout | HIGH | 7.0 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-46114 | RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads | HIGH | 7.0 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-31777 | ALSA: ctxfi: Check the error for index mapping | HIGH | 7.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43049 | HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31729 | usb: typec: ucsi: validate connector number in ucsi_notify_common() | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43176 | wifi: rtw89: pci: validate release report content before using for RTL8922DE | HIGH | 7.0 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-43198 | tcp: fix potential race in tcp_v6_syn_recv_sock() | HIGH | 7.0 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-43213 | wifi: rtw89: pci: validate sequence number of TX release report | HIGH | 7.0 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-43267 | wifi: rtw89: fix potential zero beacon interval in beacon tracking | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43101 | ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() | HIGH | 7.0 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-43199 | net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query | HIGH | 7.0 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-43083 | net: ioam6: fix OOB and missing lock | HIGH | 7.0 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-29518 | Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write | HIGH | 7.0 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-45942 | ext4: fix e4b bitmap inconsistency reports | HIGH | 7.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-45934 | btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46090 | ALSA: aloop: Fix peer runtime UAF during format-change stop | HIGH | 7.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46076 | KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 | HIGH | 7.0 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46119 | libceph: Fix slab-out-of-bounds access in auth message processing | HIGH | 7.0 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-46121 | mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock | HIGH | 7.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-33839 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-34331 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-34342 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-34345 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-34347 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-35416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 74%ile | Microsoft | 2026-05-12 |
| CVE-2026-40410 | Windows SMB Client Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-42825 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-34340 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-34341 | Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-45585 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 69%ile | Microsoft | 2026-05-12 |
| CVE-2026-32170 | Windows Rich Text Edit Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-41097 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 70%ile | Microsoft | 2026-05-12 |
| CVE-2026-21530 | Windows Rich Text Edit Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-45930 | net: mctp: ensure our nlmsg responses are initialised | MEDIUM | 6.6 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46220 | drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission | MEDIUM | 6.6 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45130 | Vim: Heap Buffer Overflow in spell file loading | MEDIUM | 6.6 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-46209 | drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() | MEDIUM | 6.6 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-37458 | Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat | MEDIUM | 6.5 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-5545 | wrong reuse of HTTP Negotiate connection | MEDIUM | 6.5 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-6478 | PostgreSQL discloses MD5-hashed passwords via covert timing channel | MEDIUM | 6.5 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-40460 | NGINX ngx_quic_module vulnerability | MEDIUM | 6.5 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-42946 | NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability | MEDIUM | 6.5 | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-43620 | Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files() | MEDIUM | 6.5 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-41401 | libyang - Heap Use-After-Free Write in XML Metadata Parsing | MEDIUM | 6.5 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-9150 | Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums | MEDIUM | 6.5 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-9149 | Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file | MEDIUM | 6.5 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-33523 | Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line | MEDIUM | 6.5 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-44283 | etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks | MEDIUM | 6.5 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-43495 | net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler | MEDIUM | 6.5 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-25680 | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | MEDIUM | 6.5 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-42827 | M365 Copilot Information Disclosure Vulnerability | MEDIUM | 6.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-34350 | Windows Storport Miniport Driver Denial of Service Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-35422 | Windows TCP/IP Driver Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-40374 | Microsoft Power Automate Desktop Information Disclosure Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-42891 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 6.5 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-42830 | Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability | MEDIUM | 6.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-43619 | Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls | MEDIUM | 6.3 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-39828 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh | MEDIUM | 6.3 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-41610 | Visual Studio Code Security Feature Bypass Vulnerability | MEDIUM | 6.3 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-43894 | jq: Wild stack write via signed-integer overflow in decNumber D2U() macro | MEDIUM | 6.2 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-43896 | jq: Stack Overflow in Recursive Object Merge | MEDIUM | 6.2 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-23679 | libusb < 1.0.30 NULL Pointer Dereference in parse_interface() | MEDIUM | 6.2 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-40380 | Windows Volume Manager Extension Driver Remote Code Execution Vulnerability | MEDIUM | 6.2 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-41614 | M365 Copilot for Desktop Spoofing Vulnerability | MEDIUM | 6.2 | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-39823 | Bypass of meta content URL escaping causes XSS in html/template | MEDIUM | 6.1 | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-42506 | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-42502 | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-27136 | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-25681 | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-44708 | Mistune Math Plugin XSS Escape Bypass | MEDIUM | 6.1 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-44897 | Mistune Heading ID Attribute Injection XSS | MEDIUM | 6.1 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-46149 | scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() | MEDIUM | 6.1 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46116 | xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46199 | drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-39826 | Escaper bypass leads to XSS in html/template | MEDIUM | 6.1 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-45989 | of: unittest: fix use-after-free in testdrv_probe() | MEDIUM | 6.1 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-44898 | Mistune TOC Anchor Injection XSS | MEDIUM | 6.1 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-46160 | btrfs: fix missing last_unlink_trans update when removing a directory | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46218 | drm/amdgpu: Add bounds checking to ib_{get,set}_value | MEDIUM | 6.1 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-4873 | connection reuse ignores TLS requirement | MEDIUM | 5.9 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-6253 | proxy credentials leak over redirect-to proxy | MEDIUM | 5.9 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-34956 | Openvswitch: open vswitch: denial of service via malformed ftp epasv command | MEDIUM | 5.9 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-44608 | Use after free and crash under special conditions in RPZ code | MEDIUM | 5.9 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-6666 | PgBouncer crash in kill_pool_logins_server_error | MEDIUM | 5.9 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-39817 | Invoking "go tool pack" does not sanitize output paths in cmd/go | MEDIUM | 5.9 | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-8376 | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed strin | MEDIUM | 5.7 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-43036 | net: use skb_header_pointer() for TCPv4 GSO frag_off check | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43010 | bpf: Reject sleepable kprobe_multi programs at attach time | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31696 | rxrpc: Fix missing validation of ticket length in non-XDR key preparsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43127 | ntfs3: fix circular locking dependency in run_unpack_ex | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43161 | iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43137 | ASoC: SOF: Intel: hda: Fix NULL pointer dereference | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43234 | team: avoid NETDEV_CHANGEMTU event when unregistering slave | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43185 | ksmbd: fix signededness bug in smb_direct_prepare_negotiation() | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2025-71273 | wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43244 | kcm: fix zero-frag skb in frag_list on partial sendmsg error | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43191 | drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2025-71272 | most: core: fix resource leak in most_register_interface error paths | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43309 | md raid: fix hang when stopping arrays with metadata through dm-raid | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43300 | drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43331 | x86/kexec: Disable KCOV instrumentation after load_segments() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43319 | spi: spidev: fix lock inversion between spi_lock and buf_lock | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43344 | perf/x86/intel/uncore: Fix die ID init and look up bugs | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43305 | drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-05-12 |
| CVE-2026-43310 | media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43292 | mm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43311 | soc/tegra: pmc: Fix unsafe generic_handle_irq() call | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43308 | btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-41256 | jq: Embedded NUL truncates top-level jq programs loaded with -f | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-31767 | drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43491 | net: qrtr: ns: Limit the maximum server registration per node | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-43465 | net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-43502 | net/rds: handle zerocopy send cleanup before the message is queued | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43496 | net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43029 | mptcp: fix soft lockup in mptcp_recvmsg() | MEDIUM | 5.5 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-46050 | md/raid10: fix deadlock with check operation and nowait requests | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-45877 | HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-45917 | ipvs: do not keep dest_dst if dev is going down | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45841 | netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46005 | xfs: fix a resource leak in xfs_alloc_buftarg() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46037 | ipv4: icmp: validate reply type before using icmp_pointers | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-46012 | rxrpc: Fix memory leaks in rxkad_verify_response() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46085 | rxrpc: Fix rxkad crypto unalignment handling | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-46059 | KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45901 | netfilter: nf_tables: revert commit_mutex usage in reset path | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-46027 | net/smc: avoid early lgr access in smc_clc_wait_msg | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46088 | ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46051 | md/raid5: fix soft lockup in retry_aligned_read() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46018 | ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES | MEDIUM | 5.5 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-45835 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45834 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45944 | iommu/vt-d: Clear Present bit before tearing down context entry | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45836 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45961 | gfs2: fix memory leaks in gfs2_fill_super error path | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45943 | erofs: fix inline data read failure for ztailpacking pclusters | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45897 | netfilter: nft_counter: serialize reset with spinlock | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-45997 | scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46070 | md/raid5: validate payload size before accessing journal metadata | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45994 | ibmasm: fix OOB reads in command_file_write due to missing size checks | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46101 | netfilter: reject zero shift in nft_bitwise | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46014 | KVM: SVM: Add missing save/restore handling of LBR MSRs | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-45845 | net/sched: taprio: fix NULL pointer dereference in class dump | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46065 | fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46098 | net: caif: clear client service pointer on teardown | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46077 | crypto: atmel-tdes - fix DMA sync direction | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46063 | x86/shstk: Prevent deadlock during shstk sigreturn | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46068 | crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45843 | slip: bound decode() reads against the compressed packet length | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-46024 | libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-45963 | ASoC: nau8821: Cancel delayed work on component remove | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45844 | netfilter: arp_tables: fix IEEE1394 ARP payload parsing | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46022 | misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46102 | net: strparser: fix skb_head leak in strp_abort_strp() | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46016 | remoteproc: xlnx: Only access buffer information if IPI is buffered | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46000 | rxrpc: Fix conn-level packet handling to unshare RESPONSE packets | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46003 | net: qrtr: ns: Limit the total number of nodes | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46219 | spi: mpc52xx: fix use-after-free on unbind | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46214 | vsock/virtio: fix accept queue count leak on transport mismatch | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46137 | mptcp: pm: ADD_ADDR rtx: fix potential data-race | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-46186 | Bluetooth: virtio_bt: validate rx pkt_type header length | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46172 | ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46168 | mptcp: fix scheduling with atomic in timestamp sockopt | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46163 | wifi: b43legacy: enforce bounds check on firmware key index in RX path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46131 | KVM: x86: check for nEPT/nNPT in slow flush hypercalls | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46128 | ipmi: Check event message buffer response for bad data | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46159 | btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46165 | openvswitch: vport: fix self-deadlock on release of tunnel ports | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46158 | mptcp: pm: ADD_ADDR rtx: always decrease sk refcount | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46107 | dm-thin: fix metadata refcount underflow | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46176 | RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46208 | batman-adv: stop tp_meter sessions during mesh teardown | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46236 | media: rc: xbox_remote: heed DMA restrictions | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46164 | btrfs: fix double free in create_space_info_sub_group() error path | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46235 | media: saa7164: add ioremap return checks and cleanups | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46127 | RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46155 | smb/client: fix out-of-bounds read in smb2_compound_op() | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-46157 | ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46136 | wifi: mt76: mt7921: fix a potential clc buffer length underflow | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46132 | net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46170 | mptcp: pm: ADD_ADDR rtx: free sk if last | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46190 | mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46175 | f2fs: fix fsck inconsistency caused by FGGC of node block | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46238 | batman-adv: stop caching unowned originator pointers in BAT IV | MEDIUM | 5.5 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-46120 | ip6_gre: Use cached t->net in ip6erspan_changelink(). | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46108 | ipmi:si: Return state to normal if message allocation fails | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46152 | wifi: mac80211: drop stray 'static' from fast-RX rx_result | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46125 | wifi: mac80211: remove station if connection prep fails | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-46153 | 8021q: delete cleared egress QoS mappings | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46241 | spi: mpc52xx: fix use-after-free on registration failure | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46147 | KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46135 | nvmet-tcp: fix race between ICReq handling and queue teardown | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-46189 | RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46151 | usb: usblp: fix heap leak in IEEE 1284 device ID via short response | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46124 | isofs: validate block number from NFS file handle in isofs_export_iget | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-46106 | eventfs: Hold eventfs_mutex and SRCU when remount walks events | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46181 | RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46178 | RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43053 | xfs: close crash window in attr dabtree inactivation | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-05-12 |
| CVE-2026-31715 | f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43073 | x86-64: rename misleadingly named '__copy_user_nocache()' function | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43204 | ASoC: qcom: q6asm: drop DSP responses for closed data streams | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43131 | drm/amd/pm: Fix null pointer dereference issue | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43126 | ALSA: mixer: oss: Add card disconnect checkpoints | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-71290 | misc: ti_fpc202: fix a potential memory leak in probe function | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43115 | srcu: Use irq_work to start GP in tiny SRCU | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2025-71293 | drm/amdgpu/ras: Move ras data alloc before bad page check | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43172 | wifi: iwlwifi: fix 22000 series SMEM parsing | MEDIUM | 5.5 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2025-71285 | net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43197 | netconsole: avoid OOB reads, msg is not nul-terminated | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-43118 | btrfs: fix zero size inode with non-zero size after log replay | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43129 | ima: verify the previous kernel's IMA buffer lies in addressable RAM | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43107 | xfrm: account XFRMA_IF_ID in aevent size calculation | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43243 | drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2025-71294 | drm/amdgpu: fix NULL pointer issue buffer funcs | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43237 | drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43201 | APEI/GHES: ARM processor Error: don't go past allocated memory | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43165 | hwmon: (nct7363) Fix a resource leak in nct7363_present_pwm_fanin | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43216 | net: Drop the lock in skb_may_tx_timestamp() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43119 | Bluetooth: hci_sync: annotate data-races around hdev->req_status | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43338 | btrfs: reserve enough transaction items for qgroup ioctls | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43416 | powerpc, perf: Check that current->mm is alive before getting user callchain | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43352 | i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-71299 | spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43456 | bonding: fix type confusion in bond_setup_by_slave() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-43299 | btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43294 | drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43220 | iommu/amd: serialize sequence allocation under concurrent TLB invalidations | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46333 | ptrace: slightly saner 'get_dumpable()' logic | MEDIUM | 5.5 | 72%ile | Microsoft | 2026-05-12 |
| CVE-2026-43492 | lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-43464 | net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ | MEDIUM | 5.5 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-43494 | net/rds: reset op_nents when zerocopy page pin fails | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-43414 | scsi: qla2xxx: Completely fix fcport double free | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-46048 | ALSA: caiaq: fix usb_dev refcount leak on probe failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46002 | ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46078 | erofs: fix the out-of-bounds nameoff handling for trailing dirents | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46064 | ibmasm: fix heap over-read in ibmasm_send_i2o_message() | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46075 | crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45973 | RDMA/mlx5: Fix UMR hang in LAG error state unload | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-45838 | bpf: fix end-of-list detection in cgroup_storage_get_next_key() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46071 | KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46049 | ALSA: ctxfi: Add fallback to default RSR for S/PDIF | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46066 | ceph: fix num_ops off-by-one when crypto allocation fails | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45855 | ata: libata-scsi: avoid Non-NCQ command starvation | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46058 | media: amphion: Fix race between m2m job_abort and device_run | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46031 | net: ks8851: Reinstate disabling of BHs around IRQ handler | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-45999 | erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45846 | bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46089 | zram: do not forget to endio for partial discard requests | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46046 | ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46038 | net: qrtr: ns: Free the node during ctrl_cmd_bye() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46040 | inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45988 | rxrpc: Fix re-decryption of RESPONSE packets | MEDIUM | 5.5 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-45996 | spi: imx: fix use-after-free on unbind | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46019 | crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46103 | can: ucan: fix devres lifetime | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46092 | wifi: rtw88: check for PCI upstream bridge existence | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45842 | slip: reject VJ receive packets on instances with no rstate array | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45949 | hwrng: core - use RCU and work_struct to fix race condition | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-05-12 |
| CVE-2026-46079 | rbd: fix null-ptr-deref when device_add_disk() fails | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46083 | spi: fix resource leaks on device setup failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45987 | KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46015 | tcp: call sk_data_ready() after listener migration | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45858 | ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-46082 | KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46026 | net: qrtr: ns: Limit the maximum number of lookups | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46200 | spi: mpc52xx: fix controller deregistration | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46148 | spi: microchip-core-qspi: control built-in cs manually | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46198 | batman-adv: fix integer overflow on buff_pos | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-46111 | Bluetooth: hci_conn: fix potential UAF in create_big_sync | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46195 | smb: client: validate dacloffset before building DACL pointers | MEDIUM | 5.5 | 49%ile | Microsoft | 2026-05-12 |
| CVE-2026-46109 | usb: ulpi: fix memory leak on ulpi_register() error paths | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46173 | exit: prevent preemption of oopsing TASK_DEAD task | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46180 | wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46115 | block: add pgmap check to biovec_phys_mergeable | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46185 | smb/client: fix out-of-bounds read in symlink_data() | MEDIUM | 5.5 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-46161 | md/raid10: fix divide-by-zero in setup_geo() with zero far_copies | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46212 | batman-adv: bla: prevent use-after-free when deleting claims | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-46205 | staging: media: atomisp: Disallow all private IOCTLs | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46234 | vsock: fix buffer size clamping order | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46171 | riscv: kvm: fix vector context allocation leak | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46179 | ASoC: SOF: Don't allow pointer operations on unconfigured streams | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-46196 | tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46133 | RDMA/rxe: Reject unknown opcodes before ICRC processing | MEDIUM | 5.5 | 44%ile | Microsoft | 2026-05-12 |
| CVE-2026-46129 | btrfs: fix double free in create_space_info() error path | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46156 | LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46138 | Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt | MEDIUM | 5.5 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-46187 | wifi: rsi: fix kthread lifetime race between self-exit and external-stop | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46167 | usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46113 | KVM: x86: Fix shadow paging use-after-free due to unexpected GFN | MEDIUM | 5.5 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-46206 | batman-adv: reject new tp_meter sessions during teardown | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-46142 | net: libwx: fix VF illegal register access | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46144 | RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46184 | sound: ua101: fix division by zero at probe | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2025-15649 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-35419 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-35440 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 5.5 | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-41612 | Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-32185 | Microsoft Teams Spoofing Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-34339 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | MEDIUM | 5.5 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-45571 | go-git: Crafted repositories may modify main and submodule .git directories | MEDIUM | 5.4 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-6472 | PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege | MEDIUM | 5.4 | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-35423 | Windows 11 Telnet Client Information Disclosure Vulnerability | MEDIUM | 5.4 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-42838 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | MEDIUM | 5.4 | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-45494 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-6429 | netrc credential leak with reused proxy connection | MEDIUM | 5.3 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-4893 | CVE-2026-4893 | MEDIUM | 5.3 | 84%ile | Microsoft | 2026-05-12 |
| CVE-2026-32792 | Packet of death with DNSCrypt | MEDIUM | 5.3 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-42923 | Degradation of service with unbounded NSEC3 hash calculations | MEDIUM | 5.3 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-3592 | Amplification vulnerabilities via self-pointed glue records | MEDIUM | 5.3 | 33%ile | Microsoft | 2026-05-12 |
| CVE-2026-5950 | Unbounded resend loop in BIND 9 resolver | MEDIUM | 5.3 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-8723 | qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly | MEDIUM | 5.3 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | MEDIUM | 5.3 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46598 | Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-6402 | webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins | MEDIUM | 5.3 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-48525 | PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS | MEDIUM | 5.3 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-43868 | Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern | MEDIUM | 5.3 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-34032 | Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) | MEDIUM | 5.3 | 39%ile | Microsoft | 2026-05-12 |
| CVE-2026-33007 | Apache HTTP Server: mod_authn_socache crash | MEDIUM | 5.3 | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-33857 | Apache HTTP Server: Off-by-one OOB reads in AJP getter functions | MEDIUM | 5.3 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-39819 | Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go | MEDIUM | 5.3 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-39825 | ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | MEDIUM | 5.3 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-7168 | cross-proxy Digest auth state leak | MEDIUM | 5.3 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-4891 | CVE-2026-4891 | MEDIUM | 5.3 | 93%ile | Microsoft | 2026-05-12 |
| CVE-2026-8368 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect | MEDIUM | 5.3 | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-42534 | Jostle logic bypass degrades resolution performance | MEDIUM | 5.3 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-44390 | Unbounded name compression in certain cases causes degradation of service | MEDIUM | 5.3 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-42015 | Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling | MEDIUM | 5.3 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-42934 | NGINX ngx_http_charset_module vulnerability | MEDIUM | 4.8 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-6324 | Libsoup: libsoup: http request smuggling via unsigned to signed conversion error | MEDIUM | 4.8 | 55%ile | Microsoft | 2026-05-12 |
| CVE-2026-33006 | Apache HTTP Server: mod_auth_digest timing attack | MEDIUM | 4.8 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-40701 | NGINX ngx_http_ssl_module vulnerability | MEDIUM | 4.8 | 49%ile | Microsoft | 2026-05-12 |
| CVE-2026-43617 | Rsync < 3.4.3 Authorization Bypass via Hostname Resolution | MEDIUM | 4.8 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-46011 | media: mtk-jpeg: fix use-after-free in release path due to uncancelled work | MEDIUM | 4.7 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46110 | net: stmmac: Prevent NULL deref when RX memory exhausted | MEDIUM | 4.7 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-44899 | Mistune Image Directive CSS Injection Vulnerability | MEDIUM | 4.7 | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-46021 | thermal: core: Fix thermal zone governor cleanup issues | MEDIUM | 4.5 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43895 | jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published art | MEDIUM | 4.4 | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-45986 | crypto: ccree - fix a memory leak in cc_mac_digest() | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-45736 | ws: Uninitialized memory disclosure | MEDIUM | 4.4 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-32209 | Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability | MEDIUM | 4.4 | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-41100 | Microsoft 365 Copilot for Android Spoofing Vulnerability | MEDIUM | 4.4 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-10028 | Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificat | MEDIUM | 4.3 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-6667 | PgBouncer missing authorization check in KILL_CLIENT admin command | MEDIUM | 4.3 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-6474 | PostgreSQL timeofday() can disclose portions of server memory | MEDIUM | 4.3 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-40421 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 4.3 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-32175 | .NET Core Tampering Vulnerability | MEDIUM | 4.3 | 50%ile | Microsoft | 2026-05-12 |
| CVE-2026-35429 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 4.3 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-40416 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 4.3 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-48522 | PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes | MEDIUM | 4.2 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-46004 | ALSA: caiaq: Handle probe errors properly | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-47104 | libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array() | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46232 | HID: playstation: Clamp num_touch_reports | MEDIUM | 4.0 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-46194 | f2fs: fix node_cnt race between extent node destroy and writeback | MEDIUM | 4.0 | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-46143 | ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46169 | hfsplus: fix uninit-value by validating catalog record size | MEDIUM | 4.0 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | MEDIUM | 4.0 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-40528 | OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c | LOW | 3.8 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-40510 | OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c | LOW | 3.8 | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-6638 | PostgreSQL REFRESH PUBLICATION allows SQL injection via table name | LOW | 3.7 | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-48524 | PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) | LOW | 3.7 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-43964 | Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash v | LOW | 3.7 | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-46483 | Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag | LOW | 3.6 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-45803 | gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection | LOW | 3.5 | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-46023 | dm mirror: fix integer overflow in create_dirty_log() | LOW | 3.4 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-45893 | apparmor: Fix & Optimize table creation from possibly unaligned memory | LOW | 3.3 | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-46123 | Bluetooth: virtio_bt: clamp rx length before skb_put | LOW | 3.3 | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-45232 | Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy | LOW | 3.1 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-45186 | In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via | LOW | 2.9 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-46044 | ipmi:ssif: Clean up kthread on errors | LOW | 1.9 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-31769 | gpib: fix use-after-free in IO ioctl handlers | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43021 | Bluetooth: hci_sync: fix leaks when hci_cmd_sync_queue_once fails | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43045 | mshv: Fix error handling in mshv_region_pin | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-33190 | CoreDNS TSIG authentication bypass on encrypted DNS transports | UNKNOWN | — | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-32936 | CoreDNS DoH GET path missing size validation causes CPU and memory amplification | UNKNOWN | — | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-35579 | CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports | UNKNOWN | — | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-41673 | xmldom: Denial of service via uncontrolled recursion in XML serialization | UNKNOWN | — | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-43474 | fs: init flags_valid before calling vfs_fileattr_get | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2025-71302 | drm/panthor: fix for dma-fence safe access rules | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-43320 | drm/amd/display: Fix dsc eDP issue | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-43443 | ASoC: amd: acp-mach-common: Add missing error check for clock acquisition | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-43400 | drm/amdgpu: add upper bound check on user inputs in signal ioctl | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43398 | drm/amdgpu: add upper bound check on user inputs in wait ioctl | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-43421 | usb: gadget: f_ncm: Fix net_device lifecycle with device_move | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-41889 | pgx: SQL Injection via placeholder confusion with dollar quoted string literals | UNKNOWN | — | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-42256 | net-imap: Denial of service via high iteration count for `SCRAM-*` authentication | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-42246 | net-imap vulnerable to STARTTLS stripping via invalid response timing | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-7261 | SoapServer session-persisted object use-after-free via SOAP header fault | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-7568 | Signed integer overflow in metaphone() | UNKNOWN | — | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-40612 | jq: Stack overflow via unbounded recursion in jv_contains | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-6210 | Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-44777 | jq: stack overflow in module loading on mutual `include` | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-44307 | Mako: Path traversal via backslash URI on Windows in TemplateLookup | UNKNOWN | — | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-7210 | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection | UNKNOWN | — | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-43969 | Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-44662 | rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-44431 | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-43970 | Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame | UNKNOWN | — | 41%ile | Microsoft | 2026-05-12 |
| CVE-2025-14575 | Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-5222 | Cargo can be coerced to share credentials between registries | UNKNOWN | — | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-44844 | eml_parser: Recursion DoS via nested message/rfc822 attachments | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-42250 | Off-by-One Leading to Out-of-Bounds Write in bzip2 | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-42790 | nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-43022 | Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-33489 | CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-32934 | CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service | UNKNOWN | — | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-41672 | xmldom: XML node injection through unvalidated comment serialization | UNKNOWN | — | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-41674 | xmldom: XML injection through unvalidated DocumentType serialization | UNKNOWN | — | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-41675 | xmldom: XML node injection through unvalidated processing instruction serialization | UNKNOWN | — | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-25243 | redis-server RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 87%ile | Microsoft | 2026-05-12 |
| CVE-2026-23631 | redis-server Lua use-after-free may allow remote code execution | UNKNOWN | — | 85%ile | Microsoft | 2026-05-12 |
| CVE-2026-23479 | redis-server use-after-free in unblock client flow may allow remote code execution | UNKNOWN | — | 67%ile | Microsoft | 2026-05-12 |
| CVE-2026-25588 | RedisTimeSeries RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 62%ile | Microsoft | 2026-05-12 |
| CVE-2026-25589 | RedisBloom RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 69%ile | Microsoft | 2026-05-12 |
| CVE-2026-43317 | most: core: fix leak on early registration failure | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-44656 | Vim: OS Command Injection via 'path' completion | UNKNOWN | — | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-33079 | Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles | UNKNOWN | — | 41%ile | Microsoft | 2026-05-12 |
| CVE-2026-42257 | net-imap: Command Injection via "raw" arguments to multiple commands | UNKNOWN | — | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-42258 | net-imap: Command Injection via unvalidated Symbol inputs | UNKNOWN | — | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-7258 | Out-of-bounds read in urldecode() on NetBSD | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-6722 | Use-After-Free in SOAP using Apache map | UNKNOWN | — | 56%ile | Microsoft | 2026-05-12 |
| CVE-2026-6735 | XSS within PHP-FPM status endpoint | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7262 | NULL pointer dereference in SOAP apache:Map decoder with missing <value> | UNKNOWN | — | 52%ile | Microsoft | 2026-05-12 |
| CVE-2025-14179 | SQL injection in pdo_firebird via NUL bytes in quoted strings | UNKNOWN | — | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-7259 | Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-41257 | jq: Signed-int overflow in `stack_reallocate` (jq VM stack) | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8295 | Integer overflow in simdjson | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-7790 | Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS | UNKNOWN | — | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-43968 | CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-8328 | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address | UNKNOWN | — | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-40622 | Another 'ghost domain names' attack variant | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-8466 | Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy | UNKNOWN | — | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-5223 | Crates in third party registries can override the cached source of other crates | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-44896 | Mistune: XSS via unescaped figclass/figwidth in Figure directive | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-45570 | go-git: Improper single-quote escaping in go-git SSH transport | UNKNOWN | — | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-41184 | ServiceAccount token disclosure via install-cni container logs | UNKNOWN | — | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-42789 | Non-CA certificate accepted as intermediate issuer in public_key path validation | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-44839 | RabbitMQ: Unsanitized vhost names allow for XSS in management UI | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9974 | Chromium: CVE-2026-9974 Out of bounds write in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7898 | Chromium: CVE-2026-7898 Use after free in Chromoting | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-7899 | Chromium: CVE-2026-7899 Out of bounds read and write in V8 | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-7897 | Chromium: CVE-2026-7897 Use after free in Mobile | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-7896 | Chromium: CVE-2026-7896 Integer overflow in Blink | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-7998 | Chromium: CVE-2026-7998 Insufficient validation of untrusted input in Dialog | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7996 | Chromium: CVE-2026-7996 Insufficient validation of untrusted input in SSL | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7994 | Chromium: CVE-2026-7994 Inappropriate implementation in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-7997 | Chromium: CVE-2026-7997 Insufficient validation of untrusted input in Updater | UNKNOWN | — | 0%ile | Microsoft | 2026-05-12 |
| CVE-2026-7995 | Chromium: CVE-2026-7995 Out of bounds read in AdFilter | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7992 | Chromium: CVE-2026-7992 Insufficient validation of untrusted input in UI | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7977 | Chromium: CVE-2026-7977 Inappropriate implementation in Canvas | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7976 | Chromium: CVE-2026-7976 Use after free in Views | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7975 | Chromium: CVE-2026-7975 Use after free in DevTools | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7974 | Chromium: CVE-2026-7974 Use after free in Blink | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7973 | Chromium: CVE-2026-7973 Integer overflow in Dawn | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7971 | Chromium: CVE-2026-7971 Inappropriate implementation in ORB | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7972 | Chromium: CVE-2026-7972 Uninitialized Use in GPU | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7970 | Chromium: CVE-2026-7970 Use after free in TopChrome | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7969 | Chromium: CVE-2026-7969 Integer overflow in Network | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7968 | Chromium: CVE-2026-7968 Insufficient validation of untrusted input in CORS | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-7967 | Chromium: CVE-2026-7967 Insufficient validation of untrusted input in Navigation | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7966 | Chromium: CVE-2026-7966 Insufficient validation of untrusted input in SiteIsolation | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-7964 | Chromium: CVE-2026-7964 Insufficient validation of untrusted input in FileSystem | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7963 | Chromium: CVE-2026-7963 Inappropriate implementation in ServiceWorker | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7993 | Chromium: CVE-2026-7993 Insufficient validation of untrusted input in Payments | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7962 | Chromium: CVE-2026-7962 Insufficient policy enforcement in DirectSockets | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7991 | Chromium: CVE-2026-7991 Use after free in UI | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7960 | Chromium: CVE-2026-7960 Race in Speech | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7961 | Chromium: CVE-2026-7961 Insufficient validation of untrusted input in Permissions | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7959 | Chromium: CVE-2026-7959 Inappropriate implementation in Navigation | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7958 | Chromium: CVE-2026-7958 Inappropriate implementation in ServiceWorker | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-7990 | Chromium: CVE-2026-7990 Insufficient validation of untrusted input in Updater | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7957 | Chromium: CVE-2026-7957 Out of bounds write in Media | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-7956 | Chromium: CVE-2026-7956 Use after free in Navigation | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7955 | Chromium: CVE-2026-7955 Uninitialized Use in GPU | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7954 | Chromium: CVE-2026-7954 Race in Shared Storage | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7953 | Chromium: CVE-2026-7953 Insufficient validation of untrusted input in Omnibox | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7965 | Chromium: CVE-2026-7965 Insufficient validation of untrusted input in DevTools | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7952 | Chromium: CVE-2026-7952 Insufficient policy enforcement in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7951 | Chromium: CVE-2026-7951 Out of bounds write in WebRTC | UNKNOWN | — | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-7949 | Chromium: CVE-2026-7949 Out of bounds read in Skia | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7950 | Chromium: CVE-2026-7950 Out of bounds read and write in GFX | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7948 | Chromium: CVE-2026-7948 Race in Chromoting | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-7999 | Chromium: CVE-2026-7999 Inappropriate implementation in V8 | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-7947 | Chromium: CVE-2026-7947 Insufficient validation of untrusted input in Network | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7946 | Chromium: CVE-2026-7946 Insufficient policy enforcement in WebUI | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7945 | Chromium: CVE-2026-7945 Insufficient validation of untrusted input in COOP | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7944 | Chromium: CVE-2026-7944 Insufficient validation of untrusted input in Persistent Cache | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7943 | Chromium: CVE-2026-7943 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-7942 | Chromium: CVE-2026-7942 Integer overflow in ANGLE | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7941 | Chromium: CVE-2026-7941 Insufficient validation of untrusted input in Mobile | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7940 | Chromium: CVE-2026-7940 Use after free in V8 | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7939 | Chromium: CVE-2026-7939 Inappropriate implementation in SanitizerAPI | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-7938 | Chromium: CVE-2026-7938 Use after free in CSS | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7986 | Chromium: CVE-2026-7986 Insufficient policy enforcement in Autofill | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7937 | Chromium: CVE-2026-7937 Insufficient policy enforcement in DevTools | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-7936 | Chromium: CVE-2026-7936 Object lifecycle issue in V8 | UNKNOWN | — | — | Microsoft | 2026-05-12 |
| CVE-2026-7989 | Chromium: CVE-2026-7989 Insufficient data validation in DataTransfer | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-7988 | Chromium: CVE-2026-7988 Type Confusion in WebRTC | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-7987 | Chromium: CVE-2026-7987 Use after free in WebRTC | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-7985 | Chromium: CVE-2026-7985 Use after free in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7984 | Chromium: CVE-2026-7984 Use after free in ReadingMode | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7983 | Chromium: CVE-2026-7983 Out of bounds read in Dawn | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7981 | Chromium: CVE-2026-7981 Out of bounds read in Codecs | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-7980 | Chromium: CVE-2026-7980 Use after free in WebAudio | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-7978 | Chromium: CVE-2026-7978 Inappropriate implementation in Companion | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7979 | Chromium: CVE-2026-7979 Inappropriate implementation in Media | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7982 | Chromium: CVE-2026-7982 Uninitialized Use in WebCodecs | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7934 | Chromium: CVE-2026-7934 Insufficient validation of untrusted input in Popup Blocker | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-7933 | Chromium: CVE-2026-7933 Out of bounds read in WebCodecs | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-7935 | Chromium: CVE-2026-7935 Inappropriate implementation in Speech | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7932 | Chromium: CVE-2026-7932 Insufficient policy enforcement in Downloads | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7929 | Chromium: CVE-2026-7929 Use after free in MediaRecording | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-7931 | Chromium: CVE-2026-7931 Insufficient validation of untrusted input in iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7930 | Chromium: CVE-2026-7930 Insufficient validation of untrusted input in Cookies | UNKNOWN | — | — | Microsoft | 2026-05-12 |
| CVE-2026-7927 | Chromium: CVE-2026-7927 Type Confusion in Runtime | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-7928 | Chromium: CVE-2026-7928 Use after free in WebRTC | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-7926 | Chromium: CVE-2026-7926 Use after free in PresentationAPI | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7925 | Chromium: CVE-2026-7925 Use after free in Chromoting | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7924 | Chromium: CVE-2026-7924 Uninitialized Use in Dawn | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-7923 | Chromium: CVE-2026-7923 Out of bounds write in Skia | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7922 | Chromium: CVE-2026-7922 Use after free in ServiceWorker | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7921 | Chromium: CVE-2026-7921 Use after free in Passwords | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7920 | Chromium: CVE-2026-7920 Use after free in Skia | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7918 | Chromium: CVE-2026-7918 Use after free in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7917 | Chromium: CVE-2026-7917 Use after free in Fullscreen | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7919 | Chromium: CVE-2026-7919 Use after free in Aura | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7916 | Chromium: CVE-2026-7916 Insufficient data validation in InterestGroups | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7915 | Chromium: CVE-2026-7915 Insufficient data validation in DevTools | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-7914 | Chromium: CVE-2026-7914 Type Confusion in Accessibility | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7913 | Chromium: CVE-2026-7913 Insufficient policy enforcement in DevTools | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-7912 | Chromium: CVE-2026-7912 Integer overflow in GPU | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-7911 | Chromium: CVE-2026-7911 Use after free in Aura | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-7909 | Chromium: CVE-2026-7909 Inappropriate implementation in ServiceWorker | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7910 | Chromium: CVE-2026-7910 Use after free in Views | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7908 | Chromium: CVE-2026-7908 Use after free in Fullscreen | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7907 | Chromium: CVE-2026-7907 Use after free in DOM | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7905 | Chromium: CVE-2026-7905 Insufficient validation of untrusted input in Media | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7906 | Chromium: CVE-2026-7906 Use after free in SVG | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7904 | Chromium: CVE-2026-7904 Out of bounds read in Fonts | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-7903 | Chromium: CVE-2026-7903 Integer overflow in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-7902 | Chromium: CVE-2026-7902 Out of bounds memory access in V8 | UNKNOWN | — | 27%ile | Microsoft | 2026-05-12 |
| CVE-2026-7901 | Chromium: CVE-2026-7901 Use after free in ANGLE | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-7900 | Chromium: CVE-2026-7900 Heap buffer overflow in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-8020 | Chromium: CVE-2026-8020 Uninitialized Use in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8019 | Chromium: CVE-2026-8019 Insufficient policy enforcement in WebApp | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8018 | Chromium: CVE-2026-8018 Insufficient policy enforcement in DevTools | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-8022 | Chromium: CVE-2026-8022 Inappropriate implementation in MHTML | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8017 | Chromium: CVE-2026-8017 Side-channel information leakage in Media | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8021 | Chromium: CVE-2026-8021 Script injection in UI | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8014 | Chromium: CVE-2026-8014 Inappropriate implementation in Preload | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8015 | Chromium: CVE-2026-8015 Inappropriate implementation in Media | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8016 | Chromium: CVE-2026-8016 Use after free in WebRTC | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-8012 | Chromium: CVE-2026-8012 Inappropriate implementation in MHTML | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8011 | Chromium: CVE-2026-8011 Insufficient policy enforcement in Search | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8013 | Chromium: CVE-2026-8013 Insufficient validation of untrusted input in FedCM | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8009 | Chromium: CVE-2026-8009 Inappropriate implementation in Cast | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-8010 | Chromium: CVE-2026-8010 Insufficient validation of untrusted input in SiteIsolation | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8008 | Chromium: CVE-2026-8008 Inappropriate implementation in DevTools | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-8007 | Chromium: CVE-2026-8007 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8006 | Chromium: CVE-2026-8006 Insufficient policy enforcement in DevTools | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-8005 | Chromium: CVE-2026-8005 Insufficient validation of untrusted input in Cast | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-8002 | Chromium: CVE-2026-8002 Use after free in Audio | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8004 | Chromium: CVE-2026-8004 Insufficient policy enforcement in DevTools | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-8003 | Chromium: CVE-2026-8003 Insufficient validation of untrusted input in TabGroups | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8000 | Chromium: CVE-2026-8000 Insufficient validation of untrusted input in ChromeDriver | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8001 | Chromium: CVE-2026-8001 Use after free in Printing | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8520 | Chromium: CVE-2026-8520 Race in Payments | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8564 | Chromium: CVE-2026-8564 Incorrect security UI in Downloads | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8583 | Chromium: CVE-2026-8583 Insufficient policy enforcement in WebXR | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9111 | Chromium: CVE-2026-9111 Use after free in WebRTC | UNKNOWN | — | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-9110 | Chromium: CVE-2026-9110 Inappropriate implementation in UI | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-9112 | Chromium: CVE-2026-9112 Use after free in GPU | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-9113 | Chromium: CVE-2026-9113 Out of bounds read in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9115 | Chromium: CVE-2026-9115 Insufficient policy enforcement in Service Worker | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9114 | Chromium: CVE-2026-9114 Use after free in QUIC | UNKNOWN | — | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-10011 | Chromium: CVE-2026-10011 Inappropriate implementation in Skia | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-10009 | Chromium: CVE-2026-10009 Integer overflow in Skia | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-10012 | Chromium: CVE-2026-10012 Use after free in Skia | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-10013 | Chromium: CVE-2026-10013 Use after free in WebCodecs | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-10015 | Chromium: CVE-2026-10015 Integer overflow in WTF | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-10016 | Chromium: CVE-2026-10016 Use after free in DOM | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-10018 | Chromium: CVE-2026-10018 Integer overflow in ANGLE | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-10019 | Chromium: CVE-2026-10019 Integer overflow in ANGLE | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-10017 | Chromium: CVE-2026-10017 Out of bounds read in Headless | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-10022 | Chromium: CVE-2026-10022 Type Confusion in V8 | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-10021 | Chromium: CVE-2026-10021 Insufficient validation of untrusted input in USB | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9884 | Chromium: CVE-2026-9884 Use after free in Browser | UNKNOWN | — | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-9882 | Chromium: CVE-2026-9882 Integer overflow in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9883 | Chromium: CVE-2026-9883 Use after free in Base | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-9886 | Chromium: CVE-2026-9886 Use after free in Base | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9887 | Chromium: CVE-2026-9887 Use after free in Proxy | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9885 | Chromium: CVE-2026-9885 Insufficient validation of untrusted input in UI | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9890 | Chromium: CVE-2026-9890 Use after free in XR | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9891 | Chromium: CVE-2026-9891 Use after free in Extensions | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9892 | Chromium: CVE-2026-9892 Inappropriate implementation in Skia | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9893 | Chromium: CVE-2026-9893 Use after free in Skia | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-9897 | Chromium: CVE-2026-9897 Use after free in DOM | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-9895 | Chromium: CVE-2026-9895 Out of bounds read in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9894 | Chromium: CVE-2026-9894 Use after free in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9896 | Chromium: CVE-2026-9896 Out of bounds write in V8 | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-9899 | Chromium: CVE-2026-9899 Use after free in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9900 | Chromium: CVE-2026-9900 Out of bounds write in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9902 | Chromium: CVE-2026-9902 Use after free in Accessibility | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9901 | Chromium: CVE-2026-9901 Use after free in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9905 | Chromium: CVE-2026-9905 Use after free in Accessibility | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9903 | Chromium: CVE-2026-9903 Insufficient validation of untrusted input in Site Isolation | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-9904 | Chromium: CVE-2026-9904 Use after free in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9909 | Chromium: CVE-2026-9909 Integer overflow in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9906 | Chromium: CVE-2026-9906 Out of bounds write in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9907 | Chromium: CVE-2026-9907 Out of bounds read in Dawn | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9910 | Chromium: CVE-2026-9910 Out of bounds memory access in ANGLE | UNKNOWN | — | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-9908 | Chromium: CVE-2026-9908 Out of bounds read in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9941 | Chromium: CVE-2026-9941 Use after free in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9944 | Chromium: CVE-2026-9944 Uninitialized Use in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-9942 | Chromium: CVE-2026-9942 Uninitialized Use in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-9945 | Chromium: CVE-2026-9945 Use after free in Media | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9949 | Chromium: CVE-2026-9949 Use after free in Core | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9946 | Chromium: CVE-2026-9946 Use after free in ANGLE | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9948 | Chromium: CVE-2026-9948 Use after free in Views | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9954 | Chromium: CVE-2026-9954 Use after free in TabStrip | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9953 | Chromium: CVE-2026-9953 Out of bounds read in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9951 | Chromium: CVE-2026-9951 Use after free in UI | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9952 | Chromium: CVE-2026-9952 Use after free in WebAudio | UNKNOWN | — | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-9962 | Chromium: CVE-2026-9962 Use after free in WebRTC | UNKNOWN | — | 28%ile | Microsoft | 2026-05-12 |
| CVE-2026-9961 | Chromium: CVE-2026-9961 Use after free in SurfaceCapture | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9964 | Chromium: CVE-2026-9964 Use after free in Bluetooth | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9965 | Chromium: CVE-2026-9965 Out of bounds write in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9968 | Chromium: CVE-2026-9968 Integer overflow in V8 | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-9970 | Chromium: CVE-2026-9970 Use after free in WebGL | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9966 | Chromium: CVE-2026-9966 Integer overflow in XML | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9967 | Chromium: CVE-2026-9967 Out of bounds write in GPU | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9975 | Chromium: CVE-2026-9975 Out of bounds read and write in ANGLE | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9976 | Chromium: CVE-2026-9976 Inappropriate implementation in USB | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9973 | Chromium: CVE-2026-9973 Out of bounds write in V8 | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-9972 | Chromium: CVE-2026-9972 Uninitialized Use in Gamepad | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9980 | Chromium: CVE-2026-9980 Insufficient validation of untrusted input in Printing | UNKNOWN | — | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-9979 | Chromium: CVE-2026-9979 Insufficient validation of untrusted input in Input | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-9978 | Chromium: CVE-2026-9978 Use after free in Glic | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9983 | Chromium: CVE-2026-9983 Type Confusion in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9981 | Chromium: CVE-2026-9981 Inappropriate implementation in Skia | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9982 | Chromium: CVE-2026-9982 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9984 | Chromium: CVE-2026-9984 Use after free in UI | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9985 | Chromium: CVE-2026-9985 Insufficient validation of untrusted input in Media | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9986 | Chromium: CVE-2026-9986 Insufficient validation of untrusted input in OptimizationGuide | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-9989 | Chromium: CVE-2026-9989 Inappropriate implementation in Media | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-9990 | Chromium: CVE-2026-9990 Use after free in WebAppInstalls | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-9988 | Chromium: CVE-2026-9988 Use after free in WebRTC | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-9992 | Chromium: CVE-2026-9992 Use after free in Network | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9993 | Chromium: CVE-2026-9993 Use after free in Views | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-9991 | Chromium: CVE-2026-9991 Inappropriate implementation in Media | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-9994 | Chromium: CVE-2026-9994 Use after free in Core | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9996 | Chromium: CVE-2026-9996 Out of bounds read in WebRTC | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9995 | Chromium: CVE-2026-9995 Use after free in WebXR | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9998 | Chromium: CVE-2026-9998 Integer overflow in Skia | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-9999 | Chromium: CVE-2026-9999 Inappropriate implementation in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9997 | Chromium: CVE-2026-9997 Use after free in Input | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2025-54518 | AMD: CVE-2025-54518 CPU OP Cache Corruption | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-45492 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-8587 | Chromium: CVE-2026-8587 Use after free in Extensions | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-8586 | Chromium: CVE-2026-8586 Inappropriate implementation in Chromoting | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-8585 | Chromium: CVE-2026-8585 Inappropriate implementation in Media | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-8584 | Chromium: CVE-2026-8584 Inappropriate implementation in Views | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-8582 | Chromium: CVE-2026-8582 Object lifecycle issue in Dawn | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8581 | Chromium: CVE-2026-8581 Use after free in GPU | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-8580 | Chromium: CVE-2026-8580 Use after free in Mojo | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8579 | Chromium: CVE-2026-8579 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-8578 | Chromium: CVE-2026-8578 Out of bounds read in GPU | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8577 | Chromium: CVE-2026-8577 Integer overflow in Fonts | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-8576 | Chromium: CVE-2026-8576 Inappropriate implementation in CORS | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8575 | Chromium: CVE-2026-8575 Use after free in UI | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-8573 | Chromium: CVE-2026-8573 Integer overflow in Codecs | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-8572 | Chromium: CVE-2026-8572 Insufficient policy enforcement in Network | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8571 | Chromium: CVE-2026-8571 Insufficient policy enforcement in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-8570 | Chromium: CVE-2026-8570 Type Confusion in V8 | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8569 | Chromium: CVE-2026-8569 Out of bounds write in Codecs | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8568 | Chromium: CVE-2026-8568 Insufficient policy enforcement in AI | UNKNOWN | — | — | Microsoft | 2026-05-12 |
| CVE-2026-8567 | Chromium: CVE-2026-8567 Integer overflow in ANGLE | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8566 | Chromium: CVE-2026-8566 Insufficient policy enforcement in Payments | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8565 | Chromium: CVE-2026-8565 Inappropriate implementation in Downloads | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2026-8563 | Chromium: CVE-2026-8563 Insufficient policy enforcement in IFrame Sandbox | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8562 | Chromium: CVE-2026-8562 Side-channel information leakage in Navigation | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8561 | Chromium: CVE-2026-8561 Incorrect security UI in Fullscreen | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8560 | Chromium: CVE-2026-8560 Heap buffer overflow in SwiftShader | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8559 | Chromium: CVE-2026-8559 Integer overflow in Internationalization | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-8558 | Chromium: CVE-2026-8558 Out of bounds write in Fonts | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-8557 | Chromium: CVE-2026-8557 Use after free in Accessibility | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8556 | Chromium: CVE-2026-8556 Inappropriate implementation in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-8555 | Chromium: CVE-2026-8555 Use after free in GTK | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-8553 | Chromium: CVE-2026-8553 Use after free in GPU | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8554 | Chromium: CVE-2026-8554 Type Confusion in ANGLE | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-8551 | Chromium: CVE-2026-8551 Use after free in Downloads | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-8552 | Chromium: CVE-2026-8552 Heap buffer overflow in GPU | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8550 | Chromium: CVE-2026-8550 Use after free in Google Lens | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-8549 | Chromium: CVE-2026-8549 Use after free in Media | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-8548 | Chromium: CVE-2026-8548 Out of bounds write in Media | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8547 | Chromium: CVE-2026-8547 Insufficient policy enforcement in Passwords | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-8546 | Chromium: CVE-2026-8546 Out of bounds read in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8545 | Chromium: CVE-2026-8545 Object corruption in Compositing | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8544 | Chromium: CVE-2026-8544 Use after free in Media | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-8543 | Chromium: CVE-2026-8543 Out of bounds read in FileSystem | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-8542 | Chromium: CVE-2026-8542 Use after free in Core | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8541 | Chromium: CVE-2026-8541 Out of bounds read in UI | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8540 | Chromium: CVE-2026-8540 Type Confusion in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-8539 | Chromium: CVE-2026-8539 Script injection in SanitizerAPI | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-8538 | Chromium: CVE-2026-8538 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8537 | Chromium: CVE-2026-8537 Insufficient policy enforcement in ViewTransitions | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8536 | Chromium: CVE-2026-8536 Insufficient validation of untrusted input in ReadingMode | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-8535 | Chromium: CVE-2026-8535 Out of bounds read in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-8534 | Chromium: CVE-2026-8534 Integer overflow in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8533 | Chromium: CVE-2026-8533 Use after free in Accessibility | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8532 | Chromium: CVE-2026-8532 Integer overflow in XML | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-8531 | Chromium: CVE-2026-8531 Heap buffer overflow in WebML | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-8530 | Chromium: CVE-2026-8530 Use after free in Network | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-8529 | Chromium: CVE-2026-8529 Heap buffer overflow in Codecs | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-8528 | Chromium: CVE-2026-8528 Insufficient validation of untrusted input in SiteIsolation | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-8527 | Chromium: CVE-2026-8527 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-8526 | Chromium: CVE-2026-8526 Out of bounds write in WebRTC | UNKNOWN | — | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-8523 | Chromium: CVE-2026-8523 Use after free in Mojo | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8519 | Chromium: CVE-2026-8519 Integer overflow in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-8518 | Chromium: CVE-2026-8518 Use after free in Blink | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-8517 | Chromium: CVE-2026-8517 Object lifecycle issue in WebShare | UNKNOWN | — | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-8516 | Chromium: CVE-2026-8516 Insufficient validation of untrusted input in DataTransfer | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-8515 | Chromium: CVE-2026-8515 Use after free in HID | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8514 | Chromium: CVE-2026-8514 Use after free in Aura | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8513 | Chromium: CVE-2026-8513 Use after free in Input | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8512 | Chromium: CVE-2026-8512 Use after free in FileSystem | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-8511 | Chromium: CVE-2026-8511 Use after free in UI | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-8509 | Chromium: CVE-2026-8509 Heap buffer overflow in WebML | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-8525 | Chromium: CVE-2026-8525 Heap buffer overflow in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-8524 | Chromium: CVE-2026-8524 Out of bounds write in WebAudio | UNKNOWN | — | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-8521 | Chromium: CVE-2026-8521 Use after free in Tab Groups | UNKNOWN | — | 5%ile | Microsoft | 2026-05-12 |
| CVE-2026-8522 | Chromium: CVE-2026-8522 Use after free in Downloads | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-8574 | Chromium: CVE-2026-8574 Use after free in Core | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9116 | Chromium: CVE-2026-9116 Insufficient policy enforcement in ServiceWorker | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9117 | Chromium: CVE-2026-9117 Type Confusion in GFX | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-9118 | Chromium: CVE-2026-9118 Use after free in XR | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-9119 | Chromium: CVE-2026-9119 Heap buffer overflow in WebRTC | UNKNOWN | — | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-9120 | Chromium: CVE-2026-9120 Use after free in WebRTC | UNKNOWN | — | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-9122 | Chromium: CVE-2026-9121 Out of bounds read in GPU | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-9124 | Chromium: CVE-2026-9123 Heap buffer overflow in Chromecast | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-9123 | Chromium: CVE-2026-9122 Out of bounds read in GPU | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9121 | Chromium: CVE-2026-9126 Use after free in DOM | UNKNOWN | — | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-9126 | Chromium: CVE-2026-9124 Insufficient validation of untrusted input in Input | UNKNOWN | — | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-10003 | Chromium: CVE-2026-10003 Use after free in Views | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-10002 | Chromium: CVE-2026-10002 Use after free in PDFium | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-10004 | Chromium: CVE-2026-10004 Insufficient validation of untrusted input in Passwords | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-10001 | Chromium: CVE-2026-10001 Use after free in PerformanceManager | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2026-10007 | Chromium: CVE-2026-10007 Use after free in SVG | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-10006 | Chromium: CVE-2026-10006 Race in WebAudio | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-10005 | Chromium: CVE-2026-10005 Use after free in WebAppInstalls | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-9874 | Chromium: CVE-2026-9874 Use after free in Dawn | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9877 | Chromium: CVE-2026-9877 Use after free in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9878 | Chromium: CVE-2026-9878 Use after free in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-9873 | Chromium: CVE-2026-9873 Use after free in Network | UNKNOWN | — | 22%ile | Microsoft | 2026-05-12 |
| CVE-2026-9879 | Chromium: CVE-2026-9879 Out of bounds write in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-9881 | Chromium: CVE-2026-9881 Use after free in Bluetooth | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-9913 | Chromium: CVE-2026-9913 Inappropriate implementation in ANGLE | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9915 | Chromium: CVE-2026-9915 Heap buffer overflow in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9916 | Chromium: CVE-2026-9916 Out of bounds write in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9914 | Chromium: CVE-2026-9914 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9918 | Chromium: CVE-2026-9918 Inappropriate implementation in Tint | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9920 | Chromium: CVE-2026-9920 Uninitialized Use in GPU | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9924 | Chromium: CVE-2026-9924 Heap buffer overflow in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9923 | Chromium: CVE-2026-9923 Use after free in Skia | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9922 | Chromium: CVE-2026-9922 Use after free in GPU | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9925 | Chromium: CVE-2026-9925 Use after free in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9926 | Chromium: CVE-2026-9926 Heap buffer overflow in ANGLE | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9928 | Chromium: CVE-2026-9928 Out of bounds read in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9927 | Chromium: CVE-2026-9927 Use after free in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9930 | Chromium: CVE-2026-9930 Out of bounds write in Dawn | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9931 | Chromium: CVE-2026-9931 Use after free in GPU | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9932 | Chromium: CVE-2026-9932 Use after free in ANGLE | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9933 | Chromium: CVE-2026-9933 Use after free in Input | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9937 | Chromium: CVE-2026-9937 Use after free in UI | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9936 | Chromium: CVE-2026-9936 Use after free in GFX | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9935 | Chromium: CVE-2026-9935 Uninitialized Use in ANGLE | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9934 | Chromium: CVE-2026-9934 Use after free in Aura | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9938 | Chromium: CVE-2026-9938 Inappropriate implementation in V8 | UNKNOWN | — | 24%ile | Microsoft | 2026-05-12 |
| CVE-2026-9939 | Chromium: CVE-2026-9939 Heap buffer overflow in WebCodecs | UNKNOWN | — | 34%ile | Microsoft | 2026-05-12 |
| CVE-2026-9940 | Chromium: CVE-2026-9940 Heap buffer overflow in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2026-05-12 |
| CVE-2026-9958 | Chromium: CVE-2026-9958 Use after free in PDFium | UNKNOWN | — | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-9957 | Chromium: CVE-2026-9957 Use after free in PDF | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-9960 | Chromium: CVE-2026-9960 Integer overflow in PDFium | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9959 | Chromium: CVE-2026-9959 Race in WebRTC | UNKNOWN | — | 4%ile | Microsoft | 2026-05-12 |
| CVE-2026-10020 | Chromium: CVE-2026-10020 Insufficient validation of untrusted input in Skia | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-9977 | Chromium: CVE-2026-9977 Insufficient validation of untrusted input in WebShare | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-9971 | Chromium: CVE-2026-9971 Inappropriate implementation in iOS | UNKNOWN | — | 6%ile | Microsoft | 2026-05-12 |
| CVE-2026-9969 | Chromium: CVE-2026-9969 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-9963 | Chromium: CVE-2026-9963 Uninitialized Use in iOS | UNKNOWN | — | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-9956 | Chromium: CVE-2026-9956 Use after free in iOS | UNKNOWN | — | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-9955 | Chromium: CVE-2026-9955 Inappropriate implementation in iOS | UNKNOWN | — | 9%ile | Microsoft | 2026-05-12 |
| CVE-2026-9950 | Chromium: CVE-2026-9950 Insufficient validation of untrusted input in iOS | UNKNOWN | — | 10%ile | Microsoft | 2026-05-12 |
| CVE-2026-9947 | Chromium: CVE-2026-9947 Use after free in XML | UNKNOWN | — | 23%ile | Microsoft | 2026-05-12 |
| CVE-2026-9943 | Chromium: CVE-2026-9943 Out of bounds read in WebGL | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9929 | Chromium: CVE-2026-9929 Inappropriate implementation in WebGL | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9921 | Chromium: CVE-2026-9921 Uninitialized Use in WebGL | UNKNOWN | — | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-9919 | Chromium: CVE-2026-9919 Out of bounds read in WebGL | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9917 | Chromium: CVE-2026-9917 Uninitialized Use in WebGL | UNKNOWN | — | 19%ile | Microsoft | 2026-05-12 |
| CVE-2026-9912 | Chromium: CVE-2026-9912 Inappropriate implementation in GPU | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9911 | Chromium: CVE-2026-9911 Integer overflow in ANGLE | UNKNOWN | — | 11%ile | Microsoft | 2026-05-12 |
| CVE-2026-9898 | Chromium: CVE-2026-9898 Insufficient validation of untrusted input in GPU | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9889 | Chromium: CVE-2026-9889 Out of bounds read and write in Dawn | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9888 | Chromium: CVE-2026-9888 Use after free in WebView | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-9880 | Chromium: CVE-2026-9880 Insufficient validation of untrusted input in WebGL | UNKNOWN | — | 14%ile | Microsoft | 2026-05-12 |
| CVE-2026-9876 | Chromium: CVE-2026-9876 Use after free in WebGL | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-9875 | Chromium: CVE-2026-9875 Out of bounds read in WebGL | UNKNOWN | — | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-8510 | Chromium: CVE-2026-8510 Integer overflow in Skia | UNKNOWN | — | 12%ile | Microsoft | 2026-05-12 |
| CVE-2026-10000 | Chromium: CVE-2026-10000 Use after free in Passwords | UNKNOWN | — | 8%ile | Microsoft | 2026-05-12 |
| CVE-2026-33819 | Microsoft Bing Remote Code Execution Vulnerability | CRITICAL | 10.0 | 54%ile | Microsoft | 2026-04-14 |
| CVE-2026-32186 | Microsoft Bing Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 50%ile | Microsoft | 2026-04-14 |
| CVE-2026-33107 | Azure Databricks Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 50%ile | Microsoft | 2026-04-14 |
| CVE-2026-35431 | Microsoft Entra ID Entitlement Management Spoofing Vulnerability | CRITICAL | 10.0 | 41%ile | Microsoft | 2026-04-14 |
| CVE-2026-32213 | Azure AI Foundry Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 57%ile | Microsoft | 2026-04-14 |
| CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 50%ile | Microsoft | 2026-04-14 |
| CVE-2026-40175 | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain | CRITICAL | 10.0 | 77%ile | Microsoft | 2026-04-14 |
| CVE-2026-21515 | Azure IoT Central Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 50%ile | Microsoft | 2026-04-14 |
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99%ile | Microsoft | 2026-04-14 |
| CVE-2026-31657 | batman-adv: hold claim backbone gateways by reference | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-04-14 |
| CVE-2026-31669 | mptcp: fix slab-use-after-free in __inet_lookup_established | CRITICAL | 9.8 | 38%ile | Microsoft | 2026-04-14 |
| CVE-2026-31659 | batman-adv: reject oversized global TT response buffers | CRITICAL | 9.8 | 33%ile | Microsoft | 2026-04-14 |
| CVE-2026-27143 | Missing bound checks can lead to memory corruption in safe Go in cmd/compile | CRITICAL | 9.8 | 42%ile | Microsoft | 2026-04-14 |
| CVE-2026-27140 | Code execution vulnerability in SWIG code generation in cmd/go | CRITICAL | 9.8 | 48%ile | Microsoft | 2026-04-14 |
| CVE-2026-5450 | scanf %mc off-by-one heap buffer overflow | CRITICAL | 9.8 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-31478 | ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() | CRITICAL | 9.8 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-31607 | usbip: validate number_of_packets in usbip_pack_ret_submit() | CRITICAL | 9.8 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-31668 | seg6: separate dst_cache for input and output paths in seg6 lwtunnel | CRITICAL | 9.8 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-24303 | Microsoft Partner Center Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-26135 | Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability | CRITICAL | 9.6 | 45%ile | Microsoft | 2026-04-14 |
| CVE-2026-32210 | Microsoft Dynamics 365 (online) Spoofing Vulnerability | CRITICAL | 9.3 | 45%ile | Microsoft | 2026-04-14 |
| CVE-2026-33102 | Microsoft 365 Copilot Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 33%ile | Microsoft | 2026-04-14 |
| CVE-2026-40372 | ASP.NET Core Elevation of Privilege Vulnerability | CRITICAL | 9.1 | 96%ile | Microsoft | 2026-04-14 |
| CVE-2026-32211 | Azure MCP Server Information Disclosure Vulnerability | CRITICAL | 9.1 | 54%ile | Microsoft | 2026-04-14 |
| CVE-2026-26149 | Microsoft Power Apps Desktop Client Spoofing Vulnerability | CRITICAL | 9.0 | 44%ile | Microsoft | 2026-04-14 |
| CVE-2026-26167 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 8.8 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-32157 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2026-04-14 |
| CVE-2026-33120 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 50%ile | Microsoft | 2026-04-14 |
| CVE-2026-26178 | Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability | HIGH | 8.8 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-32171 | Azure Logic Apps Elevation of Privilege Vulnerability | HIGH | 8.8 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-32225 | Windows Shell Security Feature Bypass Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2026-04-14 |
| CVE-2026-41445 | KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc() | HIGH | 8.8 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-31593 | KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU | HIGH | 8.8 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31570 | can: gw: fix OOB heap access in cgw_csum_crc8_rel() | HIGH | 8.8 | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-31629 | nfc: llcp: add missing return after LLCP_CLOSED checks | HIGH | 8.8 | 13%ile | Microsoft | 2026-04-14 |
| CVE-2026-31622 | NFC: digital: Bounds check NFC-A cascade depth in SDD response handler | HIGH | 8.8 | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-35093 | Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins | HIGH | 8.8 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-31588 | KVM: x86: Use scratch field in MMIO fragment to hold small write values | HIGH | 8.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-27928 | Windows Hello Security Feature Bypass Vulnerability | HIGH | 8.7 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-32173 | Azure SRE Agent Information Disclosure Vulnerability | HIGH | 8.6 | 56%ile | Microsoft | 2026-04-14 |
| CVE-2026-26150 | Microsoft Purview eDiscovery Elevation of Privilege Vulnerability | HIGH | 8.6 | 44%ile | Microsoft | 2026-04-14 |
| CVE-2026-34445 | ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. | HIGH | 8.6 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-5435 | Potential buffer overflow in ns_sprintrrf TSIG handling path | HIGH | 8.6 | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-32221 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 8.4 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-32091 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 8.4 | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-32162 | Windows COM Elevation of Privilege Vulnerability | HIGH | 8.4 | 79%ile | Microsoft | 2026-04-14 |
| CVE-2026-32190 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-33114 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-33115 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-23401 | KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE | HIGH | 8.4 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-40706 | CVE-2026-40706 | HIGH | 8.4 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-34982 | Vim modeline bypass via various options affects Vim < 9.2.0276 | HIGH | 8.2 | 38%ile | Microsoft | 2026-04-14 |
| CVE-2026-31476 | ksmbd: do not expire session on binding failure | HIGH | 8.2 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-32316 | jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow | HIGH | 8.2 | 39%ile | Microsoft | 2026-04-14 |
| CVE-2026-41604 | Apache Thrift: Swift Range crash in skip() | HIGH | 8.2 | 57%ile | Microsoft | 2026-04-14 |
| CVE-2026-33827 | Windows TCP/IP Remote Code Execution Vulnerability | HIGH | 8.1 | 54%ile | Microsoft | 2026-04-14 |
| CVE-2026-28387 | Potential Use-after-free in DANE Client Code | HIGH | 8.1 | 53%ile | Microsoft | 2026-04-14 |
| CVE-2026-40393 | CVE-2026-40393 | HIGH | 8.1 | 35%ile | Microsoft | 2026-04-14 |
| CVE-2026-31416 | netfilter: nfnetlink_log: account for netlink header size | HIGH | 8.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31418 | netfilter: ipset: drop logically empty buckets in mtype_del | HIGH | 8.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-35469 | SpdyStream: DOS on CRI | HIGH | 8.1 | 48%ile | Microsoft | 2026-04-14 |
| CVE-2026-31417 | net/x25: Fix overflow when accumulating packets | HIGH | 8.1 | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-31414 | netfilter: nf_conntrack_expect: use expect->helper | HIGH | 8.1 | 33%ile | Microsoft | 2026-04-14 |
| CVE-2026-6100 | Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure | HIGH | 8.1 | 44%ile | Microsoft | 2026-04-14 |
| CVE-2026-33826 | Windows Active Directory Remote Code Execution Vulnerability | HIGH | 8.0 | 42%ile | Microsoft | 2026-04-14 |
| CVE-2026-27912 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 8.0 | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-32172 | Microsoft Power Apps Remote Code Execution Vulnerability | HIGH | 8.0 | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-20930 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-26160 | Remote Desktop Licensing Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-26161 | Windows Sensor Data Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-26162 | Windows OLE Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-26179 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-26180 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-26181 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 14%ile | Microsoft | 2026-04-14 |
| CVE-2026-26183 | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-27907 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-27915 | Windows UPnP Device Host Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-27918 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.8 | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-27919 | Windows UPnP Device Host Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-27924 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-27927 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-32089 | Windows Speech Brokered Api Elevation of Privilege Vulnerability | HIGH | 7.8 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-32090 | Windows Speech Brokered Api Elevation of Privilege Vulnerability | HIGH | 7.8 | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-32152 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-04-14 |
| CVE-2026-32154 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2026-04-14 |
| CVE-2026-32158 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-32159 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-32160 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-32165 | Windows User Interface Core Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-32168 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-32184 | Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-04-14 |
| CVE-2026-32189 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-32192 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2026-04-14 |
| CVE-2026-32222 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-33095 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-33098 | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-33825 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 93%ile | Microsoft | 2026-04-14 |
| CVE-2026-23657 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-26143 | Microsoft PowerShell Security Feature Bypass Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-04-14 |
| CVE-2026-26153 | Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-26156 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-26159 | Remote Desktop Licensing Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-26163 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-26170 | PowerShell Elevation of Privilege Vulnerability | HIGH | 7.8 | 14%ile | Microsoft | 2026-04-14 |
| CVE-2026-26172 | Windows Push Notifications Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-26176 | Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability | HIGH | 7.8 | 14%ile | Microsoft | 2026-04-14 |
| CVE-2026-26184 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-27909 | Windows Search Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 76%ile | Microsoft | 2026-04-14 |
| CVE-2026-27910 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-27911 | Windows User Interface Core Elevation of Privilege Vulnerability | HIGH | 7.8 | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-27914 | Microsoft Management Console Elevation of Privilege Vulnerability | HIGH | 7.8 | 84%ile | Microsoft | 2026-04-14 |
| CVE-2026-27916 | Windows UPnP Device Host Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-27920 | Windows UPnP Device Host Elevation of Privilege Vulnerability | HIGH | 7.8 | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-27923 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 14%ile | Microsoft | 2026-04-14 |
| CVE-2026-32069 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-32074 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-32076 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-32077 | Windows UPnP Device Host Elevation of Privilege Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-32153 | Windows Speech Runtime Elevation of Privilege Vulnerability | HIGH | 7.8 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-32155 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-32163 | Windows User Interface Core Elevation of Privilege Vulnerability | HIGH | 7.8 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-32164 | Windows User Interface Core Elevation of Privilege Vulnerability | HIGH | 7.8 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-32197 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-32198 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-32199 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-32200 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-33101 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.8 | 13%ile | Microsoft | 2026-04-14 |
| CVE-2026-32078 | Windows Projected File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-39853 | osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification | HIGH | 7.8 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-31427 | netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp | HIGH | 7.8 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31454 | xfs: save ailp before dropping the AIL lock in push callbacks | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31432 | ksmbd: fix OOB write in QUERY_INFO for compound requests | HIGH | 7.8 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-31502 | team: fix header_ops type confusion with non-Ethernet ports | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31530 | cxl/port: Fix use after free of parent_port in cxl_detach_ep() | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31493 | RDMA/efa: Fix use of completion ctx after free | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-23447 | net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31617 | usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31589 | mm: call ->free_folio() directly in folio_unmap_invalidate() | HIGH | 7.8 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-23422 | dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler | HIGH | 7.8 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31663 | xfrm: hold dev ref until after transport_finish NF_HOOK | HIGH | 7.8 | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-31580 | bcache: fix cached_dev.sb_bio use-after-free and crash | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31630 | rxrpc: proc: size address buffers for %pISpc output | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31576 | media: hackrf: fix to not free memory after the device is registered in hackrf_probe() | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31586 | mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31578 | media: as102: fix to not free memory after the device is registered in as102_usb_probe() | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31656 | drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat | HIGH | 7.8 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31408 | Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold | HIGH | 7.8 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-23406 | apparmor: fix side-effect bug in match_char() macro usage | HIGH | 7.8 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-23407 | apparmor: fix missing bounds check on DEFAULT table in verify_dfa() | HIGH | 7.8 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-23408 | apparmor: Fix double free of ns_name in aa_replace_profiles() | HIGH | 7.8 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-23410 | apparmor: fix race on rawdata dereference | HIGH | 7.8 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-23411 | apparmor: fix race between freeing data and fs accessing it | HIGH | 7.8 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2025-14821 | Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31430 | X.509: Fix out-of-bounds access when parsing extensions | HIGH | 7.8 | 0%ile | Microsoft | 2026-04-14 |
| CVE-2026-31516 | xfrm: prevent policy_hthresh.work from racing with netns teardown | HIGH | 7.8 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31527 | driver core: platform: use generic driver_override infrastructure | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31506 | net: bcmasp: fix double free of WoL irq | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31504 | net: fix fanout UAF in packet_release() via NETDEV_UP race | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31446 | ext4: fix use-after-free in update_super_work when racing with umount | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31433 | ksmbd: fix potencial OOB in get_file_all_info() for compound requests | HIGH | 7.8 | 45%ile | Microsoft | 2026-04-14 |
| CVE-2026-31485 | spi: spi-fsl-lpspi: fix teardown order issue (UAF) | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31483 | s390/syscalls: Add spectre boundary for syscall dispatch table | HIGH | 7.8 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31507 | net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31500 | Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31494 | net: macb: use the current queue number for stats | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31473 | media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31532 | can: raw: fix ro->uniq use-after-free in raw_rcv() | HIGH | 7.8 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-23428 | ksmbd: fix use-after-free of share_conf in compound request | HIGH | 7.8 | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-31583 | media: em28xx: fix use-after-free in em28xx_v4l2_open() | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31581 | ALSA: 6fire: fix use-after-free on disconnect | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31609 | smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() | HIGH | 7.8 | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-31582 | hwmon: (powerz) Fix use-after-free on USB disconnect | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31675 | net/sched: sch_netem: fix out-of-bounds access in packet corruption | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31688 | driver core: enforce device_lock for driver_match_device() | HIGH | 7.8 | — | Microsoft | 2026-04-14 |
| CVE-2026-31548 | wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31584 | media: mediatek: vcodec: fix use-after-free in encoder release path | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31648 | mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() | HIGH | 7.8 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-34001 | Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption | HIGH | 7.8 | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-31508 | net: openvswitch: Avoid releasing netdev before teardown completes | HIGH | 7.8 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-32183 | Windows Snipping Tool Remote Code Execution Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2026-04-14 |
| CVE-2026-26168 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-27913 | Windows BitLocker Security Feature Bypass Vulnerability | HIGH | 7.7 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-27144 | Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile | HIGH | 7.7 | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-26154 | Windows Server Update Service (WSUS) Tampering Vulnerability | HIGH | 7.5 | 61%ile | Microsoft | 2026-04-14 |
| CVE-2026-32071 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | HIGH | 7.5 | 61%ile | Microsoft | 2026-04-14 |
| CVE-2026-32178 | .NET Spoofing Vulnerability | HIGH | 7.5 | 81%ile | Microsoft | 2026-04-14 |
| CVE-2026-33096 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 66%ile | Microsoft | 2026-04-14 |
| CVE-2026-33116 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | HIGH | 7.5 | 80%ile | Microsoft | 2026-04-14 |
| CVE-2026-21637 | HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers | HIGH | 7.5 | 61%ile | Microsoft | 2026-04-14 |
| CVE-2026-23666 | .NET Framework Denial of Service Vulnerability | HIGH | 7.5 | 68%ile | Microsoft | 2026-04-14 |
| CVE-2026-26171 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 76%ile | Microsoft | 2026-04-14 |
| CVE-2026-28388 | NULL Pointer Dereference When Processing a Delta CRL | HIGH | 7.5 | 61%ile | Microsoft | 2026-04-14 |
| CVE-2026-29181 | OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) | HIGH | 7.5 | 44%ile | Microsoft | 2026-04-14 |
| CVE-2026-40164 | jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed | HIGH | 7.5 | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-5928 | Static buffer overflow in deprecated nis_local_principal | HIGH | 7.5 | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-31477 | ksmbd: fix memory leaks and NULL deref in smb2_lock() | HIGH | 7.5 | 39%ile | Microsoft | 2026-04-14 |
| CVE-2026-41066 | lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files | HIGH | 7.5 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-31662 | tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG | HIGH | 7.5 | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-35385 | CVE-2026-35385 | HIGH | 7.5 | 46%ile | Microsoft | 2026-04-14 |
| CVE-2026-34601 | xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion | HIGH | 7.5 | 38%ile | Microsoft | 2026-04-14 |
| CVE-2026-35611 | Addressable has a Regular Expression Denial of Service in Addressable templates | HIGH | 7.5 | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-28389 | Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo | HIGH | 7.5 | 60%ile | Microsoft | 2026-04-14 |
| CVE-2026-28390 | Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo | HIGH | 7.5 | 60%ile | Microsoft | 2026-04-14 |
| CVE-2026-32283 | Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls | HIGH | 7.5 | 46%ile | Microsoft | 2026-04-14 |
| CVE-2026-32280 | Unexpected work during chain building in crypto/x509 | HIGH | 7.5 | 46%ile | Microsoft | 2026-04-14 |
| CVE-2026-40890 | github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer | HIGH | 7.5 | 27%ile | Microsoft | 2026-04-14 |
| CVE-2026-6507 | Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing | HIGH | 7.5 | 39%ile | Microsoft | 2026-04-14 |
| CVE-2026-31552 | wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom | HIGH | 7.5 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-31563 | net: macb: Use dev_consume_skb_any() to free TX SKBs | HIGH | 7.5 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-41602 | Apache Thrift: Go TFramedTransport uint32 overflow | HIGH | 7.5 | 64%ile | Microsoft | 2026-04-14 |
| CVE-2026-32156 | Windows UPnP Device Host Remote Code Execution Vulnerability | HIGH | 7.4 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-32631 | GitHub: CVE-2026-32631 'git clone' from manipulated repositories can leak NTLM hashes | HIGH | 7.4 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-35535 | CVE-2026-35535 | HIGH | 7.4 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-41603 | Apache Thrift: Java TSSLTransportFactory hostname verification | HIGH | 7.4 | — | Microsoft | 2026-04-14 |
| CVE-2026-41035 | CVE-2026-41035 | HIGH | 7.4 | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-32149 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 7.3 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-31789 | Heap Buffer Overflow in Hexadecimal Conversion | HIGH | 7.3 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-31619 | ALSA: fireworks: bound device-supplied status before string array lookup | HIGH | 7.3 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-41605 | Apache Thrift: Swift Compact Protocol integer overflow | HIGH | 7.3 | 57%ile | Microsoft | 2026-04-14 |
| CVE-2026-26151 | Remote Desktop Spoofing Vulnerability | HIGH | 7.1 | 54%ile | Microsoft | 2026-04-14 |
| CVE-2026-32188 | Microsoft Excel Information Disclosure Vulnerability | HIGH | 7.1 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-31407 | netfilter: conntrack: add missing netlink policy validations | HIGH | 7.1 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-31419 | net: bonding: fix use-after-free in bond_xmit_broadcast() | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31464 | scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() | HIGH | 7.1 | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-31512 | Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31624 | HID: core: clamp report_size in s32ton() to avoid undefined shift | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31626 | staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() | HIGH | 7.1 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-31537 | smb: server: make use of smbdirect_socket.send_io.bcredits | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31608 | smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() | HIGH | 7.1 | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-31611 | ksmbd: require 3 sub-authorities before reading sub_auth[2] | HIGH | 7.1 | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-31627 | i2c: s3c24xx: check the size of the SMBUS message before using it | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31612 | ksmbd: validate EaNameLength in smb2_get_ea() | HIGH | 7.1 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-31568 | s390/mm: Add missing secure storage access fixups for donated memory | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31649 | net: stmmac: fix integer underflow in chain mode | HIGH | 7.1 | 38%ile | Microsoft | 2026-04-14 |
| CVE-2026-31682 | bridge: br_nd_send: linearize skb before parsing ND options | HIGH | 7.1 | 39%ile | Microsoft | 2026-04-14 |
| CVE-2026-31679 | openvswitch: validate MPLS set/set_masked payload length | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31674 | netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31686 | mm/kasan: fix double free for kasan pXds | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-23444 | wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-40024 | Sleuth Kit tsk_recover Path Traversal | HIGH | 7.1 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-23409 | apparmor: fix differential encoding verification | HIGH | 7.1 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-31523 | nvme-pci: ensure we're polling a polled queue | HIGH | 7.1 | 0%ile | Microsoft | 2026-04-14 |
| CVE-2026-31505 | iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31469 | virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31449 | ext4: validate p_idx bounds in ext4_ext_correct_indexes | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31482 | s390/entry: Scrub r12 register on kernel entry | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31518 | esp: fix skb leak with espintcp and async crypto | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31519 | btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31528 | perf: Make sure to use pmu_ctx->pmu for groups | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31525 | bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31492 | RDMA/irdma: Initialize free_qp completion before using it | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31536 | smb: server: let send_done handle a completion without IB_SEND_SIGNALED | HIGH | 7.1 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-31616 | usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31658 | net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() | HIGH | 7.1 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-34003 | Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access | HIGH | 7.1 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-25184 | Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-26165 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-26166 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-26174 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-27908 | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability | HIGH | 7.0 | 73%ile | Microsoft | 2026-04-14 |
| CVE-2026-27917 | Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-27921 | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability | HIGH | 7.0 | 65%ile | Microsoft | 2026-04-14 |
| CVE-2026-27926 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-27929 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-32073 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-32075 | Windows UPnP Device Host Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2026-04-14 |
| CVE-2026-32082 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-32083 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-32087 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-32093 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 63%ile | Microsoft | 2026-04-14 |
| CVE-2026-32195 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-32219 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-32224 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | HIGH | 7.0 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-26152 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2026-04-14 |
| CVE-2026-26173 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-26177 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-26182 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-27922 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-32068 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-32070 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-32080 | Windows WalletService Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-04-14 |
| CVE-2026-32086 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-32150 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-33099 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-33100 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-33104 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-31448 | ext4: avoid infinite loops caused by residual data | HIGH | 7.0 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-31480 | tracing: Fix potential deadlock in cpu hotplug with osnoise | HIGH | 7.0 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31450 | ext4: publish jinode after initialization | HIGH | 7.0 | 42%ile | Microsoft | 2026-04-14 |
| CVE-2026-31521 | module: Fix kernel panic when a symbol st_shndx is out of bounds | HIGH | 7.0 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31557 | nvmet: move async event work off nvmet-wq | HIGH | 7.0 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-31667 | Input: uinput - fix circular locking dependency with ff-core | HIGH | 7.0 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31637 | rxrpc: reject undecryptable rxkad response tickets | HIGH | 7.0 | 41%ile | Microsoft | 2026-04-14 |
| CVE-2026-31591 | KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish | HIGH | 7.0 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31628 | x86/CPU: Fix FPDSS on Zen1 | HIGH | 7.0 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31487 | spi: use generic driver_override infrastructure | HIGH | 7.0 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31515 | af_key: validate families in pfkey_send_migrate() | HIGH | 7.0 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31498 | Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop | HIGH | 7.0 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31453 | xfs: avoid dereferencing log items after push callbacks | HIGH | 7.0 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31555 | futex: Clear stale exiting pointer in futex_lock_pi() retry path | HIGH | 7.0 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31638 | rxrpc: Only put the call ref if one was acquired | HIGH | 7.0 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-31613 | smb: client: fix OOB reads parsing symlink error response | HIGH | 7.0 | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-32223 | Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 41%ile | Microsoft | 2026-04-14 |
| CVE-2026-0390 | UEFI Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-32167 | SQL Server Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-32176 | SQL Server Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-4878 | Libcap: libcap: privilege escalation via toctou race condition in cap_set_file() | MEDIUM | 6.7 | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-31566 | drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib | MEDIUM | 6.6 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-41411 | Vim: Command injection via backtick expansion in tag filenames | MEDIUM | 6.6 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-31587 | ASoC: qcom: q6apm: move component registration to unmanaged version | MEDIUM | 6.6 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31597 | ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY | MEDIUM | 6.6 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31592 | KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock | MEDIUM | 6.6 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-33999 | Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling | MEDIUM | 6.6 | 31%ile | Microsoft | 2026-04-14 |
| CVE-2026-31596 | ocfs2: handle invalid dinode in ocfs2_group_extend | MEDIUM | 6.6 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31665 | netfilter: nft_ct: fix use-after-free in timeout object destroy | MEDIUM | 6.6 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31623 | net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() | MEDIUM | 6.6 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-26155 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-04-14 |
| CVE-2026-27925 | Windows UPnP Device Host Information Disclosure Vulnerability | MEDIUM | 6.5 | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-32151 | Windows Shell Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2026-04-14 |
| CVE-2026-32201 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 97%ile | Microsoft | 2026-04-14 |
| CVE-2026-34978 | OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of | MEDIUM | 6.5 | 33%ile | Microsoft | 2026-04-14 |
| CVE-2026-31410 | ksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION | MEDIUM | 6.5 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-31790 | Incorrect Failure Handling in RSA KEM RSASVE Encapsulation | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-04-14 |
| CVE-2026-23405 | apparmor: fix: limit the number of levels of policy namespaces | MEDIUM | 6.5 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-34271 | CVE-2026-34271 | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-41607 | Apache Thrift: C++ JSON OOB read | MEDIUM | 6.5 | 56%ile | Microsoft | 2026-04-14 |
| CVE-2026-35549 | CVE-2026-35549 | MEDIUM | 6.5 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-22009 | CVE-2026-22009 | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-34270 | CVE-2026-34270 | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-22017 | CVE-2026-22017 | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-34303 | CVE-2026-34303 | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-34308 | CVE-2026-34308 | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-34276 | CVE-2026-34276 | MEDIUM | 6.5 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-6732 | Libxml2: libxml2: denial of service via crafted xsd-validated document | MEDIUM | 6.5 | 47%ile | Microsoft | 2026-04-14 |
| CVE-2026-6238 | Buffer overread in ns_printrrf with corrupted RDATA field | MEDIUM | 6.5 | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-40226 | CVE-2026-40226 | MEDIUM | 6.4 | 0%ile | Microsoft | 2026-04-14 |
| CVE-2026-40225 | CVE-2026-40225 | MEDIUM | 6.4 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-31488 | drm/amd/display: Do not skip unrelated mode changes in DSC validation | MEDIUM | 6.3 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-32072 | Active Directory Spoofing Vulnerability | MEDIUM | 6.2 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-33947 | jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted() | MEDIUM | 6.2 | 14%ile | Microsoft | 2026-04-14 |
| CVE-2025-48431 | Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. | MEDIUM | 6.2 | 62%ile | Microsoft | 2026-04-14 |
| CVE-2026-33822 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 6.1 | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-26169 | Windows Kernel Memory Information Disclosure Vulnerability | MEDIUM | 6.1 | 82%ile | Microsoft | 2026-04-14 |
| CVE-2026-32088 | Windows Biometric Service Security Feature Bypass Vulnerability | MEDIUM | 6.1 | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-32196 | Windows Admin Center Spoofing Vulnerability | MEDIUM | 6.1 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-39956 | jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure | MEDIUM | 6.1 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-32289 | JsBraceDepth Context Tracking Bugs (XSS) in html/template | MEDIUM | 6.1 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-35199 | SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation | MEDIUM | 6.1 | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-40255 | @adonisjs/http-server has an Open Redirect vulnerability | MEDIUM | 6.1 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-5160 | CVE-2026-5160 | MEDIUM | 6.1 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-41305 | PostCSS has XSS via Unescaped </style> in its CSS Stringify Output | MEDIUM | 6.1 | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-6861 | Emacs: emacs: memory corruption vulnerability when processing svg css | MEDIUM | 6.1 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-25250 | MITRE: CVE-2026-25250 Secure Boot disable Eazy Fix | MEDIUM | 6.0 | — | Microsoft | 2026-04-14 |
| CVE-2026-33810 | Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 | MEDIUM | 5.9 | 27%ile | Microsoft | 2026-04-14 |
| CVE-2026-32281 | Inefficient policy validation in crypto/x509 | MEDIUM | 5.9 | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-35201 | Discount has an Out-of-bounds Read in rdiscount | MEDIUM | 5.9 | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-31429 | net: skb: fix cross-cache free of KFENCE-allocated skb head | MEDIUM | 5.9 | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-32226 | .NET Framework Denial of Service Vulnerability | MEDIUM | 5.9 | 42%ile | Microsoft | 2026-04-14 |
| CVE-2026-23653 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | MEDIUM | 5.7 | 51%ile | Microsoft | 2026-04-14 |
| CVE-2026-23670 | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | MEDIUM | 5.7 | 17%ile | Microsoft | 2026-04-14 |
| CVE-2025-13763 | Libopensc: opensc: multiple uses of uninitialized variable | MEDIUM | 5.7 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-31431 | crypto: algif_aead - Revert to operating out-of-place | MEDIUM | 5.5 | 100%ile | Microsoft | 2026-04-14 |
| CVE-2026-27931 | Windows GDI Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-04-14 |
| CVE-2026-32081 | Package Catalog Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-04-14 |
| CVE-2026-32085 | Remote Procedure Call Information Disclosure Vulnerability | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-32181 | Connected User Experiences and Telemetry Service Denial of Service Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-32215 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-04-14 |
| CVE-2026-32216 | Windows Redirected Drive Buffering System Denial of Service Vulnerability | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-32217 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2026-04-14 |
| CVE-2026-32218 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-32212 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | MEDIUM | 5.5 | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-20806 | Windows COM Server Information Disclosure Vulnerability | MEDIUM | 5.5 | 27%ile | Microsoft | 2026-04-14 |
| CVE-2026-27930 | Windows GDI Information Disclosure Vulnerability | MEDIUM | 5.5 | 31%ile | Microsoft | 2026-04-14 |
| CVE-2026-32079 | Web Account Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-32084 | Windows Print Spooler Information Disclosure Vulnerability | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-33103 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-04-14 |
| CVE-2026-32214 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | MEDIUM | 5.5 | 13%ile | Microsoft | 2026-04-14 |
| CVE-2026-31394 | mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-23468 | drm/amdgpu: Limit BO list entry count to prevent resource exhaustion | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-23442 | ipv6: add NULL checks for idev in SRv6 paths | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-34933 | Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon | MEDIUM | 5.5 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-39855 | osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-39856 | osslsigncode has an Out-of-Bounds Read via Unvalidated Section Bounds in PE Page Hash Calculation | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-31423 | net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31424 | netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31421 | net/sched: cls_fw: fix NULL pointer dereference on shared blocks | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31428 | netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31452 | ext4: convert inline data to extents when truncate exceeds inline size | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31455 | xfs: stop reclaim before pushing AIL during unmount | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31474 | can: isotp: fix tx.buf use-after-free in isotp_sendmsg() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31461 | drm/amd/display: Fix drm_edid leak in amdgpu_dm | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31441 | dmaengine: idxd: Fix memory leak when a wq is reset | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31495 | netfilter: ctnetlink: use netlink policy range checks | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31439 | dmaengine: xilinx: xdma: Fix regmap init error handling | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31531 | ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() | MEDIUM | 5.5 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-23438 | net: mvpp2: guard flow control update with global_tx_fc in buffer switching | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-23439 | udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-23446 | net: usb: aqc111: Do not perform PM inside suspend callback | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31606 | usb: gadget: f_hid: don't call cdev_init while cdev in use | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31646 | net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31590 | KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31618 | fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31660 | nfc: pn533: allocate rx skb before consuming bytes | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31605 | fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31599 | media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31602 | ALSA: ctxfi: Limit PTP to a single page | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31651 | mmc: vub300: fix NULL-deref on disconnect | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-23420 | wifi: wlcore: Fix a locking bug | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31672 | wifi: rt2x00usb: fix devres lifetime | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31565 | RDMA/irdma: Fix deadlock during netdev reset with active connections | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31621 | bnge: return after auxiliary_device_uninit() in error path | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31615 | usb: gadget: renesas_usb3: validate endpoint index in standard request handlers | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31610 | ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-31645 | net: lan966x: fix page pool leak in error paths | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31598 | ocfs2: fix possible deadlock between unlink and dio_end_io_write | MEDIUM | 5.5 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-23414 | tls: Purge async_hold in tls_decrypt_async_wait() | MEDIUM | 5.5 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-31603 | staging: sm750fb: fix division by zero in ps_to_hz() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31600 | arm64: mm: Handle invalid large leaf mappings correctly | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-31671 | xfrm_user: fix info leak in build_report() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31560 | spi: spi-dw-dma: fix print error log when wait finish transaction | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31575 | mm/userfaultfd: fix hugetlb fault mutex hash calculation | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31639 | rxrpc: Fix key reference count leak from call->key | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31579 | wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31655 | pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31685 | netfilter: ip6t_eui64: reject invalid MAC header for all packets | MEDIUM | 5.5 | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-31680 | net: ipv6: flowlabel: defer exclusive option free until RCU teardown | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31678 | openvswitch: defer tunnel netdev_put to RCU release | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31595 | PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31681 | netfilter: xt_multiport: validate range encoding in checkentry | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31625 | HID: alps: fix NULL pointer dereference in alps_raw_event() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31673 | af_unix: read UNIX_DIAG_VFS data under unix_state_lock | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31664 | xfrm: clear trailing padding in build_polexpire() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31545 | NFC: nxp-nci: allow GPIOs to sleep | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31546 | net: bonding: fix NULL deref in bond_debug_rlb_hash_show | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-23472 | serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-23403 | apparmor: fix memory leak in verify_header | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-23404 | apparmor: replace recursive profile removal with iterative approach | MEDIUM | 5.5 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-32288 | Unbounded allocation for old GNU sparse in archive/tar | MEDIUM | 5.5 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-31422 | net/sched: cls_flow: fix NULL pointer dereference on shared blocks | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31426 | ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31420 | bridge: mrp: reject zero test interval to avoid OOM panic | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31524 | HID: asus: avoid memory leak in asus_report_fixup() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31486 | hwmon: (pmbus/core) Protect regulator operations with mutex | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31496 | netfilter: nf_conntrack_expect: skip expectations in other netns via proc | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31458 | mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0] | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31462 | drm/amdgpu: prevent immediate PASID reuse case | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31497 | Bluetooth: btusb: clamp SCO altsetting table indices | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31440 | dmaengine: idxd: Fix leaking event log memory | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31489 | spi: meson-spicc: Fix double-put in remove path | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31510 | Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31520 | HID: apple: avoid memory leak in apple_report_fixup() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31447 | ext4: reject mount if bigalloc with s_first_data_block != 0 | MEDIUM | 5.5 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-31444 | ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() | MEDIUM | 5.5 | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-31522 | HID: magicmouse: avoid memory leak in magicmouse_report_fixup() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31509 | nfc: nci: fix circular locking dependency in nci_close_device | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31451 | ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31503 | udp: Fix wildcard bind conflict check when using hash2 | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31467 | erofs: add GFP_NOIO in the bio completion if needed | MEDIUM | 5.5 | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-23434 | mtd: rawnand: serialize lock/unlock against other NAND operations | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31574 | clockevents: Add missing resets of the next_event_forced flag | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-31604 | wifi: rtw88: fix device leak on probe failure | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31585 | media: vidtv: fix nfeeds state corruption on start_streaming failure | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31577 | nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31670 | net: rfkill: prevent unlimited numbers of rfkill events from being created | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31642 | rxrpc: Fix call removal to use RCU safe deletion | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31594 | PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31601 | vfio/xe: Reorganize the init to decouple migration from reset | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31676 | rxrpc: only handle RESPONSE during service challenge | MEDIUM | 5.5 | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-31677 | crypto: af_alg - limit RX SG extraction by receive buffer budget | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31634 | rxrpc: fix reference count leak in rxrpc_server_keyring() | MEDIUM | 5.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-31684 | net: sched: act_csum: validate nested VLAN headers | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31689 | EDAC/mc: Fix error path ordering in edac_mc_alloc() | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31549 | i2c: cp2615: fix serial string NULL-deref at probe | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31550 | pmdomain: bcm: bcm2835-power: Increase ASB control timeout | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31551 | wifi: mac80211: Fix static_branch_dec() underflow for aql_disable. | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31661 | wifi: brcmsmac: Fix dma_free_coherent() size | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31540 | drm/i915/gt: Check set_default_submission() before deferencing | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-31499 | Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() | MEDIUM | 5.5 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-33119 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 5.4 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2023-20585 | AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability | MEDIUM | 5.3 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-32282 | TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix | MEDIUM | 5.3 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-34979 | OpenPrinting CUPS: Heap overflow in `get_options()` | MEDIUM | 5.3 | 31%ile | Microsoft | 2026-04-14 |
| CVE-2026-39882 | OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies | MEDIUM | 5.3 | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-41606 | Apache Thrift: c_glib dispatch stack overflow | MEDIUM | 5.3 | 62%ile | Microsoft | 2026-04-14 |
| CVE-2026-34757 | LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential | MEDIUM | 5.1 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-39881 | Vim Ex command injection in Vims NetBeans integration | MEDIUM | 5.0 | 46%ile | Microsoft | 2026-04-14 |
| CVE-2026-35239 | CVE-2026-35239 | MEDIUM | 4.9 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-35238 | CVE-2026-35238 | MEDIUM | 4.9 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-34267 | CVE-2026-34267 | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-22005 | CVE-2026-22005 | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-34278 | CVE-2026-34278 | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-21998 | CVE-2026-21998 | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-35237 | CVE-2026-35237 | MEDIUM | 4.9 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-34293 | CVE-2026-34293 | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-22002 | CVE-2026-22002 | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-34304 | CVE-2026-34304 | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-22004 | CVE-2026-22004 | MEDIUM | 4.9 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-35240 | CVE-2026-35240 | MEDIUM | 4.9 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-35236 | CVE-2026-35236 | MEDIUM | 4.9 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-27447 | OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup | MEDIUM | 4.8 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-41989 | CVE-2026-41989 | MEDIUM | 4.8 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-23473 | io_uring/poll: fix multishot recv missing EOF on wakeup race | MEDIUM | 4.7 | — | Microsoft | 2026-04-14 |
| CVE-2026-27456 | util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup | MEDIUM | 4.7 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-34446 | ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load | MEDIUM | 4.7 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-20945 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 98%ile | Microsoft | 2026-04-14 |
| CVE-2026-26175 | Windows Boot Manager Security Feature Bypass Vulnerability | MEDIUM | 4.6 | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-20928 | Windows Recovery Environment Security Feature Bypass Vulnerability | MEDIUM | 4.6 | 35%ile | Microsoft | 2026-04-14 |
| CVE-2026-27906 | Windows Hello Security Feature Bypass Vulnerability | MEDIUM | 4.4 | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-32220 | UEFI Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 4.4 | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-40026 | Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read | MEDIUM | 4.4 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-40025 | Sleuth Kit APFS Keybag Parser Out-of-Bounds Read | MEDIUM | 4.4 | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-33829 | Windows Snipping Tool Spoofing Vulnerability | MEDIUM | 4.3 | 88%ile | Microsoft | 2026-04-14 |
| CVE-2026-22015 | CVE-2026-22015 | MEDIUM | 4.3 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-41079 | OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users | MEDIUM | 4.3 | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-31620 | ALSA: usx2y: us144mkii: fix NULL deref on missing interface 0 | MEDIUM | 4.3 | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-5358 | Static buffer overflow in deprecated nis_local_principal | MEDIUM | 4.3 | — | Microsoft | 2026-04-14 |
| CVE-2026-33118 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 43%ile | Microsoft | 2026-04-14 |
| CVE-2026-32202 | Windows Shell Spoofing Vulnerability | MEDIUM | 4.3 | 99%ile | Microsoft | 2026-04-14 |
| CVE-2026-35414 | CVE-2026-35414 | MEDIUM | 4.2 | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-35177 | Path traversal issue with zip.vim in Vim | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-39314 | CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported` | MEDIUM | 4.0 | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-40385 | CVE-2026-40385 | MEDIUM | 4.0 | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-33555 | CVE-2026-33555 | MEDIUM | 4.0 | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-39316 | CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer | MEDIUM | 4.0 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-40386 | CVE-2026-40386 | MEDIUM | 4.0 | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-41254 | CVE-2026-41254 | MEDIUM | 4.0 | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-3184 | Util-linux: util-linux: access control bypass due to improper hostname canonicalization | LOW | 3.7 | 36%ile | Microsoft | 2026-04-14 |
| CVE-2026-2708 | Libsoup: libsoup: http request smuggling via duplicate content-length headers | LOW | 3.7 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-35386 | CVE-2026-35386 | LOW | 3.6 | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-41988 | CVE-2026-41988 | LOW | 3.2 | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-35387 | CVE-2026-35387 | LOW | 3.1 | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-41080 | CVE-2026-41080 | LOW | 2.9 | 33%ile | Microsoft | 2026-04-14 |
| CVE-2026-22001 | CVE-2026-22001 | LOW | 2.7 | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-35388 | CVE-2026-35388 | LOW | 2.5 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-5289 | Chromium: CVE-2026-5289 Use after free in Navigation | UNKNOWN | — | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-5286 | Chromium: CVE-2026-5286 Use after free in Dawn | UNKNOWN | — | 24%ile | Microsoft | 2026-04-14 |
| CVE-2026-5287 | Chromium: CVE-2026-5287 Use after free in PDF | UNKNOWN | — | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-5285 | Chromium: CVE-2026-5285 Use after free in WebGL | UNKNOWN | — | 33%ile | Microsoft | 2026-04-14 |
| CVE-2026-5284 | Chromium: CVE-2026-5284 Use after free in Dawn | UNKNOWN | — | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-5283 | Chromium: CVE-2026-5283 Inappropriate implementation in ANGLE | UNKNOWN | — | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-5281 | Chromium: CVE-2026-5281 Use after free in Dawn | UNKNOWN | — | 91%ile | Microsoft | 2026-04-14 |
| CVE-2026-5280 | Chromium: CVE-2026-5280 Use after free in WebCodecs | UNKNOWN | — | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-5279 | Chromium: CVE-2026-5279 Object corruption in V8 | UNKNOWN | — | 27%ile | Microsoft | 2026-04-14 |
| CVE-2026-6920 | Chromium: CVE-2026-6920 Out of bounds read in GPU | UNKNOWN | — | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-5292 | Chromium: CVE-2026-5292 Out of bounds read in WebCodecs | UNKNOWN | — | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-5291 | Chromium: CVE-2026-5291 Inappropriate implementation in WebGL | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5290 | Chromium: CVE-2026-5290 Use after free in Compositing | UNKNOWN | — | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-5277 | Chromium: CVE-2026-5277 Integer overflow in ANGLE | UNKNOWN | — | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-5276 | Chromium: CVE-2026-5276 Insufficient policy enforcement in WebUSB | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5275 | Chromium: CVE-2026-5275 Heap buffer overflow in ANGLE | UNKNOWN | — | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-5274 | Chromium: CVE-2026-5274 Integer overflow in Codecs | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-5273 | Chromium: CVE-2026-5273 Use after free in CSS | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-5272 | Chromium: CVE-2026-5272 Heap buffer overflow in GPU | UNKNOWN | — | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-5899 | Chromium: CVE-2026-5899 Incorrect security UI in History Navigation | UNKNOWN | — | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-5896 | Chromium: CVE-2026-5896 Policy bypass in Audio | UNKNOWN | — | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-5897 | Chromium: CVE-2026-5897 Incorrect security UI in Downloads | UNKNOWN | — | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-5898 | Chromium: CVE-2026-5898 Incorrect security UI in Omnibox | UNKNOWN | — | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-5894 | Chromium: CVE-2026-5894 Inappropriate implementation in PDF | UNKNOWN | — | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-5895 | Chromium: CVE-2026-5895 Incorrect security UI in Omnibox | UNKNOWN | — | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-5889 | Chromium: CVE-2026-5889 Cryptographic Flaw in PDFium | UNKNOWN | — | 1%ile | Microsoft | 2026-04-14 |
| CVE-2026-5892 | Chromium: CVE-2026-5892 Insufficient policy enforcement in PWAs | UNKNOWN | — | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-5890 | Chromium: CVE-2026-5890 Race in WebCodecs | UNKNOWN | — | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-5893 | Chromium: CVE-2026-5893 Race in V8 | UNKNOWN | — | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-5884 | Chromium: CVE-2026-5884 Insufficient validation of untrusted input in Media | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-5887 | Chromium: CVE-2026-5887 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5883 | Chromium: CVE-2026-5883 Use after free in Media | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-5879 | Chromium: CVE-2026-5879 Insufficient validation of untrusted input in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-5885 | Chromium: CVE-2026-5885 Insufficient validation of untrusted input in WebML | UNKNOWN | — | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-5891 | Chromium: CVE-2026-5891 Insufficient policy enforcement in browser UI | UNKNOWN | — | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-5881 | Chromium: CVE-2026-5881 Policy bypass in LocalNetworkAccess | UNKNOWN | — | 12%ile | Microsoft | 2026-04-14 |
| CVE-2026-5878 | Chromium: CVE-2026-5878 Incorrect security UI in Blink | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5877 | Chromium: CVE-2026-5877 Use after free in Navigation | UNKNOWN | — | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-5888 | Chromium: CVE-2026-5888 Uninitialized Use in WebCodecs | UNKNOWN | — | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-5874 | Chromium: CVE-2026-5874 Use after free in PrivateAI | UNKNOWN | — | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-5886 | Chromium: CVE-2026-5886 Out of bounds read in WebAudio | UNKNOWN | — | 12%ile | Microsoft | 2026-04-14 |
| CVE-2026-5876 | Chromium: CVE-2026-5876 Side-channel information leakage in Navigation | UNKNOWN | — | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-5872 | Chromium: CVE-2026-5872 Use after free in Blink | UNKNOWN | — | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-5875 | Chromium: CVE-2026-5875 Policy bypass in Blink | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5873 | Chromium: CVE-2026-5873 Out of bounds read and write in V8 | UNKNOWN | — | 31%ile | Microsoft | 2026-04-14 |
| CVE-2026-5871 | Chromium: CVE-2026-5871 Type Confusion in V8 | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-5867 | Chromium: CVE-2026-5867 Heap buffer overflow in WebML | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-5868 | Chromium: CVE-2026-5868 Heap buffer overflow in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-5866 | Chromium: CVE-2026-5866 Use after free in Media | UNKNOWN | — | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-5869 | Chromium: CVE-2026-5869 Heap buffer overflow in WebML | UNKNOWN | — | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-5864 | Chromium: CVE-2026-5864 Heap buffer overflow in WebAudio | UNKNOWN | — | 15%ile | Microsoft | 2026-04-14 |
| CVE-2026-5861 | Chromium: CVE-2026-5861 Use after free in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-5862 | Chromium: CVE-2026-5862 Inappropriate implementation in V8 | UNKNOWN | — | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-5860 | Chromium: CVE-2026-5860 Use after free in WebRTC | UNKNOWN | — | 39%ile | Microsoft | 2026-04-14 |
| CVE-2026-5919 | Chromium: CVE-2026-5919 Insufficient validation of untrusted input in WebSockets | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5858 | Chromium: CVE-2026-5858 Heap buffer overflow in WebML | UNKNOWN | — | 46%ile | Microsoft | 2026-04-14 |
| CVE-2026-5859 | Chromium: CVE-2026-5859 Integer overflow in WebML | UNKNOWN | — | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-5918 | Chromium: CVE-2026-5918 Inappropriate implementation in Navigation | UNKNOWN | — | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-5863 | Chromium: CVE-2026-5863 Inappropriate implementation in V8 | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-5913 | Chromium: CVE-2026-5913 Out of bounds read in Blink | UNKNOWN | — | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-5912 | Chromium: CVE-2026-5912 Integer overflow in WebRTC | UNKNOWN | — | 12%ile | Microsoft | 2026-04-14 |
| CVE-2026-5914 | Chromium: CVE-2026-5914 Type Confusion in CSS | UNKNOWN | — | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-5865 | Chromium: CVE-2026-5865 Type Confusion in V8 | UNKNOWN | — | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-5870 | Chromium: CVE-2026-5870 Integer overflow in Skia | UNKNOWN | — | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-5915 | Chromium: CVE-2026-5915 Insufficient validation of untrusted input in WebML | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5908 | Chromium: CVE-2026-5908 Integer overflow in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5909 | Chromium: CVE-2026-5909 Integer overflow in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5905 | Chromium: CVE-2026-5905 Incorrect security UI in Permissions | UNKNOWN | — | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-5911 | Chromium: CVE-2026-5911 Policy bypass in ServiceWorkers | UNKNOWN | — | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-5906 | Chromium: CVE-2026-5906 Incorrect security UI in Omnibox | UNKNOWN | — | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-5907 | Chromium: CVE-2026-5907 Insufficient data validation in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5901 | Chromium: CVE-2026-5901 Policy bypass in DevTools | UNKNOWN | — | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-5904 | Chromium: CVE-2026-5904 Use after free in V8 | UNKNOWN | — | — | Microsoft | 2026-04-14 |
| CVE-2026-5910 | Chromium: CVE-2026-5910 Integer overflow in Media | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5900 | Chromium: CVE-2026-5900 Policy bypass in Downloads | UNKNOWN | — | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-5903 | Chromium: CVE-2026-5903 Policy bypass in IFrameSandbox | UNKNOWN | — | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-5902 | Chromium: CVE-2026-5902 Race in Media | UNKNOWN | — | 12%ile | Microsoft | 2026-04-14 |
| CVE-2026-5882 | Chromium: CVE-2026-5882 Incorrect security UI in Fullscreen | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5880 | Chromium: CVE-2026-5880 Incorrect security UI in browser UI | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-6296 | Chromium: CVE-2026-6296 Heap buffer overflow in ANGLE | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-6363 | Chromium: CVE-2026-6363 Type Confusion in V8 | UNKNOWN | — | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-6359 | Chromium: CVE-2026-6359 Use after free in Video | UNKNOWN | — | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-6364 | Chromium: CVE-2026-6364 Out of bounds read in Skia | UNKNOWN | — | 14%ile | Microsoft | 2026-04-14 |
| CVE-2026-6362 | Chromium: CVE-2026-6362 Use after free in Codecs | UNKNOWN | — | 13%ile | Microsoft | 2026-04-14 |
| CVE-2026-6313 | Chromium: CVE-2026-6313 Insufficient policy enforcement in CORS | UNKNOWN | — | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-6314 | Chromium: CVE-2026-6314 Out of bounds write in GPU | UNKNOWN | — | 19%ile | Microsoft | 2026-04-14 |
| CVE-2026-6318 | Chromium: CVE-2026-6318 Use after free in Codecs | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-6361 | Chromium: CVE-2026-6361 Heap buffer overflow in PDFium | UNKNOWN | — | 23%ile | Microsoft | 2026-04-14 |
| CVE-2026-6310 | Chromium: CVE-2026-6310 Use after free in Dawn | UNKNOWN | — | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-6360 | Chromium: CVE-2026-6360 Use after free in FileSystem | UNKNOWN | — | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-6316 | Chromium: CVE-2026-6316 Use after free in Forms | UNKNOWN | — | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-6309 | Chromium: CVE-2026-6309 Use after free in Viz | UNKNOWN | — | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-6311 | Chromium: CVE-2026-6311 Uninitialized Use in Accessibility | UNKNOWN | — | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-6307 | Chromium: CVE-2026-6307 Type Confusion in Turbofan | UNKNOWN | — | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-6306 | Chromium: CVE-2026-6306 Heap buffer overflow in PDFium | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-6303 | Chromium: CVE-2026-6303 Use after free in Codecs | UNKNOWN | — | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-6308 | Chromium: CVE-2026-6308 Out of bounds read in Media | UNKNOWN | — | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-6302 | Chromium: CVE-2026-6302 Use after free in Video | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-6300 | Chromium: CVE-2026-6300 Use after free in CSS | UNKNOWN | — | 27%ile | Microsoft | 2026-04-14 |
| CVE-2026-6304 | Chromium: CVE-2026-6304 Use after free in Graphite | UNKNOWN | — | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-6305 | Chromium: CVE-2026-6305 Heap buffer overflow in PDFium | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-6301 | Chromium: CVE-2026-6301 Type Confusion in Turbofan | UNKNOWN | — | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-6317 | Chromium: CVE-2026-6317 Use after free in Cast | UNKNOWN | — | 27%ile | Microsoft | 2026-04-14 |
| CVE-2026-6312 | Chromium: CVE-2026-6312 Insufficient policy enforcement in Passwords | UNKNOWN | — | 13%ile | Microsoft | 2026-04-14 |
| CVE-2026-6298 | Chromium: CVE-2026-6298 Heap buffer overflow in Skia | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-6297 | Chromium: CVE-2026-6297 Use after free in Proxy | UNKNOWN | — | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-6299 | Chromium: CVE-2026-6299 Use after free in Prerender | UNKNOWN | — | 27%ile | Microsoft | 2026-04-14 |
| CVE-2026-6921 | Chromium: CVE-2026-6921 Race in GPU | UNKNOWN | — | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-34743 | XZ Utils: Buffer overflow in lzma_index_append() | UNKNOWN | — | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-34591 | Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write | UNKNOWN | — | 38%ile | Microsoft | 2026-04-14 |
| CVE-2026-28810 | Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver | UNKNOWN | — | 19%ile | Microsoft | 2026-04-14 |
| CVE-2026-35206 | Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment | UNKNOWN | — | 10%ile | Microsoft | 2026-04-14 |
| CVE-2026-5466 | wc_VerifyEccsiHash missing sanity check | UNKNOWN | — | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-5194 | wolfSSL ECDSA Certificate Verification | UNKNOWN | — | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-5448 | 1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore | UNKNOWN | — | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-5264 | DTLS 1.3 ACK heap buffer overflow | UNKNOWN | — | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-5778 | Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path. | UNKNOWN | — | 13%ile | Microsoft | 2026-04-14 |
| CVE-2026-5460 | Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3 | UNKNOWN | — | 12%ile | Microsoft | 2026-04-14 |
| CVE-2026-5446 | wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse | UNKNOWN | — | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-33948 | jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input | UNKNOWN | — | 17%ile | Microsoft | 2026-04-14 |
| CVE-2026-27820 | zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption | UNKNOWN | — | 44%ile | Microsoft | 2026-04-14 |
| CVE-2026-5958 | Race Condition in GNU Sed | UNKNOWN | — | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-41907 | uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided | UNKNOWN | — | 26%ile | Microsoft | 2026-04-14 |
| CVE-2026-32147 | SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT | UNKNOWN | — | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-41676 | rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-41678 | rust-openssl: Incorrect bounds assertion in aes key wrap | UNKNOWN | — | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-41681 | rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check | UNKNOWN | — | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-41898 | rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjace | UNKNOWN | — | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-6357 | pip self-update functionality can import newly installed modules after wheel installation | UNKNOWN | — | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-41636 | Apache Thrift: Node.js skip() recursion | UNKNOWN | — | 37%ile | Microsoft | 2026-04-14 |
| CVE-2026-34980 | OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network | UNKNOWN | — | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-34990 | OpenPrinting CUPS: Local print admin token disclosure using temporary printers | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-34477 | Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass | UNKNOWN | — | 34%ile | Microsoft | 2026-04-14 |
| CVE-2026-5393 | OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS | UNKNOWN | — | 9%ile | Microsoft | 2026-04-14 |
| CVE-2026-5500 | Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass | UNKNOWN | — | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-5504 | PKCS7 CBC Padding Oracle — Plaintext Recovery | UNKNOWN | — | 2%ile | Microsoft | 2026-04-14 |
| CVE-2026-5501 | Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates | UNKNOWN | — | 8%ile | Microsoft | 2026-04-14 |
| CVE-2026-5507 | Session Cache Restore — Arbitrary Free via Deserialized Pointer | UNKNOWN | — | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-5477 | Prefix-substitution forgery via integer overflow in wolfCrypt CMAC | UNKNOWN | — | 35%ile | Microsoft | 2026-04-14 |
| CVE-2026-5479 | wolfSSL EVP ChaCha20-Poly1305 AEAD authentication tag | UNKNOWN | — | 5%ile | Microsoft | 2026-04-14 |
| CVE-2026-5503 | out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName | UNKNOWN | — | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-5295 | Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID | UNKNOWN | — | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-5188 | Integer underflow in X.509 SAN parsing in wolfSSL | UNKNOWN | — | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-5447 | Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier | UNKNOWN | — | 13%ile | Microsoft | 2026-04-14 |
| CVE-2026-5772 | MatchDomainName 1-Byte Stack Buffer Over-Read in Hostname Validation | UNKNOWN | — | 14%ile | Microsoft | 2026-04-14 |
| CVE-2026-5263 | URI nameConstraints not enforced in ConfirmNameConstraints() | UNKNOWN | — | 7%ile | Microsoft | 2026-04-14 |
| CVE-2026-5392 | wolfSSL heap OOB read in PKCS7 SignedData streaming | UNKNOWN | — | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-1502 | HTTP client proxy tunnel headers not validated for CR/LF | UNKNOWN | — | 44%ile | Microsoft | 2026-04-14 |
| CVE-2026-34481 | Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout | UNKNOWN | — | 49%ile | Microsoft | 2026-04-14 |
| CVE-2026-34479 | Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters | UNKNOWN | — | 42%ile | Microsoft | 2026-04-14 |
| CVE-2026-34480 | Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters | UNKNOWN | — | 55%ile | Microsoft | 2026-04-14 |
| CVE-2025-62718 | Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF | UNKNOWN | — | 64%ile | Microsoft | 2026-04-14 |
| CVE-2026-39979 | jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers | UNKNOWN | — | 43%ile | Microsoft | 2026-04-14 |
| CVE-2026-40179 | Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer | UNKNOWN | — | 18%ile | Microsoft | 2026-04-14 |
| CVE-2026-4786 | Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-3219 | pip doesn't reject concatenated ZIP and tar archives | UNKNOWN | — | 4%ile | Microsoft | 2026-04-14 |
| CVE-2026-28808 | ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) | UNKNOWN | — | 42%ile | Microsoft | 2026-04-14 |
| CVE-2026-6409 | Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input | UNKNOWN | — | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-5187 | Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-41205 | Mako: Path traversal via double-slash URI prefix in TemplateLookup | UNKNOWN | — | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-41140 | Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4 | UNKNOWN | — | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-41677 | rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length | UNKNOWN | — | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-3298 | Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes | UNKNOWN | — | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-40556 | Insecure Directory Permissions in GNU nano Leading to Privilege Abuse | UNKNOWN | — | — | Microsoft | 2026-04-14 |
| CVE-2026-6019 | BaseCookie.js_output() does not neutralize embedded characters | UNKNOWN | — | 14%ile | Microsoft | 2026-04-14 |
| CVE-2026-6919 | Chromium: CVE-2026-6919 Use after free in DevTools | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-24304 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 46%ile | Microsoft | 2026-01-13 |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98%ile | Microsoft | 2026-01-13 |
| CVE-2026-24306 | Azure Front Door Elevation of Privilege Vulnerability | CRITICAL | 9.8 | 52%ile | Microsoft | 2026-01-13 |
| CVE-2026-22184 | zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname() | CRITICAL | 9.8 | 31%ile | Microsoft | 2026-01-13 |
| CVE-2026-24305 | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL | 9.3 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-24307 | M365 Copilot Information Disclosure Vulnerability | CRITICAL | 9.3 | 53%ile | Microsoft | 2026-01-13 |
| CVE-2026-21264 | Microsoft Account Spoofing Vulnerability | CRITICAL | 9.3 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2026-01-13 |
| CVE-2026-20868 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 68%ile | Microsoft | 2026-01-13 |
| CVE-2025-69194 | Wget2: arbitrary file write via metalink path traversal in gnu wget2 | HIGH | 8.8 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-20944 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 8.4 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2026-20953 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 45%ile | Microsoft | 2026-01-13 |
| CVE-2026-20952 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-21227 | Azure Logic Apps Elevation of Privilege Vulnerability | HIGH | 8.2 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-20856 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | HIGH | 8.1 | 62%ile | Microsoft | 2026-01-13 |
| CVE-2026-20960 | PowerApps Desktop Client Remote Code Execution Vulnerability | HIGH | 8.0 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-20931 | Windows Telephony Service Elevation of Privilege Vulnerability | HIGH | 8.0 | 51%ile | Microsoft | 2026-01-13 |
| CVE-2026-20809 | Windows Kernel Memory Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2026-01-13 |
| CVE-2026-20810 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2026-20811 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2026-20816 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.8 | 82%ile | Microsoft | 2026-01-13 |
| CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 92%ile | Microsoft | 2026-01-13 |
| CVE-2026-20820 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 83%ile | Microsoft | 2026-01-13 |
| CVE-2026-20822 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-01-13 |
| CVE-2026-20826 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20831 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20832 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-20837 | Windows Media Remote Code Execution Vulnerability | HIGH | 7.8 | 48%ile | Microsoft | 2026-01-13 |
| CVE-2026-20840 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 90%ile | Microsoft | 2026-01-13 |
| CVE-2023-31096 | MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-01-13 |
| CVE-2026-20857 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-20858 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-20859 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-20860 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 94%ile | Microsoft | 2026-01-13 |
| CVE-2026-20864 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20865 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2026-20877 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20918 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20920 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2026-20922 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 61%ile | Microsoft | 2026-01-13 |
| CVE-2026-20923 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2026-01-13 |
| CVE-2026-20924 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20938 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2026-20940 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-01-13 |
| CVE-2026-20946 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 49%ile | Microsoft | 2026-01-13 |
| CVE-2026-20951 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.8 | 52%ile | Microsoft | 2026-01-13 |
| CVE-2026-20955 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 45%ile | Microsoft | 2026-01-13 |
| CVE-2026-20956 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2026-01-13 |
| CVE-2026-21224 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-20843 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 87%ile | Microsoft | 2026-01-13 |
| CVE-2026-20861 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-20866 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-20867 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-20870 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-01-13 |
| CVE-2026-20871 | Desktop Window Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 90%ile | Microsoft | 2026-01-13 |
| CVE-2026-20873 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20874 | Windows Management Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2024-55414 | Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 63%ile | Microsoft | 2026-01-13 |
| CVE-2026-20948 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20949 | Microsoft Excel Security Feature Bypass Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2026-01-13 |
| CVE-2026-20950 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2026-01-13 |
| CVE-2026-20957 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2026-01-13 |
| CVE-2026-20941 | Host Process for Windows Tasks Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | HIGH | 7.8 | 99%ile | Microsoft | 2026-01-13 |
| CVE-2026-20804 | Windows Hello Tampering Vulnerability | HIGH | 7.7 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-20852 | Windows Hello Tampering Vulnerability | HIGH | 7.7 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2025-69195 | Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls | HIGH | 7.6 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-0386 | Windows Deployment Services Remote Code Execution Vulnerability | HIGH | 7.5 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20965 | Windows Admin Center Elevation of Privilege Vulnerability | HIGH | 7.5 | 11%ile | Microsoft | 2026-01-13 |
| CVE-2026-20875 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2026-01-13 |
| CVE-2026-20919 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-01-13 |
| CVE-2026-20921 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-01-13 |
| CVE-2026-20926 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-01-13 |
| CVE-2026-20934 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-01-13 |
| CVE-2026-20848 | Windows SMB Server Elevation of Privilege Vulnerability | HIGH | 7.5 | 51%ile | Microsoft | 2026-01-13 |
| CVE-2026-20849 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.5 | 59%ile | Microsoft | 2026-01-13 |
| CVE-2026-20854 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | HIGH | 7.5 | 61%ile | Microsoft | 2026-01-13 |
| CVE-2026-20929 | Windows HTTP.sys Elevation of Privilege Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2026-01-13 |
| CVE-2026-21226 | Azure Core shared client library for Python Remote Code Execution Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2026-01-13 |
| CVE-2026-21520 | Copilot Studio Information Disclosure Vulnerability | HIGH | 7.5 | 70%ile | Microsoft | 2026-01-13 |
| CVE-2026-0719 | Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication | HIGH | 7.5 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2026-20844 | Windows Clipboard Server Elevation of Privilege Vulnerability | HIGH | 7.4 | 24%ile | Microsoft | 2026-01-13 |
| CVE-2026-20853 | Windows WalletService Elevation of Privilege Vulnerability | HIGH | 7.4 | 23%ile | Microsoft | 2026-01-13 |
| CVE-2026-21524 | Azure Data Explorer Information Disclosure Vulnerability | HIGH | 7.4 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-21521 | Word Copilot Information Disclosure Vulnerability | HIGH | 7.4 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-20803 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 7.2 | 66%ile | Microsoft | 2026-01-13 |
| CVE-2026-21223 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | HIGH | 7.1 | 16%ile | Microsoft | 2026-01-13 |
| CVE-2026-20808 | Windows File Explorer Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20814 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20815 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20836 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-20842 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.0 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2026-20869 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-20943 | Microsoft Office Click-To-Run Remote Code Execution Vulnerability | HIGH | 7.0 | 47%ile | Microsoft | 2026-01-13 |
| CVE-2026-20830 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2026-01-13 |
| CVE-2026-21221 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 12%ile | Microsoft | 2026-01-13 |
| CVE-2026-21219 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | HIGH | 7.0 | 27%ile | Microsoft | 2026-01-13 |
| CVE-2026-20863 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2026-20876 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 40%ile | Microsoft | 2026-01-13 |
| CVE-2026-20812 | LDAP Tampering Vulnerability | MEDIUM | 6.5 | 63%ile | Microsoft | 2026-01-13 |
| CVE-2026-20847 | Microsoft Windows File Explorer Spoofing Vulnerability | MEDIUM | 6.5 | 68%ile | Microsoft | 2026-01-13 |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5 | 97%ile | Microsoft | 2026-01-13 |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | 6.5 | 97%ile | Microsoft | 2026-01-13 |
| CVE-2026-21265 | Secure Boot Certificate Expiration Security Feature Bypass Vulnerability | MEDIUM | 6.4 | 58%ile | Microsoft | 2026-01-13 |
| CVE-2026-20818 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 6.2 | 49%ile | Microsoft | 2026-01-13 |
| CVE-2026-20821 | Remote Procedure Call Information Disclosure Vulnerability | MEDIUM | 6.2 | 49%ile | Microsoft | 2026-01-13 |
| CVE-2026-20851 | Capability Access Management Service (camsvc) Information Disclosure Vulnerability | MEDIUM | 6.2 | 44%ile | Microsoft | 2026-01-13 |
| CVE-2026-20935 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | MEDIUM | 6.2 | 34%ile | Microsoft | 2026-01-13 |
| CVE-2026-22695 | LIBPNG has a heap buffer over-read in png_image_read_direct_scaled (regression from CVE-2025-65018 fix) | MEDIUM | 6.1 | 7%ile | Microsoft | 2026-01-13 |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 91%ile | Microsoft | 2026-01-13 |
| CVE-2026-20819 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | MEDIUM | 5.5 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2026-20823 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 48%ile | Microsoft | 2026-01-13 |
| CVE-2026-20824 | Windows Remote Assistance Security Feature Bypass Vulnerability | MEDIUM | 5.5 | 56%ile | Microsoft | 2026-01-13 |
| CVE-2026-20827 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-01-13 |
| CVE-2026-20829 | TPM Trustlet Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20833 | Windows Kerberos Information Disclosure Vulnerability | MEDIUM | 5.5 | 39%ile | Microsoft | 2026-01-13 |
| CVE-2026-20835 | Capability Access Management Service (camsvc) Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2026-01-13 |
| CVE-2026-20838 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2026-01-13 |
| CVE-2026-20839 | Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-20932 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 48%ile | Microsoft | 2026-01-13 |
| CVE-2026-20862 | Windows Management Services Information Disclosure Vulnerability | MEDIUM | 5.5 | 46%ile | Microsoft | 2026-01-13 |
| CVE-2026-20937 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-20939 | Windows File Explorer Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2026-01-13 |
| CVE-2026-21444 | libtpms returns wrong initialization vector when certain symmetric ciphers are used | MEDIUM | 5.5 | 0%ile | Microsoft | 2026-01-13 |
| CVE-2026-20958 | Microsoft SharePoint Information Disclosure Vulnerability | MEDIUM | 5.4 | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-20927 | Windows SMB Server Denial of Service Vulnerability | MEDIUM | 5.3 | 56%ile | Microsoft | 2026-01-13 |
| CVE-2026-22693 | Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS | MEDIUM | 5.3 | 30%ile | Microsoft | 2026-01-13 |
| CVE-2026-20828 | Windows rndismp6.sys Information Disclosure Vulnerability | MEDIUM | 4.6 | 46%ile | Microsoft | 2026-01-13 |
| CVE-2026-20834 | Windows Spoofing Vulnerability | MEDIUM | 4.6 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2026-20959 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 4.6 | 94%ile | Microsoft | 2026-01-13 |
| CVE-2026-20962 | Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability | MEDIUM | 4.4 | 33%ile | Microsoft | 2026-01-13 |
| CVE-2026-20825 | Windows Hyper-V Information Disclosure Vulnerability | MEDIUM | 4.4 | 41%ile | Microsoft | 2026-01-13 |
| CVE-2026-20936 | Windows NDIS Information Disclosure Vulnerability | MEDIUM | 4.3 | 36%ile | Microsoft | 2026-01-13 |
| CVE-2026-0907 | Chromium: CVE-2026-0907 Incorrect security UI in Split View | UNKNOWN | — | 94%ile | Microsoft | 2026-01-13 |
| CVE-2026-0906 | Chromium: CVE-2026-0906 Incorrect security UI | UNKNOWN | — | 24%ile | Microsoft | 2026-01-13 |
| CVE-2026-0905 | Chromium: CVE-2026-0905 Insufficient policy enforcement in Network | UNKNOWN | — | 13%ile | Microsoft | 2026-01-13 |
| CVE-2026-0904 | Chromium: CVE-2026-0904 Incorrect security UI in Digital Credentials | UNKNOWN | — | 6%ile | Microsoft | 2026-01-13 |
| CVE-2026-0903 | Chromium: CVE-2026-0903 Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 8%ile | Microsoft | 2026-01-13 |
| CVE-2026-0901 | Chromium: CVE-2026-0901 Inappropriate implementation in Blink | UNKNOWN | — | 8%ile | Microsoft | 2026-01-13 |
| CVE-2026-0899 | Chromium: CVE-2026-0899 Out of bounds memory access in V8 | UNKNOWN | — | 31%ile | Microsoft | 2026-01-13 |
| CVE-2026-1504 | Chromium: CVE-2026-1504 Inappropriate implementation in Background Fetch API | UNKNOWN | — | 13%ile | Microsoft | 2026-01-13 |
| CVE-2026-0628 | Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag | UNKNOWN | — | 93%ile | Microsoft | 2026-01-13 |
| CVE-2026-0908 | Chromium: CVE-2026-0908 Use after free in ANGLE | UNKNOWN | — | 24%ile | Microsoft | 2026-01-13 |
| CVE-2026-0900 | Chromium: CVE-2026-0900 Inappropriate implementation in V8 | UNKNOWN | — | 25%ile | Microsoft | 2026-01-13 |
| CVE-2026-1220 | Chromium: CVE-2026-1220 Race in V8 | UNKNOWN | — | 22%ile | Microsoft | 2026-01-13 |
| CVE-2026-0902 | Chromium: CVE-2026-0902 Inappropriate implementation in V8 | UNKNOWN | — | 17%ile | Microsoft | 2026-01-13 |
| CVE-2026-21895 | rsa crate has potential panic on a prime being equal to 1 | UNKNOWN | — | 33%ile | Microsoft | 2026-01-13 |
| CVE-2026-22185 | OpenLDAP <= 2.6.10 LMDB mdb_load Heap Buffer Underflow in readline() | UNKNOWN | — | 3%ile | Microsoft | 2026-01-13 |
| CVE-2025-55241 | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 73%ile | Microsoft | 2025-09-09 |
| CVE-2025-54914 | Azure Networking Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 81%ile | Microsoft | 2025-09-09 |
| CVE-2025-39743 | jfs: truncate good inode pages when hard link is 0 | CRITICAL | 9.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-57052 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c | CRITICAL | 9.8 | 51%ile | Microsoft | 2025-09-09 |
| CVE-2025-55232 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability | CRITICAL | 9.8 | 78%ile | Microsoft | 2025-09-09 |
| CVE-2025-38714 | hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() | CRITICAL | 9.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-55244 | Azure Bot Service Elevation of Privilege Vulnerability | CRITICAL | 9.0 | 44%ile | Microsoft | 2025-09-09 |
| CVE-2025-9900 | Libtiff: libtiff write-what-where | HIGH | 8.8 | 51%ile | Microsoft | 2025-09-09 |
| CVE-2025-47906 | Unexpected paths returned from LookPath in os/exec | HIGH | 8.8 | 39%ile | Microsoft | 2025-09-09 |
| CVE-2025-54106 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 68%ile | Microsoft | 2025-09-09 |
| CVE-2025-54110 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 89%ile | Microsoft | 2025-09-09 |
| CVE-2025-54897 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-54918 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-54113 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 54%ile | Microsoft | 2025-09-09 |
| CVE-2025-55227 | Microsoft SQL Server Elevation of Privilege Vulnerability | HIGH | 8.8 | 66%ile | Microsoft | 2025-09-09 |
| CVE-2025-55234 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 8.8 | 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-55319 | Agentic AI and Visual Studio Code Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2025-09-09 |
| CVE-2025-54910 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-59362 | Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c. | HIGH | 8.2 | 29%ile | Microsoft | 2025-09-09 |
| CVE-2025-9566 | Podman: podman kube play command may overwrite host files | HIGH | 8.1 | 60%ile | Microsoft | 2025-09-09 |
| CVE-2025-58060 | cups has Authentication bypass with AuthType Negotiate | HIGH | 8.0 | 58%ile | Microsoft | 2025-09-09 |
| CVE-2025-38707 | fs/ntfs3: Add sanity check for file name | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39730 | NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() | HIGH | 7.8 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39788 | scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39751 | ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control | HIGH | 7.8 | — | Microsoft | 2025-09-09 |
| CVE-2025-39757 | ALSA: usb-audio: Validate UAC3 cluster segment descriptors | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39766 | net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39790 | bus: mhi: host: Detect events pointing to unexpected TREs | HIGH | 7.8 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39738 | btrfs: do not allow relocation of partially dropped subvolumes | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39776 | mm/debug_vm_pgtable: clear page table entries at destroy_args() | HIGH | 7.8 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39828 | atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39823 | KVM: x86: use array_index_nospec with indices that come from guest | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39824 | HID: asus: fix UAF via HID_CLAIMED_INPUT validation | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39841 | scsi: lpfc: Fix buffer free/clear order in deferred receive path | HIGH | 7.8 | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-39863 | wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work | HIGH | 7.8 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39859 | ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog | HIGH | 7.8 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39861 | Bluetooth: vhci: Prevent use-after-free by removing debugfs files early | HIGH | 7.8 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39864 | wifi: cfg80211: fix use-after-free in cmp_bss() | HIGH | 7.8 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-39866 | fs: writeback: fix use-after-free in __mark_inode_dirty() | HIGH | 7.8 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2023-53187 | btrfs: fix use-after-free of new block group that became unused | HIGH | 7.8 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53218 | rxrpc: Make it so that a waiting process can be aborted | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50406 | iomap: iomap: fix memory corruption when recording errors during writeback | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38718 | sctp: linearize cloned gso packets in sctp_rcv | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38685 | fbdev: Fix vmalloc out-of-bounds write in fast_imageblit | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38729 | ALSA: usb-audio: Validate UAC3 power domain descriptors, too | HIGH | 7.8 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38699 | scsi: bfa: Double-free fix | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38724 | nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() | HIGH | 7.8 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-38702 | fbdev: fix potential buffer overflow in do_register_framebuffer() | HIGH | 7.8 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38703 | drm/xe: Make dma-fences compliant with the safe access rules | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39686 | comedi: Make insn_rw_emulate_bits() do insn->n samples | HIGH | 7.8 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39689 | ftrace: Also allocate and copy hash for reading of filter files | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39691 | fs/buffer: fix use-after-free when call bh_read() helper | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39810 | bnxt_en: Fix memory corruption when FW resources change during ifdown | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39835 | xfs: do not propagate ENODATA disk errors into xattr code | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39873 | can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB | HIGH | 7.8 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-41244 | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-202 | HIGH | 7.8 | 94%ile | Microsoft | 2025-09-09 |
| CVE-2025-54102 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-54111 | Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability | HIGH | 7.8 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-54894 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-54895 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability | HIGH | 7.8 | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-54896 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54898 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54899 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54902 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54903 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54904 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54906 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 49%ile | Microsoft | 2025-09-09 |
| CVE-2025-54907 | Microsoft Office Visio Remote Code Execution Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2025-09-09 |
| CVE-2025-54908 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 43%ile | Microsoft | 2025-09-09 |
| CVE-2025-54913 | Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability | HIGH | 7.8 | 19%ile | Microsoft | 2025-09-09 |
| CVE-2025-54916 | Windows NTFS Remote Code Execution Vulnerability | HIGH | 7.8 | 80%ile | Microsoft | 2025-09-09 |
| CVE-2025-55228 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-55245 | Xbox Gaming Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-55316 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2025-09-09 |
| CVE-2025-55317 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-49692 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2025-09-09 |
| CVE-2025-53800 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2025-09-09 |
| CVE-2025-53801 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-54091 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-54092 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.8 | 24%ile | Microsoft | 2025-09-09 |
| CVE-2025-54098 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.8 | 84%ile | Microsoft | 2025-09-09 |
| CVE-2025-54900 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-09-09 |
| CVE-2025-54912 | Windows BitLocker Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-55224 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 7.8 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-59251 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 7.6 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-58767 | REXML has a DoS condition when parsing malformed XML file | HIGH | 7.5 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-55551 | An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when per | HIGH | 7.5 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-55552 | pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are us | HIGH | 7.5 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-40928 | JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabl | HIGH | 7.5 | 45%ile | Microsoft | 2025-09-09 |
| CVE-2025-48041 | SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles | HIGH | 7.5 | 29%ile | Microsoft | 2025-09-09 |
| CVE-2025-59375 | libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is | HIGH | 7.5 | 67%ile | Microsoft | 2025-09-09 |
| CVE-2025-58754 | Axios is vulnerable to DoS attack through lack of data size check | HIGH | 7.5 | 61%ile | Microsoft | 2025-09-09 |
| CVE-2025-11021 | Libsoup: out-of-bounds read in cookie date handling of libsoup http library | HIGH | 7.5 | 45%ile | Microsoft | 2025-09-09 |
| CVE-2025-55553 | A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS). | HIGH | 7.5 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-55557 | A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading | HIGH | 7.5 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-55560 | An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse | HIGH | 7.5 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-55558 | A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshr | HIGH | 7.5 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | HIGH | 7.5 | 76%ile | Microsoft | 2025-09-09 |
| CVE-2025-54919 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.5 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-55243 | Microsoft OfficePlus Spoofing Vulnerability | HIGH | 7.5 | 61%ile | Microsoft | 2025-09-09 |
| CVE-2025-53805 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 69%ile | Microsoft | 2025-09-09 |
| CVE-2025-55238 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability | HIGH | 7.5 | 52%ile | Microsoft | 2025-09-09 |
| CVE-2025-4953 | Podman: build context bind mount | HIGH | 7.4 | 45%ile | Microsoft | 2025-09-09 |
| CVE-2025-54103 | Windows Management Service Elevation of Privilege Vulnerability | HIGH | 7.4 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-9905 | Arbitary Code execution in Keras load_model() | HIGH | 7.3 | 10%ile | Microsoft | 2025-09-09 |
| CVE-2025-9906 | Arbitrary Code execution in Keras Safe Mode | HIGH | 7.3 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-55236 | Graphics Kernel Remote Code Execution Vulnerability | HIGH | 7.3 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-54116 | Windows MultiPoint Services Elevation of Privilege Vulnerability | HIGH | 7.3 | 40%ile | Microsoft | 2025-09-09 |
| CVE-2025-54911 | Windows BitLocker Elevation of Privilege Vulnerability | HIGH | 7.3 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-55322 | OmniParser Remote Code Execution Vulnerability | HIGH | 7.3 | 27%ile | Microsoft | 2025-09-09 |
| CVE-2025-38728 | smb3: fix for slab out of bounds on mount to ksmbd | HIGH | 7.1 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-39761 | wifi: ath12k: Decrement TID on RX peer frag setup error handling | HIGH | 7.1 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-39839 | batman-adv: fix OOB read/write in network-coding decode | HIGH | 7.1 | 15%ile | Microsoft | 2025-09-09 |
| CVE-2025-39853 | i40e: Fix potential invalid access when MAC list is empty | HIGH | 7.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38688 | iommufd: Prevent ALIGN() overflow | HIGH | 7.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38680 | media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38698 | jfs: Regular file corruption check | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38697 | jfs: upper bound check of tree index in dbAllocAG | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38679 | media: venus: Fix OOB read due to missing payload bound check | HIGH | 7.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39685 | comedi: pcl726: Prevent invalid irq number | HIGH | 7.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39702 | ipv6: sr: Fix MAC comparison to be constant-time | HIGH | 7.1 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-39710 | media: venus: Add a check for packet size after reading from shared memory | HIGH | 7.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39683 | tracing: Limit access to parser->buffer when trace_get_user failed | HIGH | 7.1 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-58063 | CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion | HIGH | 7.1 | 34%ile | Microsoft | 2025-09-09 |
| CVE-2025-39817 | efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare | HIGH | 7.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39860 | Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() | HIGH | 7.1 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-39883 | mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory | HIGH | 7.1 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53254 | cacheinfo: Fix shared_cpu_map to handle shared caches at different levels | HIGH | 7.1 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39806 | HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() | HIGH | 7.1 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-54905 | Microsoft Word Information Disclosure Vulnerability | HIGH | 7.1 | 45%ile | Microsoft | 2025-09-09 |
| CVE-2025-39732 | wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask() | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39749 | rcu: Protect ->defer_qs_iw_pending from data race | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39750 | wifi: ath12k: Correct tid cleanup when tid setup fails | HIGH | 7.0 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-39746 | wifi: ath10k: shutdown driver when hardware is unreliable | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39759 | btrfs: qgroup: fix race between quota disable and quota rescan ioctl | HIGH | 7.0 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2025-39742 | RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() | HIGH | 7.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39825 | smb: client: fix race with concurrent opens in rename(2) | HIGH | 7.0 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2025-39833 | mISDN: hfcpci: Fix warning when deleting uninitialized timer | HIGH | 7.0 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39850 | vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects | HIGH | 7.0 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-38710 | gfs2: Validate i_depth for exhash directories | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38709 | loop: Avoid updating block size under exclusive owner | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38695 | scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure | HIGH | 7.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38684 | net/sched: ets: use old 'nbands' while purging unused classes | HIGH | 7.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38692 | exfat: add cluster chain loop check for dir | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38701 | ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr | HIGH | 7.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39703 | net, hsr: reject HSR frame if skb can't hold tag | HIGH | 7.0 | 27%ile | Microsoft | 2025-09-09 |
| CVE-2025-38735 | gve: prevent ethtool ops after shutdown | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39711 | media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39721 | crypto: qat - flush misc workqueue during device shutdown | HIGH | 7.0 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39694 | s390/sclp: Fix SCCB present check | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39677 | net/sched: Fix backlog accounting in qdisc_dequeue_internal | HIGH | 7.0 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39673 | ppp: fix race conditions in ppp_fill_forward_path | HIGH | 7.0 | 20%ile | Microsoft | 2025-09-09 |
| CVE-2025-38732 | netfilter: nf_reject: don't leak dst refcount for loopback packets | HIGH | 7.0 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39713 | media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() | HIGH | 7.0 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39826 | net: rose: convert 'use' field to refcount_t | HIGH | 7.0 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2025-39832 | net/mlx5: Fix lockdep assertion on sync reset unload event | HIGH | 7.0 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2025-39843 | mm: slub: avoid wake up kswapd in set_track_prepare | HIGH | 7.0 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2025-39851 | vxlan: Fix NPD when refreshing an FDB entry with a nexthop object | HIGH | 7.0 | 20%ile | Microsoft | 2025-09-09 |
| CVE-2025-39865 | tee: fix NULL pointer dereference in tee_shm_put | HIGH | 7.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39838 | cifs: prevent NULL pointer dereference in UTF16 conversion | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39877 | mm/damon/sysfs: fix use-after-free in state_show() | HIGH | 7.0 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-49734 | PowerShell Direct Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-54099 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-55223 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 19%ile | Microsoft | 2025-09-09 |
| CVE-2025-59215 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-53802 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-53807 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-54093 | Windows TCP/IP Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-54105 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-54108 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-54112 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | HIGH | 7.0 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-54114 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-54115 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH | 7.0 | 31%ile | Microsoft | 2025-09-09 |
| CVE-2025-59216 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-59220 | Windows Bluetooth Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-55226 | Graphics Kernel Remote Code Execution Vulnerability | MEDIUM | 6.7 | 37%ile | Microsoft | 2025-09-09 |
| CVE-2025-53808 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 37%ile | Microsoft | 2025-09-09 |
| CVE-2025-53810 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-54094 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-54104 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 39%ile | Microsoft | 2025-09-09 |
| CVE-2025-54109 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 37%ile | Microsoft | 2025-09-09 |
| CVE-2025-54915 | Windows Defender Firewall Service Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-39783 | PCI: endpoint: Fix configfs group list head handling | MEDIUM | 6.6 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-40300 | x86/vmscape: Add conditional IBPB mitigation | MEDIUM | 6.5 | 26%ile | Microsoft | 2025-09-09 |
| CVE-2025-9231 | Timing side-channel in SM2 algorithm on 64 bit ARM | MEDIUM | 6.5 | 81%ile | Microsoft | 2025-09-09 |
| CVE-2025-10148 | predictable WebSocket mask | MEDIUM | 6.5 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-39682 | tls: fix handling of zero-length records on the rx_list | MEDIUM | 6.5 | 38%ile | Microsoft | 2025-09-09 |
| CVE-2025-58364 | cups: Remote DoS via null dereference | MEDIUM | 6.5 | 61%ile | Microsoft | 2025-09-09 |
| CVE-2025-53797 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2025-09-09 |
| CVE-2025-53798 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2025-09-09 |
| CVE-2025-54095 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2025-09-09 |
| CVE-2025-54096 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2025-09-09 |
| CVE-2025-54097 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2025-09-09 |
| CVE-2025-55225 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 63%ile | Microsoft | 2025-09-09 |
| CVE-2025-47997 | Microsoft SQL Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2025-09-09 |
| CVE-2025-53796 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2025-09-09 |
| CVE-2025-53806 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 62%ile | Microsoft | 2025-09-09 |
| CVE-2025-53809 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | MEDIUM | 6.5 | 69%ile | Microsoft | 2025-09-09 |
| CVE-2025-55242 | Xbox Certification Bug Copilot Djando Information Disclosure Vulnerability | MEDIUM | 6.5 | 51%ile | Microsoft | 2025-09-09 |
| CVE-2025-38708 | drbd: add missing kref_get in handle_write_conflicts | MEDIUM | 6.3 | 27%ile | Microsoft | 2025-09-09 |
| CVE-2025-38704 | rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access | MEDIUM | 6.3 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39801 | usb: dwc3: Remove WARN_ON for device endpoint command timeouts | MEDIUM | 6.2 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39794 | ARM: tegra: Use I/O memcpy to write to IRAM | MEDIUM | 6.2 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2022-50303 | drm/amdkfd: Fix double release compute pasid | MEDIUM | 6.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38713 | hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() | MEDIUM | 6.1 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39797 | xfrm: Duplicate SPI Handling | MEDIUM | 6.1 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2022-50256 | drm/meson: remove drm bridges at aggregate driver unbind time | MEDIUM | 6.1 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38678 | netfilter: nf_tables: reject duplicate device on updates | MEDIUM | 6.0 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2023-53376 | scsi: mpi3mr: Use number of bits to manage bitmap sizes | MEDIUM | 6.0 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-9901 | Libsoup: improper handling of http vary header in libsoup caching | MEDIUM | 5.9 | 37%ile | Microsoft | 2025-09-09 |
| CVE-2025-9232 | Out-of-bounds read in HTTP client no_proxy handling | MEDIUM | 5.9 | 81%ile | Microsoft | 2025-09-09 |
| CVE-2025-39857 | net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() | MEDIUM | 5.8 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-39739 | iommu/arm-smmu-qcom: Add SM6115 MDSS compatible | MEDIUM | 5.6 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39731 | f2fs: vm_unmap_ram() may be called from an invalid context | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39745 | rcutorture: Fix rcutorture_one_extend_check() splat in RT kernels | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39756 | fs: Prevent file descriptor table allocations exceeding INT_MAX | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39781 | parisc: Drop WARN_ON_ONCE() from flush_cache_vmap | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39760 | usb: core: config: Prevent OOB read in SS endpoint companion parsing | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39758 | RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages | MEDIUM | 5.5 | 28%ile | Microsoft | 2025-09-09 |
| CVE-2025-39764 | netfilter: ctnetlink: remove refcounting in expectation dumpers | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39753 | gfs2: Set .migrate_folio in gfs2_{rgrp,meta}_aops | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39779 | btrfs: subpage: keep TOWRITE tag until folio is cleaned | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39736 | mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39754 | mm/smaps: fix race between smaps_hugetlb_range and migration | MEDIUM | 5.5 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2025-39762 | drm/amd/display: add null check | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39773 | net: bridge: fix soft lockup in br_multicast_query_expired() | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39767 | LoongArch: Optimize module load time by optimizing PLT/GOT counting | MEDIUM | 5.5 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2025-39747 | drm/msm: Add error handling for krealloc in metadata setup | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39789 | crypto: x86/aegis - Add missing error checks | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39748 | bpf: Forget ranges when refining tnum after JSET | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39787 | soc: qcom: mdt_loader: Ensure we don't read past the ELF header | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39752 | ARM: rockchip: fix kernel hang during smp initialization | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39763 | ACPI: APEI: send SIGBUS to current task if synchronous memory error not recovered | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39772 | drm/hisilicon/hibmc: fix the hibmc loaded failed bug | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39737 | mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39744 | rcu: Fix rcu_read_unlock() deadloop due to IRQ work | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39819 | fs/smb: Fix inconsistent refcnt update | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39813 | ftrace: Fix potential warning in trace_printk_seq during ftrace_dump | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39827 | net: rose: include node references in rose_neigh refcount | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-09-09 |
| CVE-2025-39829 | trace/fgraph: Fix the warning caused by missing unregister notifier | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39805 | net: macb: fix unregister_netdev call order in macb_remove() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39808 | HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39812 | sctp: initialize more fields in sctp_v6_from_sk() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39842 | ocfs2: prevent release journal inode after journal shutdown | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39847 | ppp: fix memory leak in pad_compress_skb | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39846 | pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53149 | ext4: avoid deadlock in fs reclaim with page writeback | MEDIUM | 5.5 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2022-50266 | kprobes: Fix check for probe enabled in kill_kprobe() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53221 | bpf: Fix memleak due to fentry attach failure | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53240 | xsk: check IFF_UP earlier in Tx path | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53247 | btrfs: set_page_extent_mapped after read_folio in btrfs_cont_expand | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53231 | erofs: Fix detection of atomic context | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53323 | ext2/dax: Fix ext2_setsize when len is page aligned | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53332 | genirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask() | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2022-50407 | crypto: hisilicon/qm - increase the memory of local variables | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2023-53347 | net/mlx5: Handle pairing of E-switch via uplink un/load APIs | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2023-53348 | btrfs: fix deadlock when aborting transaction during relocation with scrub | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53410 | USB: ULPI: fix memory leak with using debugfs_lookup() | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53355 | staging: pi433: fix memory leak with using debugfs_lookup() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2023-53421 | blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53429 | btrfs: don't check PageError in __extent_writepage | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53383 | irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4 | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53387 | scsi: ufs: core: Fix device management cmd timeout flow | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53370 | drm/amdgpu: fix memory leak in mes self test | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38693 | media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38723 | LoongArch: BPF: Fix jump offset calculation in tailcall | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38696 | MIPS: Don't crash in stack_top() for tasks without ABI or vDSO | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-38691 | pNFS: Fix uninited ptr deref in block/scsi layout | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38681 | mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-38715 | hfs: fix slab-out-of-bounds in hfs_bnode_read() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38730 | io_uring/net: commit partial buffers on retry | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38716 | hfs: fix general protection fault in hfs_find_init() | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-38705 | drm/amd/pm: fix null pointer access | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38687 | comedi: fix race between polling and detaching | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-38712 | hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38721 | netfilter: ctnetlink: fix refcount leak on table dump | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-38711 | smb/server: avoid deadlock when linking with ReplaceIfExists | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-38722 | habanalabs: fix UAF in export_dmabuf() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38717 | net: kcm: Fix race condition in kcm_unattach() | MEDIUM | 5.5 | 1%ile | Microsoft | 2025-09-09 |
| CVE-2025-38725 | net: usb: asix_devices: add phy_mask for ax88772 mdio bus | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-38700 | scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39697 | NFS: Fix a race when updating an existing write | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39709 | media: venus: protect against spurious interrupts during probe | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39726 | s390/ism: fix concurrency management in ism_cmd() | MEDIUM | 5.5 | 12%ile | Microsoft | 2025-09-09 |
| CVE-2025-39718 | vsock/virtio: Validate length in packet header before skb_put() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39684 | comedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39692 | smb: server: split ksmbd_rdma_stop_listening() out of ksmbd_rdma_destroy() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39724 | serial: 8250: fix panic due to PSLVERR | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39720 | ksmbd: fix refcount leak causing resource not released | MEDIUM | 5.5 | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-39687 | iio: light: as73211: Ensure buffer holes are zeroed | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39693 | drm/amd/display: Avoid a NULL pointer dereference | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39705 | drm/amd/display: fix a Null pointer dereference vulnerability | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39706 | drm/amdkfd: Destroy KFD debugfs after destroy KFD wq | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39707 | drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-38734 | net/smc: fix UAF on smcsk after smc_listen_out() | MEDIUM | 5.5 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-39701 | ACPI: pfr_update: Fix the driver update version check | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39715 | parisc: Revise gateway LWS calls to probe user read access | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39675 | drm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39716 | parisc: Revise __get_user() to probe user read access | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-39719 | iio: imu: bno055: fix OOB access of hw_xlate array | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39714 | media: usbtv: Lock resolution while streaming | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39679 | drm/nouveau/nvif: Fix potential memory leak in nvif_vmm_ctor(). | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39676 | scsi: qla4xxx: Prevent a potential error pointer dereference | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-38736 | net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39681 | x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39798 | NFS: Fix the setting of capabilities when automounting a new filesystem | MEDIUM | 5.5 | 17%ile | Microsoft | 2025-09-09 |
| CVE-2025-39795 | block: avoid possible overflow for chunk_sectors check in blk_stack_limits() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39800 | btrfs: abort transaction on unexpected eb generation at btrfs_copy_root() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39799 | ACPI: processor: perflib: Move problematic pr->performance check | MEDIUM | 5.5 | — | Microsoft | 2025-09-09 |
| CVE-2022-50380 | mm: /proc/pid/smaps_rollup: fix no vma's null-deref | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39849 | wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-09-09 |
| CVE-2025-39845 | x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39862 | wifi: mt76: mt7915: fix list corruption after hardware restart | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2025-39844 | mm: move page table sync declarations to linux/pgtable.h | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39848 | ax25: properly unshare skbs in ax25_kiss_rcv() | MEDIUM | 5.5 | 13%ile | Microsoft | 2025-09-09 |
| CVE-2025-39885 | ocfs2: fix recursive semaphore deadlock in fiemap call | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-39881 | kernfs: Fix UAF in polling when open file is released | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39886 | bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39869 | dmaengine: ti: edma: Fix memory allocation size for queue_priority_map | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2025-39876 | net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39880 | libceph: fix invalid accesses to ceph_connection_v1_info | MEDIUM | 5.5 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-10911 | Libxslt: use-after-free with key data stored cross-rvt | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-11083 | GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow | MEDIUM | 5.5 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2022-50236 | iommu/mediatek: Fix crash on isr after kexec() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53152 | drm/amdgpu: fix calltrace warning in amddrm_buddy_fini | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2022-50260 | drm/msm: Make .remove and .shutdown HW shutdown consistent | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2022-50350 | scsi: target: iscsi: Fix a race condition between login_work and the login thread | MEDIUM | 5.5 | 16%ile | Microsoft | 2025-09-09 |
| CVE-2023-53261 | coresight: Fix memory leak in acpi_buffer->pointer | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2023-53292 | blk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2022-50316 | orangefs: Fix kmemleak in orangefs_sysfs_init() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53248 | drm/amdgpu: install stub fence into potential unused fence pointers | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2022-50304 | mtd: core: fix possible resource leak in init_mtd() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53209 | wifi: mac80211_hwsim: Fix possible NULL dereference | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2022-50357 | usb: dwc3: core: fix some leaks in probe | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2023-53353 | accel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2023-53424 | clk: mediatek: fix of_iomap memory leak | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53438 | x86/MCE: Always save CS register on AMD Zen IF Poison errors | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53366 | block: be a bit more careful in checking for NULL bdev while polling | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-09-09 |
| CVE-2023-53367 | accel/habanalabs: fix mem leak in capture user mappings | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50390 | drm/ttm: fix undefined behavior in bit shift for TTM_TT_FLAG_PRIV_POPULATED | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50393 | drm/amdgpu: SDMA update use unlocked iterator | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2022-50418 | wifi: ath11k: mhi: fix potential memory leak in ath11k_mhi_register() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2023-53371 | net/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2024-58241 | Bluetooth: hci_core: Disable works on hci_unregister_dev | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-38683 | hv_netvsc: Fix panic during namespace deletion with VF | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2025-39734 | Revert "fs/ntfs3: Replace inode_trylock with inode_lock" | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2022-50327 | ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-39770 | net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM | MEDIUM | 5.5 | 26%ile | Microsoft | 2025-09-09 |
| CVE-2025-39782 | jbd2: prevent softlockup in jbd2_log_do_checkpoint() | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2025-53799 | Windows Imaging Component Information Disclosure Vulnerability | MEDIUM | 5.5 | 51%ile | Microsoft | 2025-09-09 |
| CVE-2025-53803 | Windows Kernel Memory Information Disclosure Vulnerability | MEDIUM | 5.5 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-53804 | Windows Kernel-Mode Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 46%ile | Microsoft | 2025-09-09 |
| CVE-2025-54901 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 45%ile | Microsoft | 2025-09-09 |
| CVE-2025-48040 | Malicious Key Exchange Messages may Lead to Excessive Resource Consumption | MEDIUM | 5.3 | 33%ile | Microsoft | 2025-09-09 |
| CVE-2025-46148 | In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results. | MEDIUM | 5.3 | 30%ile | Microsoft | 2025-09-09 |
| CVE-2025-58749 | WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode | MEDIUM | 5.3 | 27%ile | Microsoft | 2025-09-09 |
| CVE-2025-10824 | axboe fio init.c __parse_jobs_ini use after free | MEDIUM | 5.3 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2025-46152 | In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" a | MEDIUM | 5.3 | 35%ile | Microsoft | 2025-09-09 |
| CVE-2025-11082 | GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow | MEDIUM | 5.3 | 14%ile | Microsoft | 2025-09-09 |
| CVE-2025-46153 | PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency wit | MEDIUM | 5.3 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-46149 | In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error. | MEDIUM | 5.3 | 26%ile | Microsoft | 2025-09-09 |
| CVE-2025-46150 | In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results. | MEDIUM | 5.3 | 29%ile | Microsoft | 2025-09-09 |
| CVE-2025-55554 | pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). | MEDIUM | 5.3 | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-60018 | Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certific | MEDIUM | 4.8 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-54101 | Windows SMB Client Remote Code Execution Vulnerability | MEDIUM | 4.8 | 82%ile | Microsoft | 2025-09-09 |
| CVE-2025-38706 | ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() | MEDIUM | 4.7 | 8%ile | Microsoft | 2025-09-09 |
| CVE-2025-39867 | netfilter: nft_set_pipapo: fix null deref for empty set | MEDIUM | 4.7 | — | Microsoft | 2025-09-09 |
| CVE-2023-53178 | mm: fix zswap writeback race condition | MEDIUM | 4.7 | 2%ile | Microsoft | 2025-09-09 |
| CVE-2023-53401 | mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required() | MEDIUM | 4.7 | 3%ile | Microsoft | 2025-09-09 |
| CVE-2023-53447 | f2fs: don't reset unchangable mount option in f2fs_remount() | MEDIUM | 4.7 | 0%ile | Microsoft | 2025-09-09 |
| CVE-2025-47967 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | MEDIUM | 4.7 | 27%ile | Microsoft | 2025-09-09 |
| CVE-2025-53791 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | MEDIUM | 4.7 | 29%ile | Microsoft | 2025-09-09 |
| CVE-2025-9086 | Out of bounds read for cookie path | MEDIUM | 4.3 | 68%ile | Microsoft | 2025-09-09 |
| CVE-2025-48038 | Unverified File Handles can Cause Excessive Use of System Resources | MEDIUM | 4.3 | 29%ile | Microsoft | 2025-09-09 |
| CVE-2025-48039 | Unverified Paths can Cause Excessive Use of System Resources | MEDIUM | 4.3 | 29%ile | Microsoft | 2025-09-09 |
| CVE-2025-54107 | MapUrlToZone Security Feature Bypass Vulnerability | MEDIUM | 4.3 | 55%ile | Microsoft | 2025-09-09 |
| CVE-2025-54917 | MapUrlToZone Security Feature Bypass Vulnerability | MEDIUM | 4.3 | 54%ile | Microsoft | 2025-09-09 |
| CVE-2025-49728 | Microsoft PC Manager Security Feature Bypass Vulnerability | MEDIUM | 4.0 | 13%ile | Microsoft | 2025-09-09 |
| CVE-2025-60019 | Glib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via | LOW | 3.7 | 26%ile | Microsoft | 2025-09-09 |
| CVE-2025-7039 | Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file() | LOW | 3.7 | 32%ile | Microsoft | 2025-09-09 |
| CVE-2025-10823 | axboe fio options.c str_buffer_pattern_cb null pointer dereference | LOW | 3.3 | 4%ile | Microsoft | 2025-09-09 |
| CVE-2025-11081 | GNU Binutils objdump.c dump_dwarf_section out-of-bounds | LOW | 3.3 | 9%ile | Microsoft | 2025-09-09 |
| CVE-2025-8277 | Libssh: memory exhaustion via repeated key exchange in libssh | LOW | 3.1 | 30%ile | Microsoft | 2025-09-09 |
| CVE-2025-58354 | Kata Containers coco-tdx malicious host can circumvent initdata verification | UNKNOWN | — | 24%ile | Microsoft | 2025-09-09 |
| CVE-2025-8869 | Fallback tar extraction in pip doesn't check symbolic links point to extraction directory | UNKNOWN | — | 36%ile | Microsoft | 2025-09-09 |
| CVE-2025-59825 | astral-tokio-tar has a path traversal in tar extraction | UNKNOWN | — | 10%ile | Microsoft | 2025-09-09 |
| CVE-2025-9648 | Denial of Service in CivetWeb | UNKNOWN | — | 50%ile | Microsoft | 2025-09-09 |
| CVE-2025-10501 | Chromium: CVE-2025-10501 Use after free in WebRTC | UNKNOWN | — | 19%ile | Microsoft | 2025-09-09 |
| CVE-2025-10585 | Chromium: CVE-2025-10585 Type Confusion in V8 | UNKNOWN | — | 92%ile | Microsoft | 2025-09-09 |
| CVE-2025-10890 | Chromium: CVE-2025-10890 Side-channel information leakage in V8 | UNKNOWN | — | 22%ile | Microsoft | 2025-09-09 |
| CVE-2024-21907 | VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json | UNKNOWN | — | 98%ile | Microsoft | 2025-09-09 |
| CVE-2025-9867 | Chromium: CVE-2025-9867 Inappropriate implementation in Downloads | UNKNOWN | — | 22%ile | Microsoft | 2025-09-09 |
| CVE-2025-9866 | Chromium: CVE-2025-9866 Inappropriate implementation in Extensions | UNKNOWN | — | 29%ile | Microsoft | 2025-09-09 |
| CVE-2025-9865 | Chromium: CVE-2025-9865 Inappropriate implementation in Toolbar | UNKNOWN | — | 17%ile | Microsoft | 2025-09-09 |
| CVE-2025-9864 | Chromium: CVE-2025-9864 Use after free in V8 | UNKNOWN | — | — | Microsoft | 2025-09-09 |
| CVE-2025-10201 | Chromium: CVE-2025-10201 Inappropriate implementation in Mojo | UNKNOWN | — | 17%ile | Microsoft | 2025-09-09 |
| CVE-2025-10200 | Chromium: CVE-2025-10200 Use after free in Serviceworker | UNKNOWN | — | 45%ile | Microsoft | 2025-09-09 |
| CVE-2025-10502 | Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE | UNKNOWN | — | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-10500 | Chromium: CVE-2025-10500 Use after free in Dawn | UNKNOWN | — | 17%ile | Microsoft | 2025-09-09 |
| CVE-2025-10891 | Chromium: CVE-2025-10891 Integer overflow in V8 | UNKNOWN | — | 93%ile | Microsoft | 2025-09-09 |
| CVE-2025-10892 | Chromium: CVE-2025-10892 Integer overflow in V8 | UNKNOWN | — | 18%ile | Microsoft | 2025-09-09 |
| CVE-2025-49747 | Azure Machine Learning Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 47%ile | Microsoft | 2025-07-08 |
| CVE-2025-49746 | Azure Machine Learning Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 49%ile | Microsoft | 2025-07-08 |
| CVE-2025-38483 | comedi: das16m1: Fix bit shift out of bounds | CRITICAL | 9.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38482 | comedi: das6402: Fix bit shift out of bounds | CRITICAL | 9.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38497 | usb: gadget: configfs: Fix OOB read on empty string write | CRITICAL | 9.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2024-25176 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strf | CRITICAL | 9.8 | 39%ile | Microsoft | 2025-07-08 |
| CVE-2025-6965 | Integer Truncation on SQLite | CRITICAL | 9.8 | 100%ile | Microsoft | 2025-07-08 |
| CVE-2025-38478 | comedi: Fix initialization of data for instructions that write to subdevice | CRITICAL | 9.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38490 | net: libwx: remove duplicate page_pool_put_full_page() | CRITICAL | 9.8 | 22%ile | Microsoft | 2025-07-08 |
| CVE-2025-47981 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | CRITICAL | 9.8 | 98%ile | Microsoft | 2025-07-08 |
| CVE-2025-53770 | Microsoft SharePoint Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100%ile | Microsoft | 2025-07-08 |
| CVE-2024-25178 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler i | CRITICAL | 9.4 | 42%ile | Microsoft | 2025-07-08 |
| CVE-2024-48916 | Ceph is vulnerable to authentication bypass through RadosGW | CRITICAL | 9.1 | 9%ile | Microsoft | 2025-07-08 |
| CVE-2025-23048 | Apache HTTP Server: mod_ssl access control bypass with session resumption | CRITICAL | 9.1 | 58%ile | Microsoft | 2025-07-08 |
| CVE-2025-7458 | SQLite integer overflow in key info allocation may lead to information disclosure. | CRITICAL | 9.1 | 14%ile | Microsoft | 2025-07-08 |
| CVE-2025-23266 | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher | CRITICAL | 9.0 | 83%ile | Microsoft | 2025-07-08 |
| CVE-2025-47158 | Azure DevOps Server Elevation of Privilege Vulnerability | CRITICAL | 9.0 | 49%ile | Microsoft | 2025-07-08 |
| CVE-2025-51480 | Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit | HIGH | 8.8 | 44%ile | Microsoft | 2025-07-08 |
| CVE-2025-47986 | Universal Print Management Service Elevation of Privilege Vulnerability | HIGH | 8.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-48824 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 56%ile | Microsoft | 2025-07-08 |
| CVE-2025-49657 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2025-07-08 |
| CVE-2025-49672 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2025-07-08 |
| CVE-2025-49674 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-49676 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2025-07-08 |
| CVE-2025-49687 | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | HIGH | 8.8 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-49688 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2025-07-08 |
| CVE-2025-49723 | Windows StateRepository API Server file Tampering Vulnerability | HIGH | 8.8 | 24%ile | Microsoft | 2025-07-08 |
| CVE-2025-49713 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.8 | 49%ile | Microsoft | 2025-07-08 |
| CVE-2025-49753 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-47998 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2025-07-08 |
| CVE-2025-48817 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2025-07-08 |
| CVE-2025-49663 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-49668 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-49669 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-49673 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-49701 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 55%ile | Microsoft | 2025-07-08 |
| CVE-2025-49704 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 100%ile | Microsoft | 2025-07-08 |
| CVE-2025-49724 | Windows Connected Devices Platform Service Remote Code Execution Vulnerability | HIGH | 8.8 | 94%ile | Microsoft | 2025-07-08 |
| CVE-2025-49729 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 44%ile | Microsoft | 2025-07-08 |
| CVE-2025-49739 | Visual Studio Elevation of Privilege Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2025-07-08 |
| CVE-2025-49740 | Windows SmartScreen Security Feature Bypass Vulnerability | HIGH | 8.8 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-53762 | Microsoft Purview Elevation of Privilege Vulnerability | HIGH | 8.7 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-4674 | Unexpected command execution in untrusted VCS repositories in cmd/go | HIGH | 8.6 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2025-53547 | Helm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink Can Lead To Code Execution | HIGH | 8.6 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-48822 | Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability | HIGH | 8.6 | 45%ile | Microsoft | 2025-07-08 |
| CVE-2025-49717 | Microsoft SQL Server Remote Code Execution Vulnerability | HIGH | 8.5 | 57%ile | Microsoft | 2025-07-08 |
| CVE-2025-38349 | eventpoll: don't decrement ep refcount while still holding the ep mutex | HIGH | 8.4 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-49695 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 45%ile | Microsoft | 2025-07-08 |
| CVE-2025-49696 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-49697 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-33054 | Remote Desktop Spoofing Vulnerability | HIGH | 8.1 | 54%ile | Microsoft | 2025-07-08 |
| CVE-2025-49735 | Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability | HIGH | 8.1 | 61%ile | Microsoft | 2025-07-08 |
| CVE-2025-47972 | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | HIGH | 8.0 | 42%ile | Microsoft | 2025-07-08 |
| CVE-2025-49691 | Windows Miracast Wireless Display Remote Code Execution Vulnerability | HIGH | 8.0 | 37%ile | Microsoft | 2025-07-08 |
| CVE-2025-47178 | Microsoft Configuration Manager Remote Code Execution Vulnerability | HIGH | 8.0 | 80%ile | Microsoft | 2025-07-08 |
| CVE-2025-38118 | Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38183 | net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get() | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38198 | fbcon: Make sure modelist not set on unregistered console | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38212 | ipc: fix to protect IPCS lookups using RCU | HIGH | 7.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38236 | af_unix: Don't leave consecutive consumed OOB skbs. | HIGH | 7.8 | 17%ile | Microsoft | 2025-07-08 |
| CVE-2025-38257 | s390/pkey: Prevent overflow in size calculation for memdup_user() | HIGH | 7.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38313 | bus: fsl-mc: fix double-free on mc_dev | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38332 | scsi: lpfc: Use memcpy() for BIOS version | HIGH | 7.8 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38428 | Input: ims-pcu - check record size in ims_pcu_flash_firmware() | HIGH | 7.8 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38466 | perf: Revert to requiring CAP_SYS_ADMIN for uprobes | HIGH | 7.8 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38437 | ksmbd: fix potential use-after-free in oplock/lease break ack | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-38439 | bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT | HIGH | 7.8 | 39%ile | Microsoft | 2025-07-08 |
| CVE-2025-38456 | ipmi:msghandler: Fix potential memory corruption in ipmi_create_user() | HIGH | 7.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38375 | virtio-net: ensure the received length does not exceed allocated size | HIGH | 7.8 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38401 | mtk-sd: Prevent memory corruption from DMA map failure | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38465 | netlink: Fix wraparounds of sk->sk_rmem_alloc. | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38361 | drm/amd/display: Check dce_hwseq before dereferencing it | HIGH | 7.8 | 9%ile | Microsoft | 2025-07-08 |
| CVE-2025-38443 | nbd: fix uaf in nbd_genl_connect() error path | HIGH | 7.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-52496 | Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may b | HIGH | 7.8 | 9%ile | Microsoft | 2025-07-08 |
| CVE-2025-38464 | tipc: Fix use-after-free in tipc_conn_close(). | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38459 | atm: clip: Fix infinite recursive call of clip_push(). | HIGH | 7.8 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38129 | page_pool: Fix use-after-free in page_pool_recycle_in_ring | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38477 | net/sched: sch_qfq: Fix race condition on qfq_aggregate | HIGH | 7.8 | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38494 | HID: core: do not bypass hid_hw_raw_request | HIGH | 7.8 | 10%ile | Microsoft | 2025-07-08 |
| CVE-2025-38476 | rpl: Fix use-after-free in rpl_do_srh_inline(). | HIGH | 7.8 | 25%ile | Microsoft | 2025-07-08 |
| CVE-2025-38485 | iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush | HIGH | 7.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-7425 | Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr | HIGH | 7.8 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-38096 | wifi: iwlwifi: don't warn when if there is a FW error | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38350 | net/sched: Always pass notifications when child class becomes empty | HIGH | 7.8 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38488 | smb: client: fix use-after-free in crypt_message when using async crypto | HIGH | 7.8 | 46%ile | Microsoft | 2025-07-08 |
| CVE-2023-6175 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark | HIGH | 7.8 | 88%ile | Microsoft | 2025-07-08 |
| CVE-2025-38091 | drm/amd/display: check stream id dml21 wrapper to get plane_id | HIGH | 7.8 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38131 | coresight: prevent deactivate active config while enabling the config | HIGH | 7.8 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38147 | calipso: Don't call calipso functions for AF_INET sk. | HIGH | 7.8 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38230 | jfs: validate AG parameters in dbMount() to prevent crashes | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38245 | atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister(). | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38259 | ASoC: codecs: wcd9335: Fix missing free of regulator supplies | HIGH | 7.8 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38290 | wifi: ath12k: fix node corruption in ar->arvifs list | HIGH | 7.8 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38312 | fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() | HIGH | 7.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38323 | net: atm: add lec_mutex | HIGH | 7.8 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38338 | fs/nfs/read: fix double-unlock bug in nfs_return_empty_folio() | HIGH | 7.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38422 | net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38425 | i2c: tegra: check msg length in SMBUS block read | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-49809 | mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environm | HIGH | 7.8 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38311 | iavf: get rid of the crit lock | HIGH | 7.8 | 1%ile | Microsoft | 2025-07-08 |
| CVE-2025-38377 | rose: fix dangling neighbour pointers in rose_rt_device_down() | HIGH | 7.8 | 14%ile | Microsoft | 2025-07-08 |
| CVE-2025-47159 | Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-47971 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-47976 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 32%ile | Microsoft | 2025-07-08 |
| CVE-2025-47985 | Windows Event Tracing Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-47987 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | HIGH | 7.8 | 75%ile | Microsoft | 2025-07-08 |
| CVE-2025-49661 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-49686 | Windows TCP/IP Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-49689 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | HIGH | 7.8 | 48%ile | Microsoft | 2025-07-08 |
| CVE-2025-49694 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-47991 | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | HIGH | 7.8 | 23%ile | Microsoft | 2025-07-08 |
| CVE-2025-47993 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-47994 | Microsoft Office Elevation of Privilege Vulnerability | HIGH | 7.8 | 85%ile | Microsoft | 2025-07-08 |
| CVE-2025-49711 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2025-07-08 |
| CVE-2025-49721 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2025-07-08 |
| CVE-2025-49726 | Windows Notification Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-47973 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-47982 | Windows Storage VSP Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-47996 | Windows MBT Transport Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-48000 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 21%ile | Microsoft | 2025-07-08 |
| CVE-2025-48799 | Windows Update Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 61%ile | Microsoft | 2025-07-08 |
| CVE-2025-48805 | Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-48806 | Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-48815 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 35%ile | Microsoft | 2025-07-08 |
| CVE-2025-48816 | HID Class Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-48820 | Windows AppX Deployment Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 34%ile | Microsoft | 2025-07-08 |
| CVE-2025-49659 | Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-49660 | Windows Event Tracing Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-49665 | Workspace Broker Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2025-49667 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2025-07-08 |
| CVE-2025-49675 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 29%ile | Microsoft | 2025-07-08 |
| CVE-2025-49679 | Windows Shell Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-49683 | Microsoft Virtual Hard Disk Remote Code Execution Vulnerability | HIGH | 7.8 | 78%ile | Microsoft | 2025-07-08 |
| CVE-2025-49693 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-49698 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2025-07-08 |
| CVE-2025-49700 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2025-07-08 |
| CVE-2025-49702 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2025-07-08 |
| CVE-2025-49703 | Microsoft Word Remote Code Execution Vulnerability | HIGH | 7.8 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-49705 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 31%ile | Microsoft | 2025-07-08 |
| CVE-2025-49714 | Visual Studio Code Python Extension Remote Code Execution Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2025-07-08 |
| CVE-2025-49725 | Windows Notification Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2025-49730 | Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 45%ile | Microsoft | 2025-07-08 |
| CVE-2025-49732 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2025-49733 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2025-49738 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-49742 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2025-38248 | bridge: mcast: Fix use-after-free during router port configuration | HIGH | 7.6 | 17%ile | Microsoft | 2025-07-08 |
| CVE-2025-48367 | Redis DoS Vulnerability due to bad connection error handling | HIGH | 7.5 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-49630 | Apache HTTP Server: mod_proxy_http2 denial of service | HIGH | 7.5 | 64%ile | Microsoft | 2025-07-08 |
| CVE-2025-49812 | Apache HTTP Server: mod_ssl TLS upgrade attack | HIGH | 7.5 | 41%ile | Microsoft | 2025-07-08 |
| CVE-2025-8194 | Tarfile infinite loop during parsing with negative member offset | HIGH | 7.5 | 46%ile | Microsoft | 2025-07-08 |
| CVE-2024-25177 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which l | HIGH | 7.5 | 37%ile | Microsoft | 2025-07-08 |
| CVE-2025-40777 | A possible assertion failure when 'stale-answer-client-timeout' is set to '0' | HIGH | 7.5 | 56%ile | Microsoft | 2025-07-08 |
| CVE-2023-50967 | latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PB | HIGH | 7.5 | 70%ile | Microsoft | 2025-07-08 |
| CVE-2024-42516 | Apache HTTP Server: HTTP response splitting | HIGH | 7.5 | 49%ile | Microsoft | 2025-07-08 |
| CVE-2024-43204 | Apache HTTP Server: SSRF with mod_headers setting Content-Type header | HIGH | 7.5 | 52%ile | Microsoft | 2025-07-08 |
| CVE-2024-47252 | Apache HTTP Server: mod_ssl error log variable escaping | HIGH | 7.5 | 48%ile | Microsoft | 2025-07-08 |
| CVE-2025-53020 | Apache HTTP Server: HTTP/2 DoS by Memory Increase | HIGH | 7.5 | 91%ile | Microsoft | 2025-07-08 |
| CVE-2025-7345 | Gdk‑pixbuf: heap‑buffer‑overflow in gdk‑pixbuf | HIGH | 7.5 | 61%ile | Microsoft | 2025-07-08 |
| CVE-2025-24294 | The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the le | HIGH | 7.5 | 42%ile | Microsoft | 2025-07-08 |
| CVE-2025-47984 | Windows GDI Information Disclosure Vulnerability | HIGH | 7.5 | 96%ile | Microsoft | 2025-07-08 |
| CVE-2025-49716 | Windows Netlogon Denial of Service Vulnerability | HIGH | 7.5 | 68%ile | Microsoft | 2025-07-08 |
| CVE-2025-49719 | Microsoft SQL Server Information Disclosure Vulnerability | HIGH | 7.5 | 95%ile | Microsoft | 2025-07-08 |
| CVE-2025-48814 | Remote Desktop Licensing Service Security Feature Bypass Vulnerability | HIGH | 7.5 | 60%ile | Microsoft | 2025-07-08 |
| CVE-2025-49718 | Microsoft SQL Server Information Disclosure Vulnerability | HIGH | 7.5 | 85%ile | Microsoft | 2025-07-08 |
| CVE-2025-47988 | Azure Monitor Agent Remote Code Execution Vulnerability | HIGH | 7.5 | 54%ile | Microsoft | 2025-07-08 |
| CVE-2025-38352 | posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() | HIGH | 7.4 | 66%ile | Microsoft | 2025-07-08 |
| CVE-2025-38471 | tls: always refresh the queue when reading sock | HIGH | 7.4 | 32%ile | Microsoft | 2025-07-08 |
| CVE-2025-49690 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | HIGH | 7.4 | 16%ile | Microsoft | 2025-07-08 |
| CVE-2025-49741 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.4 | 88%ile | Microsoft | 2025-07-08 |
| CVE-2025-38461 | vsock: Fix transport_* TOCTOU | HIGH | 7.3 | 2%ile | Microsoft | 2025-07-08 |
| CVE-2025-38250 | Bluetooth: hci_core: Fix use-after-free in vhci_flush() | HIGH | 7.3 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-7424 | Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes | HIGH | 7.3 | 65%ile | Microsoft | 2025-07-08 |
| CVE-2025-49680 | Windows Performance Recorder (WPR) Denial of Service Vulnerability | HIGH | 7.3 | 39%ile | Microsoft | 2025-07-08 |
| CVE-2025-49682 | Windows Media Elevation of Privilege Vulnerability | HIGH | 7.3 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-49666 | Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability | HIGH | 7.2 | 64%ile | Microsoft | 2025-07-08 |
| CVE-2025-38277 | mtd: nand: ecc-mxic: Fix use of uninitialized variable ret | HIGH | 7.1 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38278 | octeontx2-pf: QOS: Refactor TC_HTB_LEAF_DEL_LAST callback | HIGH | 7.1 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38285 | bpf: Fix WARN() in get_bpf_raw_tp_regs | HIGH | 7.1 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38429 | bus: mhi: ep: Update read pointer only after buffer is written | HIGH | 7.1 | 31%ile | Microsoft | 2025-07-08 |
| CVE-2025-38457 | net/sched: Abort __tc_modify_qdisc if parent class does not exist | HIGH | 7.1 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38445 | md/raid1: Fix stack memory use after return in raid1_reshape | HIGH | 7.1 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38386 | ACPICA: Refuse to evaluate a method if arguments are missing | HIGH | 7.1 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38403 | vsock/vmci: Clear the vmci transport packet properly when initializing it | HIGH | 7.1 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38463 | tcp: Correct signedness in skb remaining space calculation | HIGH | 7.1 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38438 | ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak. | HIGH | 7.1 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38379 | smb: client: fix warning when reconnecting channel | HIGH | 7.1 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-38237 | media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() | HIGH | 7.1 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38264 | nvme-tcp: sanitize request list handling | HIGH | 7.1 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2025-38410 | drm/msm: Fix a fence leak in submit error path | HIGH | 7.1 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38380 | i2c/designware: Fix an initialization issue | HIGH | 7.1 | — | Microsoft | 2025-07-08 |
| CVE-2025-38329 | firmware: cs_dsp: Fix OOB memory read access in KUnit test (wmfw info) | HIGH | 7.1 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38330 | firmware: cs_dsp: Fix OOB memory read access in KUnit test (ctl cache) | HIGH | 7.1 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38111 | net/mdiobus: Fix potential out-of-bounds read/write access | HIGH | 7.1 | 9%ile | Microsoft | 2025-07-08 |
| CVE-2025-38159 | wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds | HIGH | 7.1 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38249 | ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() | HIGH | 7.1 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38283 | hisi_acc_vfio_pci: bugfix live migration function without VF device driver | HIGH | 7.1 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38310 | seg6: Fix validation of nexthop addresses | HIGH | 7.1 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38328 | jffs2: check jffs2_prealloc_raw_node_refs() result in few other places | HIGH | 7.1 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38430 | nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request | HIGH | 7.1 | 40%ile | Microsoft | 2025-07-08 |
| CVE-2025-38409 | drm/msm: Fix another leak in the submit error path | HIGH | 7.1 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38395 | regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods | HIGH | 7.1 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38412 | platform/x86: dell-wmi-sysman: Fix WMI data block retrieval in sysfs callbacks | HIGH | 7.1 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-48819 | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability | HIGH | 7.1 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-48821 | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability | HIGH | 7.1 | 37%ile | Microsoft | 2025-07-08 |
| CVE-2025-38100 | x86/iopl: Cure TIF_IO_BITMAP inconsistencies | HIGH | 7.0 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38126 | net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38157 | wifi: ath9k_htc: Abort software beacon handling if disabled | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38160 | clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38184 | tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer | HIGH | 7.0 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38193 | net_sched: sch_sfq: reject invalid perturb period | HIGH | 7.0 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38200 | i40e: fix MMIO write access to an invalid page in i40e_clear_hw | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38369 | dmaengine: idxd: Check availability of workqueue allocated by idxd wq driver before using | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38420 | wifi: carl9170: do not ping device which has failed to load firmware | HIGH | 7.0 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38458 | atm: clip: Fix NULL pointer dereference in vcc_sendmsg() | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38399 | scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port() | HIGH | 7.0 | 34%ile | Microsoft | 2025-07-08 |
| CVE-2025-38408 | genirq/irq_sim: Initialize work context pointers properly | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38462 | vsock: Fix transport_{g2h,h2g} TOCTOU | HIGH | 7.0 | 2%ile | Microsoft | 2025-07-08 |
| CVE-2025-38206 | exfat: fix double free in delayed_free | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38414 | wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition for WCN7850 | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38449 | drm/gem: Acquire references on GEM handles for framebuffers | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38099 | Bluetooth: Disable SCO support if READ_VOICE_SETTING is unsupported/broken | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38105 | ALSA: usb-audio: Kill timer properly at removal | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38125 | net: stmmac: make sure that ptp_rate is not 0 before configuring EST | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38495 | HID: core: ensure the allocated report buffer can contain the reserved report ID | HIGH | 7.0 | 21%ile | Microsoft | 2025-07-08 |
| CVE-2025-38162 | netfilter: nft_set_pipapo: prevent overflow in lookup table allocation | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38491 | mptcp: make fallback action and fallback decision atomic | HIGH | 7.0 | 10%ile | Microsoft | 2025-07-08 |
| CVE-2025-38493 | tracing/osnoise: Fix crash in timerlat_dump_stack() | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38204 | jfs: fix array-index-out-of-bounds read in add_missing_indices | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-32023 | Redis allows out of bounds writes in hyperloglog commands leading to RCE | HIGH | 7.0 | 89%ile | Microsoft | 2025-07-08 |
| CVE-2025-38107 | net_sched: ets: fix a race in ets_qdisc_change() | HIGH | 7.0 | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38146 | net: openvswitch: Fix the dead loop of MPLS parse | HIGH | 7.0 | 33%ile | Microsoft | 2025-07-08 |
| CVE-2025-38149 | net: phy: clear phydev->devlink when the link is deleted | HIGH | 7.0 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38170 | arm64/fpsimd: Discard stale CPU state when handling SME traps | HIGH | 7.0 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38180 | net: atm: fix /proc/net/atm/lec handling | HIGH | 7.0 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38181 | calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). | HIGH | 7.0 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-38182 | ublk: santizize the arguments from userspace when adding a device | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38194 | jffs2: check that raw node were preallocated before writing summary | HIGH | 7.0 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38197 | platform/x86: dell_rbu: Fix list usage | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38214 | fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38220 | ext4: only dirty folios when data journaling regular files | HIGH | 7.0 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38229 | media: cxusb: no longer judge rbuf when the write fails | HIGH | 7.0 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38244 | smb: client: fix potential deadlock when reconnecting channels | HIGH | 7.0 | 12%ile | Microsoft | 2025-07-08 |
| CVE-2025-38363 | drm/tegra: Fix a possible null pointer dereference | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38415 | Squashfs: check return result of sb_min_blocksize | HIGH | 7.0 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38424 | perf: Fix sample vs do_exit() | HIGH | 7.0 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38436 | drm/scheduler: signal scheduled fence when kill job | HIGH | 7.0 | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38468 | net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38140 | dm: limit swapping tables for devices with zone write plugs | HIGH | 7.0 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-45768 | pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length i | HIGH | 7.0 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-49677 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 58%ile | Microsoft | 2025-07-08 |
| CVE-2025-47975 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 25%ile | Microsoft | 2025-07-08 |
| CVE-2025-49678 | NTFS Elevation of Privilege Vulnerability | HIGH | 7.0 | 14%ile | Microsoft | 2025-07-08 |
| CVE-2025-49685 | Windows Search Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 25%ile | Microsoft | 2025-07-08 |
| CVE-2025-49699 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.0 | 25%ile | Microsoft | 2025-07-08 |
| CVE-2025-49727 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.0 | 28%ile | Microsoft | 2025-07-08 |
| CVE-2025-49737 | Microsoft Teams Elevation of Privilege Vulnerability | HIGH | 7.0 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-49744 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH | 7.0 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-48001 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 32%ile | Microsoft | 2025-07-08 |
| CVE-2025-48003 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-48800 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-48804 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-48818 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 34%ile | Microsoft | 2025-07-08 |
| CVE-2025-47999 | Windows Hyper-V Denial of Service Vulnerability | MEDIUM | 6.8 | 30%ile | Microsoft | 2025-07-08 |
| CVE-2025-7519 | Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write | MEDIUM | 6.7 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-48803 | Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 17%ile | Microsoft | 2025-07-08 |
| CVE-2025-48811 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 17%ile | Microsoft | 2025-07-08 |
| CVE-2025-8197 | Rejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465 | MEDIUM | 6.6 | — | Microsoft | 2025-07-08 |
| CVE-2025-50078 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte | MEDIUM | 6.5 | 42%ile | Microsoft | 2025-07-08 |
| CVE-2025-48924 | Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs | MEDIUM | 6.5 | 80%ile | Microsoft | 2025-07-08 |
| CVE-2025-48964 | ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data co | MEDIUM | 6.5 | 25%ile | Microsoft | 2025-07-08 |
| CVE-2025-40913 | Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow | MEDIUM | 6.5 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2023-4527 | Glibc: stack read overflow in getaddrinfo in no-aaaa mode | MEDIUM | 6.5 | 72%ile | Microsoft | 2025-07-08 |
| CVE-2023-5371 | Memory Allocation with Excessive Size Value in Wireshark | MEDIUM | 6.5 | 39%ile | Microsoft | 2025-07-08 |
| CVE-2023-6174 | Out-of-bounds Read in Wireshark | MEDIUM | 6.5 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-50082 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 6.5 | 42%ile | Microsoft | 2025-07-08 |
| CVE-2025-32988 | Gnutls: vulnerability in gnutls othername san export | MEDIUM | 6.5 | 65%ile | Microsoft | 2025-07-08 |
| CVE-2025-32990 | Gnutls: vulnerability in gnutls certtool template parsing | MEDIUM | 6.5 | 50%ile | Microsoft | 2025-07-08 |
| CVE-2025-38192 | net: clear the dst when changing skb protocol | MEDIUM | 6.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-50083 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 6.5 | 42%ile | Microsoft | 2025-07-08 |
| CVE-2025-6395 | Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite() | MEDIUM | 6.5 | 46%ile | Microsoft | 2025-07-08 |
| CVE-2025-49670 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | MEDIUM | 6.5 | 55%ile | Microsoft | 2025-07-08 |
| CVE-2025-49671 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2025-07-08 |
| CVE-2025-53771 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 100%ile | Microsoft | 2025-07-08 |
| CVE-2025-47978 | Windows Kerberos Denial of Service Vulnerability | MEDIUM | 6.5 | 78%ile | Microsoft | 2025-07-08 |
| CVE-2025-48802 | Windows SMB Server Spoofing Vulnerability | MEDIUM | 6.5 | 52%ile | Microsoft | 2025-07-08 |
| CVE-2025-49681 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2025-07-08 |
| CVE-2025-49706 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 100%ile | Microsoft | 2025-07-08 |
| CVE-2025-47995 | Azure Machine Learning Elevation of Privilege Vulnerability | MEDIUM | 6.5 | 47%ile | Microsoft | 2025-07-08 |
| CVE-2025-38472 | netfilter: nf_conntrack: fix crash due to removal of uninitialised entry | MEDIUM | 6.3 | 34%ile | Microsoft | 2025-07-08 |
| CVE-2025-38337 | jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata() | MEDIUM | 6.3 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-54090 | Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 | MEDIUM | 6.3 | 49%ile | Microsoft | 2025-07-08 |
| CVE-2025-38344 | ACPICA: fix acpi parse and parseext cache leaks | MEDIUM | 6.2 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38448 | usb: gadget: u_serial: Fix race condition in TTY wakeup | MEDIUM | 6.2 | 2%ile | Microsoft | 2025-07-08 |
| CVE-2025-47980 | Windows Imaging Component Information Disclosure Vulnerability | MEDIUM | 6.2 | 44%ile | Microsoft | 2025-07-08 |
| CVE-2025-38340 | firmware: cs_dsp: Fix OOB memory read access in KUnit test | MEDIUM | 6.0 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2023-53034 | ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans | MEDIUM | 6.0 | 22%ile | Microsoft | 2025-07-08 |
| CVE-2025-21195 | Azure Service Fabric Runtime Elevation of Privilege Vulnerability | MEDIUM | 6.0 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-6491 | NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix | MEDIUM | 5.9 | 58%ile | Microsoft | 2025-07-08 |
| CVE-2025-53605 | The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputSt | MEDIUM | 5.9 | 31%ile | Microsoft | 2025-07-08 |
| CVE-2025-1735 | pgsql extension does not check for errors during escaping | MEDIUM | 5.9 | 58%ile | Microsoft | 2025-07-08 |
| CVE-2025-38208 | smb: client: add NULL check in automount_fullpath | MEDIUM | 5.9 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-48823 | Windows Cryptographic Services Information Disclosure Vulnerability | MEDIUM | 5.9 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-38158 | hisi_acc_vfio_pci: fix XQE dma address error | MEDIUM | 5.7 | 1%ile | Microsoft | 2025-07-08 |
| CVE-2025-48002 | Windows Hyper-V Information Disclosure Vulnerability | MEDIUM | 5.7 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-49722 | Windows Print Spooler Denial of Service Vulnerability | MEDIUM | 5.7 | 40%ile | Microsoft | 2025-07-08 |
| CVE-2024-36357 | AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue | MEDIUM | 5.6 | 23%ile | Microsoft | 2025-07-08 |
| CVE-2024-36350 | AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue | MEDIUM | 5.6 | 36%ile | Microsoft | 2025-07-08 |
| CVE-2025-38333 | f2fs: fix to bail out in get_new_segment() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-50085 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 5.5 | 35%ile | Microsoft | 2025-07-08 |
| CVE-2025-38102 | VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38117 | Bluetooth: MGMT: Protect mgmt_pending list with its own lock | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38142 | hwmon: (asus-ec-sensors) check sensor index in read_string() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38148 | net: phy: mscc: Fix memory leak when using one step timestamping | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38163 | f2fs: fix to do sanity check on sbi->total_valid_block_count | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38167 | fs/ntfs3: handle hdr_first_de() return value | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38174 | thunderbolt: Do not double dequeue a configuration request | MEDIUM | 5.5 | 14%ile | Microsoft | 2025-07-08 |
| CVE-2025-38173 | crypto: marvell/cesa - Handle zero-length skcipher requests | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38202 | bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38215 | fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38218 | f2fs: fix to do sanity check on sit_bitmap_size | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38222 | ext4: inline: fix len overflow in ext4_prepare_inline_data | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38226 | media: vivid: Change the siize of the composing | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38251 | atm: clip: prevent NULL deref in clip_push() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38262 | tty: serial: uartlite: register uart driver in init | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38263 | bcache: fix NULL pointer in cache_set_flush() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38304 | Bluetooth: Fix NULL pointer deference on eir_get_service_data | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38305 | ptp: remove ptp->n_vclocks check logic in ptp_vclock_in_use() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38319 | drm/amd/pp: Fix potential NULL pointer dereference in atomctrl_initialize_mc_reg_table | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38326 | aoe: clean device rq_list in aoedev_downdev() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38336 | ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330 | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38342 | software node: Correct a OOB check in software_node_get_reference_args() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38354 | drm/msm/gpu: Fix crash when throttling GPU immediately during boot | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38368 | misc: tps6594-pfsm: Add NULL pointer check in tps6594_pfsm_probe() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38419 | remoteproc: core: Cleanup acquired resources when rproc_handle_resources() fails in rproc_attach() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38199 | wifi: ath12k: Fix memory leak due to multiple rx_stats allocation | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38393 | NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN | MEDIUM | 5.5 | 25%ile | Microsoft | 2025-07-08 |
| CVE-2025-38396 | fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38203 | jfs: Fix null-ptr-deref in jfs_ioc_trim | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38234 | sched/rt: Fix race in push_rt_task | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38426 | drm/amdgpu: Add basic validation for RAS header | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38385 | net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38384 | mtd: spinand: fix memory leak of ECC engine conf | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38207 | mm: fix uprobe pte be overwritten when expanding vma | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38359 | s390/mm: Fix in_atomic() handling in do_secure_storage_access() | MEDIUM | 5.5 | 1%ile | Microsoft | 2025-07-08 |
| CVE-2025-38364 | maple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38411 | netfs: Fix double put of request | MEDIUM | 5.5 | 25%ile | Microsoft | 2025-07-08 |
| CVE-2025-38246 | bnxt: properly flush XDP redirect lists | MEDIUM | 5.5 | 21%ile | Microsoft | 2025-07-08 |
| CVE-2025-38353 | drm/xe: Fix taking invalid lock on wedge | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-07-08 |
| CVE-2025-38460 | atm: clip: Fix potential null-ptr-deref in to_atmarpd(). | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38406 | wifi: ath6kl: remove WARN on bad firmware input | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38261 | riscv: save the SR_SUM status over switches | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38480 | comedi: Fix use of uninitialized data in insn_rw_emulate_bits() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38481 | comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38470 | net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38487 | soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38132 | coresight: holding cscfg_csdev_lock while removing cscfg from csdev | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-8224 | GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference | MEDIUM | 5.5 | 13%ile | Microsoft | 2025-07-08 |
| CVE-2025-38269 | btrfs: exit after state insertion failure at btrfs_convert_extent_bit() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38272 | net: dsa: b53: do not enable EEE on bcm63xx | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38351 | KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38189 | drm/v3d: Avoid NULL pointer dereference in `v3d_job_update_stats()` | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38164 | f2fs: zone: fix to avoid inconsistence in between SIT and SSA | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38092 | ksmbd: use list_first_entry_or_null for opinfo_get_list() | MEDIUM | 5.5 | 20%ile | Microsoft | 2025-07-08 |
| CVE-2025-38097 | espintcp: remove encap socket caching to avoid reference leak | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38103 | HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38109 | net/mlx5: Fix ECVF vports unload on shutdown flow | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38115 | net_sched: sch_sfq: fix a potential crash on gso_skb handling | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38119 | scsi: core: ufs: Fix a hang in the error handler | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38122 | gve: add missing NULL check for gve_alloc_pending_packet() in TX DQO | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38123 | net: wwan: t7xx: Fix napi rx poll issue | MEDIUM | 5.5 | 32%ile | Microsoft | 2025-07-08 |
| CVE-2025-38135 | serial: Fix potential null-ptr-deref in mlb_usio_probe() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38136 | usb: renesas_usbhs: Reorder clock handling and power management in probe | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38143 | backlight: pm8941: Add NULL check in wled_configure() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38145 | soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38153 | net: usb: aqc111: fix error handling of usbnet read calls | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38165 | bpf, sockmap: Fix panic when calling skb_linearize | MEDIUM | 5.5 | 22%ile | Microsoft | 2025-07-08 |
| CVE-2025-38166 | bpf: fix ktls panic with sockmap | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38185 | atm: atmtcp: Free invalid length skb in atmtcp_c_send(). | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38190 | atm: Revert atm_account_tx() if copy_from_iter_full() fails. | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38191 | ksmbd: fix null pointer dereference in destroy_previous_session | MEDIUM | 5.5 | 63%ile | Microsoft | 2025-07-08 |
| CVE-2025-38211 | RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction | MEDIUM | 5.5 | 27%ile | Microsoft | 2025-07-08 |
| CVE-2025-38213 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | MEDIUM | 5.5 | — | Microsoft | 2025-07-08 |
| CVE-2025-38217 | hwmon: (ftsteutates) Fix TOCTOU race in fts_read() | MEDIUM | 5.5 | 1%ile | Microsoft | 2025-07-08 |
| CVE-2025-38219 | f2fs: prevent kernel warning due to negative i_nlink from corrupted image | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38225 | media: imx-jpeg: Cleanup after an allocation error | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38227 | media: vidtv: Terminating the subsequent process of initialization failure | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38258 | mm/damon/sysfs-schemes: free old damon_sysfs_scheme_filter->memcg_path on write | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38260 | btrfs: handle csum tree error with rescue=ibadroots correctly | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38265 | serial: jsm: fix NPE during jsm_uart_port_init | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38274 | fpga: fix potential null pointer deref in fpga_mgr_test_img_load_sgt() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38275 | phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38280 | bpf: Avoid __bpf_prog_ret0_warn when jit fails | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38300 | crypto: sun8i-ce-cipher - fix error handling in sun8i_ce_cipher_prepare() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38307 | ASoC: Intel: avs: Verify content returned by parse_int_array() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38320 | arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38321 | smb: Log an error when close_all_cached_dirs fails | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38331 | net: ethernet: cortina: Use TOE/TSO on all TCP | MEDIUM | 5.5 | 23%ile | Microsoft | 2025-07-08 |
| CVE-2025-38334 | x86/sgx: Prevent attempts to reclaim poisoned pages | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38343 | wifi: mt76: mt7996: drop fragments with multicast or broadcast RA | MEDIUM | 5.5 | 12%ile | Microsoft | 2025-07-08 |
| CVE-2025-38345 | ACPICA: fix acpi operand cache leak in dswstate.c | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38346 | ftrace: Fix UAF when lookup kallsym after ftrace disabled | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38347 | f2fs: fix to do sanity check on ino and xnid | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38348 | wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38362 | drm/amd/display: Add null pointer check for get_first_active_display() | MEDIUM | 5.5 | 1%ile | Microsoft | 2025-07-08 |
| CVE-2025-38365 | btrfs: fix a race between renames and directory logging | MEDIUM | 5.5 | 21%ile | Microsoft | 2025-07-08 |
| CVE-2025-38416 | NFC: nci: uart: Set tty->disc_data only in success path | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38418 | remoteproc: core: Release rproc->clean_table after rproc_attach() fails | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38467 | drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38098 | drm/amd/display: Don't treat wb connector as physical in create_validate_stream_for_sink | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38335 | Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-07-08 |
| CVE-2025-38474 | usb: net: sierra: check for no status endpoint | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38389 | drm/i915/gt: Fix timeline left held on VMA alloc error | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38404 | usb: typec: displayport: Fix potential deadlock | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38391 | usb: typec: altmodes/displayport: do not index invalid pin_assignments | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38444 | raid10: cleanup memleak at raid10_make_request | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38376 | usb: chipidea: udc: disconnect/reconnect from host when do suspend/resume | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38387 | RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38095 | dma-buf: insert memory barrier before updating num_fences | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38371 | drm/v3d: Disable interrupts before resetting the GPU | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38177 | sch_hfsc: make hfsc_qlen_notify() idempotent | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38441 | netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38473 | Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38400 | nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails. | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-26636 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 34%ile | Microsoft | 2025-07-08 |
| CVE-2025-49658 | Windows Transport Driver Interface (TDI) Translation Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 37%ile | Microsoft | 2025-07-08 |
| CVE-2025-48812 | Microsoft Excel Information Disclosure Vulnerability | MEDIUM | 5.5 | 41%ile | Microsoft | 2025-07-08 |
| CVE-2025-48808 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 40%ile | Microsoft | 2025-07-08 |
| CVE-2025-48809 | Windows Secure Kernel Mode Information Disclosure Vulnerability | MEDIUM | 5.5 | 36%ile | Microsoft | 2025-07-08 |
| CVE-2025-48810 | Windows Secure Kernel Mode Information Disclosure Vulnerability | MEDIUM | 5.5 | 37%ile | Microsoft | 2025-07-08 |
| CVE-2025-49664 | Windows User-Mode Driver Framework Host Information Disclosure Vulnerability | MEDIUM | 5.5 | 42%ile | Microsoft | 2025-07-08 |
| CVE-2025-49684 | Windows Storage Port Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 36%ile | Microsoft | 2025-07-08 |
| CVE-2025-32989 | Gnutls: vulnerability in gnutls sct extension parsing | MEDIUM | 5.3 | 65%ile | Microsoft | 2025-07-08 |
| CVE-2025-38110 | net/mdiobus: Fix potential out-of-bounds clause 45 read/write access | MEDIUM | 5.3 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-7545 | GNU Binutils objcopy.c copy_section heap-based overflow | MEDIUM | 5.3 | 18%ile | Microsoft | 2025-07-08 |
| CVE-2025-8177 | LibTIFF thumbnail.c setrow buffer overflow | MEDIUM | 5.3 | 19%ile | Microsoft | 2025-07-08 |
| CVE-2025-54126 | WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified | MEDIUM | 5.3 | 46%ile | Microsoft | 2025-07-08 |
| CVE-2025-7546 | GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds write | MEDIUM | 5.3 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-8176 | LibTIFF tiffmedian.c get_histogram use after free | MEDIUM | 5.3 | 15%ile | Microsoft | 2025-07-08 |
| CVE-2025-5987 | Libssh: invalid return code for chacha20 poly1305 with openssl backend | MEDIUM | 5.0 | 71%ile | Microsoft | 2025-07-08 |
| CVE-2025-5372 | Libssh: incorrect return code handling in ssh_kdf() in libssh | MEDIUM | 5.0 | 34%ile | Microsoft | 2025-07-08 |
| CVE-2025-50080 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-50084 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 41%ile | Microsoft | 2025-07-08 |
| CVE-2025-50092 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-50093 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 43%ile | Microsoft | 2025-07-08 |
| CVE-2025-50099 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-50102 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-50091 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 44%ile | Microsoft | 2025-07-08 |
| CVE-2023-52971 | MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan. | MEDIUM | 4.9 | 39%ile | Microsoft | 2025-07-08 |
| CVE-2025-50077 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 44%ile | Microsoft | 2025-07-08 |
| CVE-2025-50079 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 44%ile | Microsoft | 2025-07-08 |
| CVE-2025-50086 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 41%ile | Microsoft | 2025-07-08 |
| CVE-2025-50087 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 35%ile | Microsoft | 2025-07-08 |
| CVE-2025-50094 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 39%ile | Microsoft | 2025-07-08 |
| CVE-2025-50097 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions | MEDIUM | 4.9 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-50101 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.9 | 38%ile | Microsoft | 2025-07-08 |
| CVE-2025-53023 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). | MEDIUM | 4.9 | 39%ile | Microsoft | 2025-07-08 |
| CVE-2025-38232 | NFSD: fix race between nfsd registration and exports_proc | MEDIUM | 4.7 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38382 | btrfs: fix iteration of extrefs during log replay | MEDIUM | 4.7 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-8114 | : null pointer dereference in libssh kex session id calculation | MEDIUM | 4.7 | 12%ile | Microsoft | 2025-07-08 |
| CVE-2025-38496 | dm-bufio: fix sched in atomic context | MEDIUM | 4.7 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38112 | net: Fix TOCTOU issue in sk_is_readable() | MEDIUM | 4.7 | 2%ile | Microsoft | 2025-07-08 |
| CVE-2023-53159 | The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_ho | MEDIUM | 4.5 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-38155 | wifi: mt76: mt7915: Fix null-ptr-deref in mt7915_mmio_wed_init() | MEDIUM | 4.4 | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38498 | do_change_type(): refuse to operate on unmounted/not ours mounts | MEDIUM | 4.4 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-50096 | Vulnerability in the MySQL Server product of Oracle MySQL | MEDIUM | 4.4 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38303 | Bluetooth: eir: Fix possible crashes on eir_create_adv_data | MEDIUM | 4.4 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38279 | bpf: Do not include stack ptr register in precision backtracking bookkeeping | MEDIUM | 4.4 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38138 | dmaengine: ti: Add NULL check in udma_probe() | MEDIUM | 4.4 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38161 | RDMA/mlx5: Fix error flow upon firmware failure for RQ destruction | MEDIUM | 4.4 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-8225 | GNU Binutils DWARF Section dwarf.c process_debug_info memory leak | MEDIUM | 4.4 | 13%ile | Microsoft | 2025-07-08 |
| CVE-2025-54567 | hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327. | MEDIUM | 4.2 | 15%ile | Microsoft | 2025-07-08 |
| CVE-2025-5351 | Libssh: double free vulnerability in libssh key export functions | MEDIUM | 4.2 | 40%ile | Microsoft | 2025-07-08 |
| CVE-2025-54566 | hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327. | MEDIUM | 4.2 | 15%ile | Microsoft | 2025-07-08 |
| CVE-2025-38108 | net_sched: red: fix a race in __red_change() | MEDIUM | 4.1 | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38113 | ACPI: CPPC: Fix NULL pointer dereference when nosmp is used | MEDIUM | 4.1 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-38127 | ice: fix Tx scheduler error handling in XDP callback | MEDIUM | 4.1 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-53906 | Vim has path traversal issue with zip.vim and special crafted zip archives | MEDIUM | 4.1 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2025-45582 | GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step proc | MEDIUM | 4.1 | 36%ile | Microsoft | 2025-07-08 |
| CVE-2025-38231 | nfsd: Initialize ssc before laundromat_work to prevent NULL dereference | MEDIUM | 4.1 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-53905 | Vim has path traversial issue with tar.vim and special crafted tar files | MEDIUM | 4.1 | 15%ile | Microsoft | 2025-07-08 |
| CVE-2023-53158 | The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IF | MEDIUM | 4.1 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-1220 | Null byte termination in hostnames | LOW | 3.7 | 41%ile | Microsoft | 2025-07-08 |
| CVE-2025-4056 | Glib: glib crash after long command line | LOW | 3.7 | 36%ile | Microsoft | 2025-07-08 |
| CVE-2025-4878 | Libssh: use of uninitialized variable in privatekey_from_file() | LOW | 3.6 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-49760 | Windows Storage Spoofing Vulnerability | LOW | 3.5 | 67%ile | Microsoft | 2025-07-08 |
| CVE-2025-7339 | on-headers vulnerable to http response header manipulation | LOW | 3.4 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2025-38324 | mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). | LOW | 3.3 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-38201 | netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX | LOW | 3.3 | 9%ile | Microsoft | 2025-07-08 |
| CVE-2025-7067 | HDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflow | LOW | 3.3 | 13%ile | Microsoft | 2025-07-08 |
| CVE-2025-7068 | HDF5 H5FL.c H5FL__malloc memory leak | LOW | 3.3 | 10%ile | Microsoft | 2025-07-08 |
| CVE-2025-7207 | mruby nregs codegen.c scope_new heap-based overflow | LOW | 3.3 | 12%ile | Microsoft | 2025-07-08 |
| CVE-2025-38282 | kernfs: Relax constraint in draining guard | LOW | 3.3 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-7069 | HDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow | LOW | 3.3 | 13%ile | Microsoft | 2025-07-08 |
| CVE-2025-49756 | Office Developer Platform Security Feature Bypass Vulnerability | LOW | 3.3 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2024-58266 | The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa | LOW | 3.2 | 52%ile | Microsoft | 2025-07-08 |
| CVE-2025-50081 | Vulnerability in the MySQL Server product of Oracle MySQL | LOW | 3.1 | 16%ile | Microsoft | 2025-07-08 |
| CVE-2025-49731 | Microsoft Teams Elevation of Privilege Vulnerability | LOW | 3.1 | 31%ile | Microsoft | 2025-07-08 |
| CVE-2025-54314 | Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier becau | LOW | 2.8 | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-50098 | Vulnerability in the MySQL Server product of Oracle MySQL | LOW | 2.7 | 35%ile | Microsoft | 2025-07-08 |
| CVE-2025-50104 | Vulnerability in the MySQL Server product of Oracle MySQL | LOW | 2.7 | 35%ile | Microsoft | 2025-07-08 |
| CVE-2025-50100 | Vulnerability in the MySQL Server product of Oracle MySQL | LOW | 2.2 | 28%ile | Microsoft | 2025-07-08 |
| CVE-2025-38239 | scsi: megaraid_sas: Fix invalid node index | UNKNOWN | — | 4%ile | Microsoft | 2025-07-08 |
| CVE-2025-38286 | pinctrl: at91: Fix possible out-of-boundary access | UNKNOWN | — | 8%ile | Microsoft | 2025-07-08 |
| CVE-2025-5994 | Cache poisoning via the ECS-enabled Rebirthday Attack | UNKNOWN | — | 9%ile | Microsoft | 2025-07-08 |
| CVE-2025-7394 | In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to | UNKNOWN | — | 31%ile | Microsoft | 2025-07-08 |
| CVE-2025-8058 | The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocat | UNKNOWN | — | 5%ile | Microsoft | 2025-07-08 |
| CVE-2025-38205 | drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 | UNKNOWN | — | 3%ile | Microsoft | 2025-07-08 |
| CVE-2025-38293 | wifi: ath11k: fix node corruption in ar->arvifs list | UNKNOWN | — | 18%ile | Microsoft | 2025-07-08 |
| CVE-2025-50076 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte | UNKNOWN | — | 42%ile | Microsoft | 2025-07-08 |
| CVE-2025-38292 | wifi: ath12k: fix invalid access to memory | UNKNOWN | — | 12%ile | Microsoft | 2025-07-08 |
| CVE-2025-7395 | Domain Name Validation Bypass with Apple Native Certificate Validation | UNKNOWN | — | 13%ile | Microsoft | 2025-07-08 |
| CVE-2025-7783 | Usage of unsafe random function in form-data for choosing boundary | UNKNOWN | — | 75%ile | Microsoft | 2025-07-08 |
| CVE-2025-27613 | GitHub: CVE-2025-27613 Gitk Arguments Vulnerability | UNKNOWN | — | 21%ile | Microsoft | 2025-07-08 |
| CVE-2025-27614 | GitHub: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability | UNKNOWN | — | 24%ile | Microsoft | 2025-07-08 |
| CVE-2025-46334 | GitHub: CVE-2025-46334 Git Malicious Shell Vulnerability | UNKNOWN | — | 18%ile | Microsoft | 2025-07-08 |
| CVE-2025-46835 | GitHub: CVE-2025-46835 Git File Overwrite Vulnerability | UNKNOWN | — | 22%ile | Microsoft | 2025-07-08 |
| CVE-2025-48384 | GitHub: CVE-2025-48384 Git Symlink Vulnerability | UNKNOWN | — | 85%ile | Microsoft | 2025-07-08 |
| CVE-2025-48385 | GitHub: CVE-2025-48385 Git Protocol Injection Vulnerability | UNKNOWN | — | 56%ile | Microsoft | 2025-07-08 |
| CVE-2025-48386 | GitHub: CVE-2025-48386 Git Credential Helper Vulnerability | UNKNOWN | — | 25%ile | Microsoft | 2025-07-08 |
| CVE-2025-6554 | Chromium: CVE-2025-6554 Type Confusion in V8 | UNKNOWN | — | 95%ile | Microsoft | 2025-07-08 |
| CVE-2025-7657 | Chromium: CVE-2025-7657 Use after free in WebRTC | UNKNOWN | — | 40%ile | Microsoft | 2025-07-08 |
| CVE-2025-6558 | Chromium: CVE-2025-6558 Incorrect validation of untrusted input in ANGLE and GPU | UNKNOWN | — | 95%ile | Microsoft | 2025-07-08 |
| CVE-2025-7656 | Chromium: CVE-2025-7656 Integer overflow in V8 | UNKNOWN | — | 95%ile | Microsoft | 2025-07-08 |
| CVE-2025-8011 | Chromium: CVE-2025-8011 Type Confusion in V8 | UNKNOWN | — | 16%ile | Microsoft | 2025-07-08 |
| CVE-2025-8010 | Chromium: CVE-2025-8010 Type Confusion in V8 | UNKNOWN | — | 16%ile | Microsoft | 2025-07-08 |
| CVE-2025-8292 | Chromium: CVE-2025-8292 Use after free in Media Stream | UNKNOWN | — | 24%ile | Microsoft | 2025-07-08 |
| CVE-2025-29813 | Azure DevOps Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 73%ile | Microsoft | 2025-05-13 |
| CVE-2025-29972 | Azure Storage Resource Provider Spoofing Vulnerability | CRITICAL | 9.9 | 85%ile | Microsoft | 2025-05-13 |
| CVE-2025-29827 | Azure Automation Elevation of Privilege Vulnerability | CRITICAL | 9.9 | 69%ile | Microsoft | 2025-05-13 |
| CVE-2025-30387 | Document Intelligence Studio On-Prem Elevation of Privilege Vulnerability | CRITICAL | 9.8 | 63%ile | Microsoft | 2025-05-13 |
| CVE-2025-47733 | Microsoft Power Apps Information Disclosure Vulnerability | CRITICAL | 9.1 | 74%ile | Microsoft | 2025-05-13 |
| CVE-2025-47273 | setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write | HIGH | 8.8 | 71%ile | Microsoft | 2025-05-13 |
| CVE-2025-44904 | hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function. | HIGH | 8.8 | 30%ile | Microsoft | 2025-05-13 |
| CVE-2025-47181 | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | HIGH | 8.8 | 40%ile | Microsoft | 2025-05-13 |
| CVE-2025-29964 | Windows Media Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2025-05-13 |
| CVE-2025-29966 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 67%ile | Microsoft | 2025-05-13 |
| CVE-2025-29967 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH | 8.8 | 65%ile | Microsoft | 2025-05-13 |
| CVE-2025-29840 | Windows Media Remote Code Execution Vulnerability | HIGH | 8.8 | 57%ile | Microsoft | 2025-05-13 |
| CVE-2025-29962 | Windows Media Remote Code Execution Vulnerability | HIGH | 8.8 | 95%ile | Microsoft | 2025-05-13 |
| CVE-2025-29963 | Windows Media Remote Code Execution Vulnerability | HIGH | 8.8 | 58%ile | Microsoft | 2025-05-13 |
| CVE-2025-47732 | Microsoft Dataverse Remote Code Execution Vulnerability | HIGH | 8.7 | 87%ile | Microsoft | 2025-05-13 |
| CVE-2025-23150 | ext4: fix off-by-one error in do_split | HIGH | 8.4 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-4802 | Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker c | HIGH | 8.4 | 43%ile | Microsoft | 2025-05-13 |
| CVE-2025-30377 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 44%ile | Microsoft | 2025-05-13 |
| CVE-2025-30386 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 8.4 | 45%ile | Microsoft | 2025-05-13 |
| CVE-2025-32704 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 8.4 | 31%ile | Microsoft | 2025-05-13 |
| CVE-2025-33072 | Microsoft msagsfeedback.azurewebsites.net Information Disclosure Vulnerability | HIGH | 8.1 | 72%ile | Microsoft | 2025-05-13 |
| CVE-2025-37943 | wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi | HIGH | 8.0 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-26646 | .NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability | HIGH | 8.0 | 63%ile | Microsoft | 2025-05-13 |
| CVE-2025-37789 | net: openvswitch: fix nested key length validation in the set() action | HIGH | 7.8 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37923 | tracing: Fix oob write in trace_seq_to_buffer() | HIGH | 7.8 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37924 | ksmbd: fix use-after-free in kerberos authentication | HIGH | 7.8 | 96%ile | Microsoft | 2025-05-13 |
| CVE-2025-37947 | ksmbd: prevent out-of-bounds stream writes by validating *pos | HIGH | 7.8 | 39%ile | Microsoft | 2025-05-13 |
| CVE-2025-37926 | ksmbd: fix use-after-free in ksmbd_session_rpc_open | HIGH | 7.8 | 38%ile | Microsoft | 2025-05-13 |
| CVE-2025-37899 | ksmbd: fix use-after-free in session logoff | HIGH | 7.8 | 57%ile | Microsoft | 2025-05-13 |
| CVE-2025-37777 | ksmbd: fix use-after-free in __smb2_lease_break_noti() | HIGH | 7.8 | 27%ile | Microsoft | 2025-05-13 |
| CVE-2025-37882 | usb: xhci: Fix isochronous Ring Underrun/Overrun event handling | HIGH | 7.8 | 18%ile | Microsoft | 2025-05-13 |
| CVE-2025-37822 | riscv: uprobes: Add missing fence.i after building the XOL buffer | HIGH | 7.8 | 15%ile | Microsoft | 2025-05-13 |
| CVE-2025-37786 | net: dsa: free routing table on probe failure | HIGH | 7.8 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37798 | codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() | HIGH | 7.8 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37803 | udmabuf: fix a buf size overflow issue during udmabuf creation | HIGH | 7.8 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37840 | mtd: rawnand: brcmnand: fix PM resume warning | HIGH | 7.8 | 21%ile | Microsoft | 2025-05-13 |
| CVE-2025-37849 | KVM: arm64: Tear down vGIC on failed vCPU creation | HIGH | 7.8 | 18%ile | Microsoft | 2025-05-13 |
| CVE-2025-37858 | fs/jfs: Prevent integer overflow in AG size calculation | HIGH | 7.8 | 19%ile | Microsoft | 2025-05-13 |
| CVE-2025-37890 | net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc | HIGH | 7.8 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37916 | pds_core: remove write-after-free of client_id | HIGH | 7.8 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37938 | tracing: Verify event formats that have "%*p.." | HIGH | 7.8 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37944 | wifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process | HIGH | 7.8 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-37750 | smb: client: fix UAF in decryption with multichannel | HIGH | 7.8 | 29%ile | Microsoft | 2025-05-13 |
| CVE-2025-37928 | dm-bufio: don't schedule in atomic context | HIGH | 7.8 | 47%ile | Microsoft | 2025-05-13 |
| CVE-2023-53072 | mptcp: use the workqueue to destroy unaccepted sockets | HIGH | 7.8 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-29970 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2025-05-13 |
| CVE-2025-29975 | Microsoft PC Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2025-05-13 |
| CVE-2025-29976 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2025-05-13 |
| CVE-2025-29977 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 45%ile | Microsoft | 2025-05-13 |
| CVE-2025-29978 | Microsoft PowerPoint Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2025-05-13 |
| CVE-2025-29979 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 45%ile | Microsoft | 2025-05-13 |
| CVE-2025-30375 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-05-13 |
| CVE-2025-30376 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2025-05-13 |
| CVE-2025-30379 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2025-05-13 |
| CVE-2025-30381 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2025-05-13 |
| CVE-2025-30382 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.8 | 82%ile | Microsoft | 2025-05-13 |
| CVE-2025-30383 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2025-05-13 |
| CVE-2025-30393 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2025-05-13 |
| CVE-2025-30400 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 76%ile | Microsoft | 2025-05-13 |
| CVE-2025-32701 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 68%ile | Microsoft | 2025-05-13 |
| CVE-2025-32706 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 80%ile | Microsoft | 2025-05-13 |
| CVE-2025-32709 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 74%ile | Microsoft | 2025-05-13 |
| CVE-2025-30385 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2025-05-13 |
| CVE-2025-30388 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2025-05-13 |
| CVE-2025-32702 | Visual Studio Remote Code Execution Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2025-05-13 |
| CVE-2025-32705 | Microsoft Outlook Remote Code Execution Vulnerability | HIGH | 7.8 | 37%ile | Microsoft | 2025-05-13 |
| CVE-2025-32707 | NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2025-05-13 |
| CVE-2025-47161 | Microsoft Defender for Endpoint Elevation of Privilege Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2025-05-13 |
| CVE-2025-24063 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 46%ile | Microsoft | 2025-05-13 |
| CVE-2025-29833 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability | HIGH | 7.7 | 33%ile | Microsoft | 2025-05-13 |
| CVE-2024-47619 | tranport: TLS host name wildcard matching too lax | HIGH | 7.5 | 25%ile | Microsoft | 2025-05-13 |
| CVE-2025-40775 | DNS message with invalid TSIG causes an assertion failure | HIGH | 7.5 | 96%ile | Microsoft | 2025-05-13 |
| CVE-2025-4948 | Libsoup: integer underflow in soup_multipart_new_from_message() leading to denial of service in libsoup | HIGH | 7.5 | 49%ile | Microsoft | 2025-05-13 |
| CVE-2025-23166 | The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executi | HIGH | 7.5 | 52%ile | Microsoft | 2025-05-13 |
| CVE-2025-47291 | containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods. | HIGH | 7.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-48060 | AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt) | HIGH | 7.5 | 37%ile | Microsoft | 2025-05-13 |
| CVE-2025-29969 | MS-EVEN RPC Remote Code Execution Vulnerability | HIGH | 7.5 | 61%ile | Microsoft | 2025-05-13 |
| CVE-2025-29971 | Web Threat Defense (WTD.sys) Denial of Service Vulnerability | HIGH | 7.5 | 99%ile | Microsoft | 2025-05-13 |
| CVE-2025-26677 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2025-05-13 |
| CVE-2025-29831 | Windows Remote Desktop Services Remote Code Execution Vulnerability | HIGH | 7.5 | 57%ile | Microsoft | 2025-05-13 |
| CVE-2025-29842 | UrlMon Security Feature Bypass Vulnerability | HIGH | 7.5 | 33%ile | Microsoft | 2025-05-13 |
| CVE-2025-30397 | Scripting Engine Memory Corruption Vulnerability | HIGH | 7.5 | 97%ile | Microsoft | 2025-05-13 |
| CVE-2025-30384 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.4 | 65%ile | Microsoft | 2025-05-13 |
| CVE-2025-29838 | Windows ExecutionContext Driver Elevation of Privilege Vulnerability | HIGH | 7.4 | 26%ile | Microsoft | 2025-05-13 |
| CVE-2025-44905 | hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function. | HIGH | 7.3 | 32%ile | Microsoft | 2025-05-13 |
| CVE-2025-29826 | Microsoft Dataverse Elevation of Privilege Vulnerability | HIGH | 7.3 | 52%ile | Microsoft | 2025-05-13 |
| CVE-2025-37738 | ext4: ignore xattrs past end | HIGH | 7.1 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37879 | 9p/net: fix improper handling of bogus negative read/write replies | HIGH | 7.1 | 49%ile | Microsoft | 2025-05-13 |
| CVE-2025-21264 | Visual Studio Code Security Feature Bypass Vulnerability | HIGH | 7.1 | 50%ile | Microsoft | 2025-05-13 |
| CVE-2025-37831 | cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate() | HIGH | 7.0 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37892 | mtd: inftlcore: Add error check for inftl_read_oob() | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37936 | perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value. | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37954 | smb: client: Avoid race in open_cached_dir with lease breaks | HIGH | 7.0 | 22%ile | Microsoft | 2025-05-13 |
| CVE-2025-37960 | memblock: Accept allocated memory before use in memblock_double_array() | HIGH | 7.0 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-37963 | arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users | HIGH | 7.0 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37997 | netfilter: ipset: fix region locking in hash types | HIGH | 7.0 | 4%ile | Microsoft | 2025-05-13 |
| CVE-2025-37968 | iio: light: opt3001: fix deadlock due to concurrent flag access | HIGH | 7.0 | 3%ile | Microsoft | 2025-05-13 |
| CVE-2025-37776 | ksmbd: fix use-after-free in smb_break_all_levII_oplock() | HIGH | 7.0 | 25%ile | Microsoft | 2025-05-13 |
| CVE-2025-37780 | isofs: Prevent the use of too small fid | HIGH | 7.0 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37797 | net_sched: hfsc: Fix a UAF vulnerability in class handling | HIGH | 7.0 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37897 | wifi: plfxlc: Remove erroneous assert in plfxlc_mac_release | HIGH | 7.0 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37903 | drm/amd/display: Fix slab-use-after-free in hdcp | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37911 | bnxt_en: Fix out-of-bound memcpy() during ethtool -w | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37914 | net_sched: ets: Fix double list add in class with netem as child qdisc | HIGH | 7.0 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37921 | vxlan: vnifilter: Fix unlocked deletion of default FDB entry | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37940 | ftrace: Add cond_resched() to ftrace_graph_set_hash() | HIGH | 7.0 | 3%ile | Microsoft | 2025-05-13 |
| CVE-2025-37948 | arm64: bpf: Add BHB mitigation to the epilogue for cBPF programs | HIGH | 7.0 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37951 | drm/v3d: Add job to pending list if the reset was skipped | HIGH | 7.0 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-37952 | ksmbd: Fix UAF in __close_file_table_ids | HIGH | 7.0 | 23%ile | Microsoft | 2025-05-13 |
| CVE-2025-37958 | mm/huge_memory: fix dereferencing invalid pmd migration entry | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37969 | iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo | HIGH | 7.0 | 3%ile | Microsoft | 2025-05-13 |
| CVE-2025-37982 | wifi: wl1251: fix memory leak in wl1251_tx_work | HIGH | 7.0 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37987 | pds_core: Prevent possible adminq overflow/stuck condition | HIGH | 7.0 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-37988 | fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount() | HIGH | 7.0 | 2%ile | Microsoft | 2025-05-13 |
| CVE-2025-37994 | usb: typec: ucsi: displayport: Fix NULL pointer access | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37995 | module: ensure that kobject_put() is safe for module type kobjects | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-5222 | Icu: stack buffer overflow in the srbroot::addtag function | HIGH | 7.0 | 24%ile | Microsoft | 2025-05-13 |
| CVE-2025-37807 | bpf: Fix kmemleak warning for percpu hashmap | HIGH | 7.0 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37977 | scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set | HIGH | 7.0 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37976 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | HIGH | 7.0 | — | Microsoft | 2025-05-13 |
| CVE-2025-29973 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2025-05-13 |
| CVE-2025-30378 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.0 | 66%ile | Microsoft | 2025-05-13 |
| CVE-2025-27468 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 13%ile | Microsoft | 2025-05-13 |
| CVE-2025-29841 | Universal Print Management Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 27%ile | Microsoft | 2025-05-13 |
| CVE-2025-37973 | wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation | MEDIUM | 6.7 | 13%ile | Microsoft | 2025-05-13 |
| CVE-2025-37922 | book3s64/radix : Align section vmemmap start address to PAGE_SIZE | MEDIUM | 6.7 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-26684 | Microsoft Defender Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 32%ile | Microsoft | 2025-05-13 |
| CVE-2025-27488 | Microsoft Windows Hardware Lab Kit (HLK) Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 29%ile | Microsoft | 2025-05-13 |
| CVE-2025-46836 | net-tools Stack-based Buffer Overflow vulnerability | MEDIUM | 6.6 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37961 | ipvs: fix uninit-value for saddr in do_output_route4 | MEDIUM | 6.5 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-4969 | Libsoup: off-by-one out-of-bounds read in find_boundary() in soup-multipart.c | MEDIUM | 6.5 | 52%ile | Microsoft | 2025-05-13 |
| CVE-2025-4575 | The x509 application adds trusted use instead of rejected use | MEDIUM | 6.5 | 24%ile | Microsoft | 2025-05-13 |
| CVE-2025-23167 | A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required | MEDIUM | 6.5 | 38%ile | Microsoft | 2025-05-13 |
| CVE-2025-47268 | ping in iputils before 20250602 allows a denial of service | MEDIUM | 6.5 | 72%ile | Microsoft | 2025-05-13 |
| CVE-2025-4947 | QUIC certificate check skip with wolfSSL | MEDIUM | 6.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-37984 | crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() | MEDIUM | 6.5 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-4373 | Glib: buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar | MEDIUM | 6.5 | 40%ile | Microsoft | 2025-05-13 |
| CVE-2025-29825 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 6.5 | 53%ile | Microsoft | 2025-05-13 |
| CVE-2025-29959 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 68%ile | Microsoft | 2025-05-13 |
| CVE-2025-29960 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 68%ile | Microsoft | 2025-05-13 |
| CVE-2025-29968 | Active Directory Certificate Services (AD CS) Denial of Service Vulnerability | MEDIUM | 6.5 | 75%ile | Microsoft | 2025-05-13 |
| CVE-2025-26685 | Microsoft Defender for Identity Spoofing Vulnerability | MEDIUM | 6.5 | 48%ile | Microsoft | 2025-05-13 |
| CVE-2025-29830 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 63%ile | Microsoft | 2025-05-13 |
| CVE-2025-29832 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 63%ile | Microsoft | 2025-05-13 |
| CVE-2025-29835 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 6.5 | 63%ile | Microsoft | 2025-05-13 |
| CVE-2025-29836 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 64%ile | Microsoft | 2025-05-13 |
| CVE-2025-29958 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2025-05-13 |
| CVE-2025-29961 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2025-05-13 |
| CVE-2025-37915 | net_sched: drr: Fix double list add in class with netem as child qdisc | MEDIUM | 6.3 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37913 | net_sched: qfq: Fix double list add in class with netem as child qdisc | MEDIUM | 6.3 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37861 | scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue | MEDIUM | 6.3 | 20%ile | Microsoft | 2025-05-13 |
| CVE-2025-29955 | Windows Hyper-V Denial of Service Vulnerability | MEDIUM | 6.2 | 39%ile | Microsoft | 2025-05-13 |
| CVE-2025-29957 | Windows Deployment Services Denial of Service Vulnerability | MEDIUM | 6.2 | 42%ile | Microsoft | 2025-05-13 |
| CVE-2025-23141 | KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses | MEDIUM | 6.1 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37749 | net: ppp: Add bound checking for skb data on ppp_sync_txmung | MEDIUM | 6.1 | 30%ile | Microsoft | 2025-05-13 |
| CVE-2025-37757 | tipc: fix memory leak in tipc_link_xmit | MEDIUM | 6.1 | 34%ile | Microsoft | 2025-05-13 |
| CVE-2025-22247 | Insecure file handling vulnerability | MEDIUM | 6.1 | 17%ile | Microsoft | 2025-05-13 |
| CVE-2025-4207 | PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation | MEDIUM | 5.9 | 49%ile | Microsoft | 2025-05-13 |
| CVE-2025-40909 | Perl threads have a working directory race condition where file operations may target unintended paths | MEDIUM | 5.9 | 30%ile | Microsoft | 2025-05-13 |
| CVE-2025-30394 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | MEDIUM | 5.9 | 98%ile | Microsoft | 2025-05-13 |
| CVE-2025-29954 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | MEDIUM | 5.9 | 66%ile | Microsoft | 2025-05-13 |
| CVE-2025-29974 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.7 | 46%ile | Microsoft | 2025-05-13 |
| CVE-2025-37933 | octeon_ep: Fix host hang issue during device reboot | MEDIUM | 5.6 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-23144 | backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() | MEDIUM | 5.5 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-23145 | mptcp: fix NULL pointer in can_accept_new_subflow | MEDIUM | 5.5 | 42%ile | Microsoft | 2025-05-13 |
| CVE-2025-23156 | media: venus: hfi_parser: refactor hfi packet parsing logic | MEDIUM | 5.5 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-23163 | net: vlan: don't propagate flags on open | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-05-13 |
| CVE-2025-37740 | jfs: add sanity check for agwidth in dbMount | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37741 | jfs: Prevent copying of nlink with value 0 from disk inode | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-37755 | net: libwx: handle page_pool_dev_alloc_pages error | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37765 | drm/nouveau: prime: fix ttm_bo_delayed_delete oops | MEDIUM | 5.5 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-37767 | drm/amd/pm: Prevent division by zero | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37772 | RDMA/cma: Fix workqueue crash in cma_netevent_work_handler | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37773 | virtiofs: add filesystem context source name check | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37778 | ksmbd: Fix dangling pointer in krb_authenticate | MEDIUM | 5.5 | 40%ile | Microsoft | 2025-05-13 |
| CVE-2025-37781 | i2c: cros-ec-tunnel: defer probe if parent EC is not present | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37787 | net: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37794 | wifi: mac80211: Purge vif txq in ieee80211_do_stop() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37801 | spi: spi-imx: Add check for spi_imx_setupxfer() | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37808 | crypto: null - Use spin lock instead of mutex | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37810 | usb: dwc3: gadget: check that event count does not exceed event buffer length | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37819 | irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37823 | net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37830 | cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37839 | jbd2: remove wrong sb->s_sequence check | MEDIUM | 5.5 | 21%ile | Microsoft | 2025-05-13 |
| CVE-2025-37841 | pm: cpupower: bench: Prevent NULL dereference on malloc failure | MEDIUM | 5.5 | 17%ile | Microsoft | 2025-05-13 |
| CVE-2025-37851 | fbdev: omapfb: Add 'plane' value check | MEDIUM | 5.5 | 17%ile | Microsoft | 2025-05-13 |
| CVE-2025-37853 | drm/amdkfd: debugfs hang_hws skip GPU with MES | MEDIUM | 5.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-37864 | net: dsa: clean up FDB, MDB, VLAN entries on unbind | MEDIUM | 5.5 | 17%ile | Microsoft | 2025-05-13 |
| CVE-2025-37862 | HID: pidff: Fix null pointer dereference in pidff_find_fields | MEDIUM | 5.5 | 19%ile | Microsoft | 2025-05-13 |
| CVE-2025-37875 | igc: fix PTM cycle trigger logic | MEDIUM | 5.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-37884 | bpf: Fix deadlock between rcu_tasks_trace and event_mutex. | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37885 | KVM: x86: Reset IRTE to host control if *new* route isn't postable | MEDIUM | 5.5 | 20%ile | Microsoft | 2025-05-13 |
| CVE-2025-37909 | net: lan743x: Fix memleak issue when GSO enabled | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37956 | ksmbd: prevent rename with empty string | MEDIUM | 5.5 | 24%ile | Microsoft | 2025-05-13 |
| CVE-2025-37992 | net_sched: Flush gso_skb list too during ->change() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37942 | HID: pidff: Make sure to fetch pool before checking SIMULTANEOUS_MAX | MEDIUM | 5.5 | — | Microsoft | 2025-05-13 |
| CVE-2025-37743 | wifi: ath12k: Avoid memory leak while enabling statistics | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-05-13 |
| CVE-2025-37834 | mm/vmscan: don't try to reclaim hwpoison folio | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37759 | ublk: fix handling recovery & reissue in ublk_abort_queue() | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37855 | drm/amd/display: Guard Possible Null Pointer Dereference | MEDIUM | 5.5 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-37870 | drm/amd/display: prevent hang on link training fail | MEDIUM | 5.5 | 15%ile | Microsoft | 2025-05-13 |
| CVE-2025-37920 | xsk: Fix race condition in AF_XDP generic RX path | MEDIUM | 5.5 | 3%ile | Microsoft | 2025-05-13 |
| CVE-2025-23155 | net: stmmac: Fix accessing freed irq affinity_hint | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2022-49901 | blk-mq: Fix kmemleak in blk_mq_init_allocated_queue | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37877 | iommu: Clear iommu-dma ops on cleanup | MEDIUM | 5.5 | 15%ile | Microsoft | 2025-05-13 |
| CVE-2025-37826 | scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37880 | um: work around sched_yield not yielding in time-travel mode | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-37931 | btrfs: adjust subpage bit start based on sectorsize | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37745 | PM: hibernate: Avoid deadlock in hibernate_compressor_param_set() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-05-13 |
| CVE-2025-37806 | fs/ntfs3: Keep write operations atomic | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37856 | btrfs: harden block_group::bg_list against list_del() races | MEDIUM | 5.5 | 18%ile | Microsoft | 2025-05-13 |
| CVE-2025-37833 | net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37842 | spi: fsl-qspi: use devm function instead of driver remove | MEDIUM | 5.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2022-49764 | bpf: Prevent bpf program recursion for raw tracepoint probes | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2022-49803 | netdevsim: Fix memory leak of nsim_dev->fa_cookie | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2022-49810 | netfs: Fix missing xas_retry() calls in xarray iteration | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2023-53068 | net: usb: lan78xx: Limit packet length to skb->len | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37945 | net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2024-58098 | bpf: track changes_pkt_data property for global functions | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2024-58100 | bpf: check changes_pkt_data property for extension programs | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2024-58237 | bpf: consider that tail calls invalidate packet pointers | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-23140 | misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error | MEDIUM | 5.5 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-23142 | sctp: detect and prevent references to a freed transport in sendmsg | MEDIUM | 5.5 | 12%ile | Microsoft | 2025-05-13 |
| CVE-2025-23146 | mfd: ene-kb3930: Fix a potential NULL pointer dereference | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-23147 | i3c: Add NULL pointer check in i3c_master_queue_ibi() | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-23148 | soc: samsung: exynos-chipid: Add NULL pointer check in exynos_chipid_probe() | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-23157 | media: venus: hfi_parser: add check to avoid out of bound access | MEDIUM | 5.5 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-23158 | media: venus: hfi: add check to handle incorrect queue size | MEDIUM | 5.5 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-23159 | media: venus: hfi: add a check to handle OOB in sfr region | MEDIUM | 5.5 | 12%ile | Microsoft | 2025-05-13 |
| CVE-2025-37739 | f2fs: fix to avoid out-of-bounds access in f2fs_truncate_inode_blocks() | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37742 | jfs: Fix uninit-value access of imap allocated in the diMount() function | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37754 | drm/i915/huc: Fix fence not released on early probe errors | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37766 | drm/amd/pm: Prevent division by zero | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37768 | drm/amd/pm: Prevent division by zero | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37769 | drm/amd/pm/smu11: Prevent division by zero | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37770 | drm/amd/pm: Prevent division by zero | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37771 | drm/amd/pm: Prevent division by zero | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37775 | ksmbd: fix the warning from __kernel_write_iter | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37790 | net: mctp: Set SOCK_RCU_FREE | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37792 | Bluetooth: btrtl: Prevent potential NULL dereference | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37796 | wifi: at76c50x: fix use after free access in at76_disconnect | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37800 | driver core: fix potential NULL pointer dereference in dev_uevent() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37805 | sound/virtio: Fix cancel_sync warnings on uninitialized work_structs | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37812 | usb: cdns3: Fix deadlock when using NCM gadget | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-05-13 |
| CVE-2025-37817 | mcb: fix a double free bug in chameleon_parse_gdd() | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-37818 | LoongArch: Return NULL from huge_pte_offset() for invalid PMD | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37824 | tipc: fix NULL pointer dereference in tipc_mon_reinit_self() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37828 | scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort() | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37829 | cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate() | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37836 | PCI: Fix reference leak in pci_register_host_bridge() | MEDIUM | 5.5 | 19%ile | Microsoft | 2025-05-13 |
| CVE-2025-37844 | cifs: avoid NULL pointer dereference in dbg call | MEDIUM | 5.5 | 17%ile | Microsoft | 2025-05-13 |
| CVE-2025-37852 | drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() | MEDIUM | 5.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-37854 | drm/amdkfd: Fix mode1 reset crash issue | MEDIUM | 5.5 | 17%ile | Microsoft | 2025-05-13 |
| CVE-2025-37857 | scsi: st: Fix array overflow in st_setup() | MEDIUM | 5.5 | 19%ile | Microsoft | 2025-05-13 |
| CVE-2025-37859 | page_pool: avoid infinite loop to schedule delayed worker | MEDIUM | 5.5 | 19%ile | Microsoft | 2025-05-13 |
| CVE-2025-37865 | net: dsa: mv88e6xxx: fix -ENOENT when deleting VLANs and MST is unsupported | MEDIUM | 5.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-37867 | RDMA/core: Silence oversized kvmalloc() warning | MEDIUM | 5.5 | 18%ile | Microsoft | 2025-05-13 |
| CVE-2025-37874 | net: ngbe: fix memory leak in ngbe_probe() error path | MEDIUM | 5.5 | 20%ile | Microsoft | 2025-05-13 |
| CVE-2025-37878 | perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init | MEDIUM | 5.5 | 15%ile | Microsoft | 2025-05-13 |
| CVE-2025-37883 | s390/sclp: Add check for get_zeroed_page() | MEDIUM | 5.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-37886 | pds_core: make wait_context part of q_info | MEDIUM | 5.5 | 18%ile | Microsoft | 2025-05-13 |
| CVE-2025-37887 | pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result | MEDIUM | 5.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-37891 | ALSA: ump: Fix buffer overflow at UMP SysEx message conversion | MEDIUM | 5.5 | 12%ile | Microsoft | 2025-05-13 |
| CVE-2025-37901 | irqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37927 | iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid | MEDIUM | 5.5 | 11%ile | Microsoft | 2025-05-13 |
| CVE-2025-37932 | sch_htb: make htb_qlen_notify() idempotent | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37957 | KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-37967 | usb: typec: ucsi: displayport: Fix deadlock | MEDIUM | 5.5 | 2%ile | Microsoft | 2025-05-13 |
| CVE-2025-37972 | Input: mtk-pmic-keys - fix possible null pointer dereference | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-37979 | ASoC: qcom: Fix sc7280 lpass potential buffer overflow | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37980 | block: fix resource leak in blk_register_queue() error path | MEDIUM | 5.5 | 5%ile | Microsoft | 2025-05-13 |
| CVE-2025-37989 | net: phy: leds: fix memory leak | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37802 | ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING" | MEDIUM | 5.5 | 22%ile | Microsoft | 2025-05-13 |
| CVE-2025-37744 | wifi: ath12k: fix memory leak in ath12k_pci_remove() | MEDIUM | 5.5 | 4%ile | Microsoft | 2025-05-13 |
| CVE-2025-37782 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | MEDIUM | 5.5 | — | Microsoft | 2025-05-13 |
| CVE-2025-37804 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | MEDIUM | 5.5 | — | Microsoft | 2025-05-13 |
| CVE-2025-23143 | net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-37747 | perf: Fix hang while freeing sigtrap event | MEDIUM | 5.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2023-53064 | iavf: fix hang on reboot with ice | MEDIUM | 5.5 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2022-49766 | netlink: Bounds-check struct nlmsgerr creation | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2022-49829 | drm/scheduler: fix fence ref counting | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2022-49833 | btrfs: zoned: clone zoned device info when cloning a device | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2022-49858 | octeontx2-pf: Fix SQE threshold checking | MEDIUM | 5.5 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2023-53105 | net/mlx5e: Fix cleanup null-ptr deref on encap lock | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2022-49932 | KVM: VMX: Do _all_ initialization before exposing /dev/kvm to userspace | MEDIUM | 5.5 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2023-53042 | drm/amd/display: Do not set DRR on pipe Commit | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2023-53074 | drm/amdgpu: fix ttm_bo calltrace warning in psp_hw_fini | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2023-53093 | tracing: Do not let histogram values have some modifiers | MEDIUM | 5.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37820 | xen-netfront: handle NULL returned by xdp_convert_buff_to_frame() | MEDIUM | 5.5 | 27%ile | Microsoft | 2025-05-13 |
| CVE-2025-37959 | bpf: Scrub packet on bpf_redirect_peer | MEDIUM | 5.5 | 23%ile | Microsoft | 2025-05-13 |
| CVE-2025-32703 | Visual Studio Information Disclosure Vulnerability | MEDIUM | 5.5 | 35%ile | Microsoft | 2025-05-13 |
| CVE-2025-29829 | Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 38%ile | Microsoft | 2025-05-13 |
| CVE-2025-29837 | Windows Installer Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2025-05-13 |
| CVE-2025-29956 | Windows SMB Information Disclosure Vulnerability | MEDIUM | 5.4 | 56%ile | Microsoft | 2025-05-13 |
| CVE-2025-4432 | Ring: some aes functions may panic when overflow checking is enabled in ring | MEDIUM | 5.3 | 57%ile | Microsoft | 2025-05-13 |
| CVE-2025-5244 | GNU Binutils ld elflink.c elf_gc_sweep memory corruption | MEDIUM | 5.3 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2025-5245 | GNU Binutils objdump debug.c debug_type_samep memory corruption | MEDIUM | 5.3 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2024-22653 | yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at se | MEDIUM | 4.8 | 12%ile | Microsoft | 2025-05-13 |
| CVE-2025-4574 | Crossbeam-channel: crossbeam-channel vulnerable to double free on drop | MEDIUM | 4.8 | 41%ile | Microsoft | 2025-05-13 |
| CVE-2025-5025 | No QUIC certificate pinning with wolfSSL | MEDIUM | 4.8 | 17%ile | Microsoft | 2025-05-13 |
| CVE-2025-37985 | USB: wdm: close race between wdm_open and wdm_wwan_port_stop | MEDIUM | 4.7 | 2%ile | Microsoft | 2025-05-13 |
| CVE-2025-37983 | qibfs: fix _another_ leak | MEDIUM | 4.7 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37907 | accel/ivpu: Fix locking order in ivpu_job_submit | MEDIUM | 4.7 | 2%ile | Microsoft | 2025-05-13 |
| CVE-2025-4598 | Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the result | MEDIUM | 4.7 | 51%ile | Microsoft | 2025-05-13 |
| CVE-2025-27151 | redis-check-aof may lead to stack overflow and potential RCE | MEDIUM | 4.7 | 54%ile | Microsoft | 2025-05-13 |
| CVE-2025-37881 | usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() | MEDIUM | 4.7 | 19%ile | Microsoft | 2025-05-13 |
| CVE-2025-37918 | Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue() | MEDIUM | 4.7 | 14%ile | Microsoft | 2025-05-13 |
| CVE-2025-37970 | iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo | MEDIUM | 4.7 | 3%ile | Microsoft | 2025-05-13 |
| CVE-2025-37990 | wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() | MEDIUM | 4.7 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37998 | openvswitch: Fix unsafe attribute parsing in output_userspace() | MEDIUM | 4.5 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37758 | ata: pata_pxa: Fix potential NULL pointer dereference in pxa_ata_probe() | MEDIUM | 4.4 | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-37793 | ASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe() | MEDIUM | 4.4 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2024-23337 | jq has signed integer overflow in jv.c:jvp_array_write | MEDIUM | 4.3 | 30%ile | Microsoft | 2025-05-13 |
| CVE-2025-4476 | Libsoup: null pointer dereference in libsoup may lead to denial of service | MEDIUM | 4.3 | 26%ile | Microsoft | 2025-05-13 |
| CVE-2023-53037 | scsi: mpi3mr: Bad drive in topology results kernel crash | MEDIUM | 4.1 | 10%ile | Microsoft | 2025-05-13 |
| CVE-2025-29839 | Windows Multiple UNC Provider Driver Information Disclosure Vulnerability | MEDIUM | 4.0 | 36%ile | Microsoft | 2025-05-13 |
| CVE-2025-46712 | Erlang/OTP SSH Has Strict KEX Violations | LOW | 3.7 | 39%ile | Microsoft | 2025-05-13 |
| CVE-2025-23165 | In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path | LOW | 3.7 | 39%ile | Microsoft | 2025-05-13 |
| CVE-2025-23161 | PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type | LOW | 3.3 | 4%ile | Microsoft | 2025-05-13 |
| CVE-2025-37756 | net: tls: explicitly disallow disconnect | LOW | 3.3 | 24%ile | Microsoft | 2025-05-13 |
| CVE-2025-4287 | PyTorch nccl.py torch.cuda.nccl.reduce denial of service | LOW | 3.3 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37788 | cxgb4: fix memory leak in cxgb4_init_ethtool_filters() error path | LOW | 3.3 | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-47279 | undici Denial of Service attack via bad certificate data | LOW | 3.1 | 18%ile | Microsoft | 2025-05-13 |
| CVE-2023-53154 | parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_Pars | LOW | 2.9 | 14%ile | Microsoft | 2025-05-13 |
| CVE-2025-37930 | drm/nouveau: Fix WARN_ON in nouveau_fence_context_kill() | LOW | 2.5 | 7%ile | Microsoft | 2025-05-13 |
| CVE-2025-37905 | firmware: arm_scmi: Balance device refcount when destroying devices | LOW | 2.3 | 6%ile | Microsoft | 2025-05-13 |
| CVE-2025-37795 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | Microsoft | 2025-05-13 |
| CVE-2025-4516 | Use-after-free in "unicode_escape" decoder with error handler | UNKNOWN | — | 8%ile | Microsoft | 2025-05-13 |
| CVE-2025-46569 | OPA server Data API HTTP path injection of Rego | UNKNOWN | — | 34%ile | Microsoft | 2025-05-13 |
| CVE-2025-48938 | Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server | UNKNOWN | — | 38%ile | Microsoft | 2025-05-13 |
| CVE-2025-4050 | Chromium: CVE-2025-4050 Out of bounds memory access in DevTools | UNKNOWN | — | 38%ile | Microsoft | 2025-05-13 |
| CVE-2025-4096 | Chromium: CVE-2025-4096 Heap buffer overflow in HTML | UNKNOWN | — | 39%ile | Microsoft | 2025-05-13 |
| CVE-2025-5066 | Chromium: CVE-2025-5066 Inappropriate implementation in Messages | UNKNOWN | — | 33%ile | Microsoft | 2025-05-13 |
| CVE-2025-5067 | Chromium: CVE-2025-5067 Inappropriate implementation in Tab Strip | UNKNOWN | — | 29%ile | Microsoft | 2025-05-13 |
| CVE-2025-5283 | Chromium: CVE-2025-5283 Use after free in libvpx | UNKNOWN | — | 41%ile | Microsoft | 2025-05-13 |
| CVE-2025-5281 | Chromium: CVE-2025-5281 Inappropriate implementation in BFCache | UNKNOWN | — | 9%ile | Microsoft | 2025-05-13 |
| CVE-2025-5065 | Chromium: CVE-2025-5065 Inappropriate implementation in FileSystemAccess API | UNKNOWN | — | 33%ile | Microsoft | 2025-05-13 |
| CVE-2025-5064 | Chromium: CVE-2025-5064 Inappropriate implementation in Background Fetch API | UNKNOWN | — | 25%ile | Microsoft | 2025-05-13 |
| CVE-2025-5280 | Chromium: CVE-2025-5280 Out of bounds write in V8 | UNKNOWN | — | 82%ile | Microsoft | 2025-05-13 |
| CVE-2025-5063 | Chromium: CVE-2025-5063 Use after free in Compositing | UNKNOWN | — | 87%ile | Microsoft | 2025-05-13 |
| CVE-2025-4372 | Chromium: CVE-2025-4372 Use after free in WebAudio | UNKNOWN | — | 39%ile | Microsoft | 2025-05-13 |
| CVE-2025-4609 | Chromium: CVE-2025-4609 Incorrect handle provided in unspecified circumstances in Mojo | UNKNOWN | — | 32%ile | Microsoft | 2025-05-13 |
| CVE-2025-4664 | Chromium: CVE-2025-4664 Insufficient policy enforcement in Loader | UNKNOWN | — | 92%ile | Microsoft | 2025-05-13 |
| CVE-2025-4051 | Chromium: CVE-2025-4051 Insufficient data validation in DevTools | UNKNOWN | — | 22%ile | Microsoft | 2025-05-13 |
| CVE-2025-4052 | Chromium: CVE-2025-4052 Inappropriate implementation in DevTools | UNKNOWN | — | 45%ile | Microsoft | 2025-05-13 |
| CVE-2024-30080 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99%ile | Microsoft | 2024-06-11 |
| CVE-2024-30078 | Windows Wi-Fi Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 92%ile | Microsoft | 2024-06-11 |
| CVE-2024-30064 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 53%ile | Microsoft | 2024-06-11 |
| CVE-2024-30068 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 52%ile | Microsoft | 2024-06-11 |
| CVE-2024-30097 | Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2024-06-11 |
| CVE-2024-30103 | Microsoft Outlook Remote Code Execution Vulnerability | HIGH | 8.8 | 88%ile | Microsoft | 2024-06-11 |
| CVE-2024-35249 | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | HIGH | 8.8 | 88%ile | Microsoft | 2024-06-11 |
| CVE-2024-37325 | Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability | HIGH | 8.1 | 63%ile | Microsoft | 2024-06-11 |
| CVE-2024-30074 | Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | HIGH | 8.0 | 65%ile | Microsoft | 2024-06-11 |
| CVE-2024-30075 | Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | HIGH | 8.0 | 56%ile | Microsoft | 2024-06-11 |
| CVE-2024-30077 | Windows OLE Remote Code Execution Vulnerability | HIGH | 8.0 | 76%ile | Microsoft | 2024-06-11 |
| CVE-2024-35260 | Microsoft Dataverse Remote Code Execution Vulnerability | HIGH | 8.0 | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-30072 | Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability | HIGH | 7.8 | 55%ile | Microsoft | 2024-06-11 |
| CVE-2024-30082 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 67%ile | Microsoft | 2024-06-11 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 98%ile | Microsoft | 2024-06-11 |
| CVE-2024-30062 | Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability | HIGH | 7.8 | 60%ile | Microsoft | 2024-06-11 |
| CVE-2024-30085 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 96%ile | Microsoft | 2024-06-11 |
| CVE-2024-30086 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 63%ile | Microsoft | 2024-06-11 |
| CVE-2024-30087 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 95%ile | Microsoft | 2024-06-11 |
| CVE-2024-30089 | Microsoft Streaming Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 94%ile | Microsoft | 2024-06-11 |
| CVE-2024-30091 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 90%ile | Microsoft | 2024-06-11 |
| CVE-2024-30094 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.8 | 56%ile | Microsoft | 2024-06-11 |
| CVE-2024-30095 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.8 | 60%ile | Microsoft | 2024-06-11 |
| CVE-2024-30100 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.8 | 65%ile | Microsoft | 2024-06-11 |
| CVE-2024-30104 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 72%ile | Microsoft | 2024-06-11 |
| CVE-2024-30070 | DHCP Server Service Denial of Service Vulnerability | HIGH | 7.5 | 82%ile | Microsoft | 2024-06-11 |
| CVE-2023-50868 | MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU | HIGH | 7.5 | 100%ile | Microsoft | 2024-06-11 |
| CVE-2024-30083 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | HIGH | 7.5 | 83%ile | Microsoft | 2024-06-11 |
| CVE-2024-30101 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.5 | 76%ile | Microsoft | 2024-06-11 |
| CVE-2024-35252 | Azure Storage Movement Client Library Denial of Service Vulnerability | HIGH | 7.5 | 83%ile | Microsoft | 2024-06-11 |
| CVE-2024-29187 | GitHub: CVE-2024-29187 WiX Burn-based bundles are vulnerable to binary hijack when run as SYSTEM | HIGH | 7.3 | 38%ile | Microsoft | 2024-06-11 |
| CVE-2024-30093 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.3 | 63%ile | Microsoft | 2024-06-11 |
| CVE-2024-30102 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.3 | 52%ile | Microsoft | 2024-06-11 |
| CVE-2024-35248 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | HIGH | 7.3 | 58%ile | Microsoft | 2024-06-11 |
| CVE-2024-35254 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 7.1 | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-30084 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 92%ile | Microsoft | 2024-06-11 |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 99%ile | Microsoft | 2024-06-11 |
| CVE-2024-30090 | Microsoft Streaming Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 78%ile | Microsoft | 2024-06-11 |
| CVE-2024-30099 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 42%ile | Microsoft | 2024-06-11 |
| CVE-2024-35265 | Windows Perception Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 29%ile | Microsoft | 2024-06-11 |
| CVE-2024-30076 | Windows Container Manager Service Elevation of Privilege Vulnerability | MEDIUM | 6.8 | 75%ile | Microsoft | 2024-06-11 |
| CVE-2024-29060 | Visual Studio Elevation of Privilege Vulnerability | MEDIUM | 6.7 | 56%ile | Microsoft | 2024-06-11 |
| CVE-2024-30063 | Windows Distributed File System (DFS) Remote Code Execution Vulnerability | MEDIUM | 6.7 | 60%ile | Microsoft | 2024-06-11 |
| CVE-2024-35263 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | MEDIUM | 5.7 | 74%ile | Microsoft | 2024-06-11 |
| CVE-2024-35255 | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-30065 | Windows Themes Denial of Service Vulnerability | MEDIUM | 5.5 | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-30066 | Winlogon Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2024-06-11 |
| CVE-2024-30067 | Winlogon Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 47%ile | Microsoft | 2024-06-11 |
| CVE-2024-30096 | Windows Cryptographic Services Information Disclosure Vulnerability | MEDIUM | 5.5 | 58%ile | Microsoft | 2024-06-11 |
| CVE-2024-30058 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 32%ile | Microsoft | 2024-06-11 |
| CVE-2024-30057 | Microsoft Edge for iOS Spoofing Vulnerability | MEDIUM | 5.4 | 33%ile | Microsoft | 2024-06-11 |
| CVE-2024-30069 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 4.7 | 44%ile | Microsoft | 2024-06-11 |
| CVE-2024-38082 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.7 | 40%ile | Microsoft | 2024-06-11 |
| CVE-2024-30052 | Visual Studio Remote Code Execution Vulnerability | MEDIUM | 4.7 | 69%ile | Microsoft | 2024-06-11 |
| CVE-2024-35253 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | MEDIUM | 4.4 | 51%ile | Microsoft | 2024-06-11 |
| CVE-2024-38093 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 40%ile | Microsoft | 2024-06-11 |
| CVE-2024-38083 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 40%ile | Microsoft | 2024-06-11 |
| CVE-2024-5841 | Chromium: CVE-2024-5841 Use after free in V8 | UNKNOWN | — | 91%ile | Microsoft | 2024-06-11 |
| CVE-2024-5835 | Chromium: CVE-2024-5835 Heap buffer overflow in Tab Groups | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-5837 | Chromium: CVE-2024-5837 Type Confusion in V8 | UNKNOWN | — | 42%ile | Microsoft | 2024-06-11 |
| CVE-2024-5844 | Chromium: CVE-2024-5844 Heap buffer overflow in Tab Strip | UNKNOWN | — | 42%ile | Microsoft | 2024-06-11 |
| CVE-2024-5833 | Chromium: CVE-2024-5833 Type Confusion in V8 | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-5839 | Chromium: CVE-2024-5839 Inappropriate Implementation in Memory Allocator | UNKNOWN | — | 39%ile | Microsoft | 2024-06-11 |
| CVE-2024-5836 | Chromium: CVE-2024-5836 Inappropriate Implementation in DevTools | UNKNOWN | — | 40%ile | Microsoft | 2024-06-11 |
| CVE-2024-5834 | Chromium: CVE-2024-5834 Inappropriate implementation in Dawn | UNKNOWN | — | 44%ile | Microsoft | 2024-06-11 |
| CVE-2024-5843 | Chromium: CVE-2024-5843 Inappropriate implementation in Downloads | UNKNOWN | — | 38%ile | Microsoft | 2024-06-11 |
| CVE-2024-5831 | Chromium: CVE-2024-5831 Use after free in Dawn | UNKNOWN | — | 39%ile | Microsoft | 2024-06-11 |
| CVE-2024-5840 | Chromium: CVE-2024-5840 Policy Bypass in CORS | UNKNOWN | — | 34%ile | Microsoft | 2024-06-11 |
| CVE-2024-5842 | Chromium: CVE-2024-5842 Use after free in Browser UI | UNKNOWN | — | 39%ile | Microsoft | 2024-06-11 |
| CVE-2024-5838 | Chromium: CVE-2024-5838 Type Confusion in V8 | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-5832 | Chromium: CVE-2024-5832 Use after free in Dawn | UNKNOWN | — | 39%ile | Microsoft | 2024-06-11 |
| CVE-2024-5830 | Chromium: CVE-2024-5830 Type Confusion in V8 | UNKNOWN | — | 57%ile | Microsoft | 2024-06-11 |
| CVE-2024-5493 | Chromium: CVE-2024-5493 Heap buffer overflow in WebRTC | UNKNOWN | — | 51%ile | Microsoft | 2024-06-11 |
| CVE-2024-5498 | Chromium: CVE-2024-5498 Use after free in Presentation API | UNKNOWN | — | 47%ile | Microsoft | 2024-06-11 |
| CVE-2024-5496 | Chromium: CVE-2024-5496 Use after free in Media Session | UNKNOWN | — | 54%ile | Microsoft | 2024-06-11 |
| CVE-2024-5499 | Chromium: CVE-2024-5499 Out of bounds write in Streams API | UNKNOWN | — | 56%ile | Microsoft | 2024-06-11 |
| CVE-2024-5494 | Chromium: CVE-2024-5494 Use after free in Dawn | UNKNOWN | — | 48%ile | Microsoft | 2024-06-11 |
| CVE-2024-5497 | Chromium: CVE-2024-5497 Out of bounds memory access in Keyboard Inputs | UNKNOWN | — | 51%ile | Microsoft | 2024-06-11 |
| CVE-2024-5495 | Chromium: CVE-2024-5495 Use after free in Dawn | UNKNOWN | — | 49%ile | Microsoft | 2024-06-11 |
| CVE-2024-6103 | Chromium: CVE-2024-6103: Use after free in Dawn | UNKNOWN | — | 47%ile | Microsoft | 2024-06-11 |
| CVE-2024-6102 | Chromium: CVE-2024-6102: Out of bounds memory access in Dawn | UNKNOWN | — | 49%ile | Microsoft | 2024-06-11 |
| CVE-2024-6101 | Chromium: CVE-2024-6101: Inappropriate implementation in WebAssembly | UNKNOWN | — | 53%ile | Microsoft | 2024-06-11 |
| CVE-2024-6100 | Chromium: CVE-2024-6100 Type Confusion in V8 | UNKNOWN | — | 64%ile | Microsoft | 2024-06-11 |
| CVE-2024-6290 | Chromium: CVE-2024-6290 Use after free in Dawn | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-6293 | Chromium: CVE-2024-6293 Use after free in Dawn | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-6292 | Chromium: CVE-2024-6292 Use after free in Dawn | UNKNOWN | — | 41%ile | Microsoft | 2024-06-11 |
| CVE-2024-6291 | Chromium: CVE-2024-6291 Use after free in Swiftshader | UNKNOWN | — | 43%ile | Microsoft | 2024-06-11 |
| CVE-2024-34122 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | UNKNOWN | — | 24%ile | Microsoft | 2024-06-11 |
| CVE-2024-5846 | Chromium: CVE-2024-5846 Use after free in PDFium | UNKNOWN | — | 38%ile | Microsoft | 2024-06-11 |
| CVE-2024-5847 | Chromium: CVE-2024-5847 Use after free in PDFium | UNKNOWN | — | 38%ile | Microsoft | 2024-06-11 |
| CVE-2024-5845 | Chromium: CVE-2024-5845 Use after free in Audio | UNKNOWN | — | 38%ile | Microsoft | 2024-06-11 |
| CVE-2022-2601-M | CVE-2022-2601-M | UNKNOWN | — | — | Microsoft | 2024-06-11 |
| CVE-2022-3775-M | CVE-2022-3775-M | UNKNOWN | — | — | Microsoft | 2024-06-11 |
| CVE-2024-29157 | HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read resulting in the corruption of the instruction pointer | CRITICAL | 9.8 | 56%ile | Microsoft | 2024-05-14 |
| CVE-2024-29159 | HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset resulting in the corruption of the instruction | CRITICAL | 9.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-32615 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c caused b | CRITICAL | 9.8 | 62%ile | Microsoft | 2024-05-14 |
| CVE-2024-32621 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_ | CRITICAL | 9.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-33874 | HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c. | CRITICAL | 9.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-4778 | Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that w | CRITICAL | 9.8 | 36%ile | Microsoft | 2024-05-14 |
| CVE-2024-29164 | HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap resulting in the corruption of the instruction | CRITICAL | 9.8 | 55%ile | Microsoft | 2024-05-14 |
| CVE-2024-32611 | HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c. | CRITICAL | 9.8 | 58%ile | Microsoft | 2024-05-14 |
| CVE-2024-4323 | Fluent Bit Memory Corruption Vulnerability | CRITICAL | 9.8 | 98%ile | Microsoft | 2024-05-14 |
| CVE-2024-27053 | wifi: wilc1000: fix RCU usage in connect path | CRITICAL | 9.1 | 74%ile | Microsoft | 2024-05-14 |
| CVE-2024-32622 | HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_ex | CRITICAL | 9.1 | 59%ile | Microsoft | 2024-05-14 |
| CVE-2024-32002 | GitHub: CVE-2024-32002 Recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote | CRITICAL | 9.0 | 98%ile | Microsoft | 2024-05-14 |
| CVE-2024-29161 | HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table resulting in the corruption of the instru | HIGH | 8.8 | 55%ile | Microsoft | 2024-05-14 |
| CVE-2024-32617 | HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in | HIGH | 8.8 | 54%ile | Microsoft | 2024-05-14 |
| CVE-2024-32623 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_e | HIGH | 8.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-35854 | mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash | HIGH | 8.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-35955 | kprobes: Fix possible use-after-free issue on kprobe registration | HIGH | 8.8 | 64%ile | Microsoft | 2024-05-14 |
| CVE-2021-47323 | watchdog: sc520_wdt: Fix possible use-after-free in wdt_turnoff() | HIGH | 8.8 | 64%ile | Microsoft | 2024-05-14 |
| CVE-2021-47324 | watchdog: Fix possible use-after-free in wdt_startup() | HIGH | 8.8 | 64%ile | Microsoft | 2024-05-14 |
| CVE-2024-4770 | When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability af | HIGH | 8.8 | 45%ile | Microsoft | 2024-05-14 |
| CVE-2024-32605 | HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readv | HIGH | 8.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-32614 | HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c. | HIGH | 8.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-33873 | HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c. | HIGH | 8.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-33877 | HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c. | HIGH | 8.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-2746 | Incomplete fix for CVE-2024-1929 | HIGH | 8.8 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-30006 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2024-05-14 |
| CVE-2024-30007 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 8.8 | 43%ile | Microsoft | 2024-05-14 |
| CVE-2024-30009 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 75%ile | Microsoft | 2024-05-14 |
| CVE-2024-30010 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-05-14 |
| CVE-2024-30017 | Windows Hyper-V Remote Code Execution Vulnerability | HIGH | 8.8 | 78%ile | Microsoft | 2024-05-14 |
| CVE-2024-30040 | Windows MSHTML Platform Security Feature Bypass Vulnerability | HIGH | 8.8 | 89%ile | Microsoft | 2024-05-14 |
| CVE-2024-34402 | An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long ke | HIGH | 8.6 | 66%ile | Microsoft | 2024-05-14 |
| CVE-2024-33602 | nscd: netgroup cache assumes NSS callback uses in-buffer strings | HIGH | 8.6 | 33%ile | Microsoft | 2024-05-14 |
| CVE-2023-52755 | ksmbd: fix slab out of bounds write in smb_inherit_dacl() | HIGH | 8.4 | 98%ile | Microsoft | 2024-05-14 |
| CVE-2024-27407 | fs/ntfs3: Fixed overflow check in mi_enum_attr() | HIGH | 8.4 | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-35869 | smb: client: guarantee refcounted children from parent session | HIGH | 8.4 | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-26945 | crypto: iaa - Fix nr_cpus < nr_iaa case | HIGH | 8.4 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-3727 | Containers/image: digest type does not guarantee valid type | HIGH | 8.3 | 67%ile | Microsoft | 2024-05-14 |
| CVE-2024-33599 | nscd: Stack-based buffer overflow in netgroup cache | HIGH | 8.1 | 68%ile | Microsoft | 2024-05-14 |
| CVE-2024-36912 | Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl | HIGH | 8.1 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-36913 | Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails | HIGH | 8.1 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-5564 | Libndp: buffer overflow in route information length field | HIGH | 8.1 | 64%ile | Microsoft | 2024-05-14 |
| CVE-2024-30020 | Windows Cryptographic Services Remote Code Execution Vulnerability | HIGH | 8.1 | 68%ile | Microsoft | 2024-05-14 |
| CVE-2024-32004 | GitHub: CVE-2024-32004 Remote Code Execution while cloning special-crafted local repositories | HIGH | 8.1 | 67%ile | Microsoft | 2024-05-14 |
| CVE-2024-26929 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | HIGH | 7.8 | — | Microsoft | 2024-05-14 |
| CVE-2024-26930 | scsi: qla2xxx: Fix double free of the ha->vp_map pointer | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-26983 | bootconfig: use memblock_free_late to free xbc memory to buddy | HIGH | 7.8 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-27018 | netfilter: br_netfilter: skip conntrack input hook for promisc packets | HIGH | 7.8 | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-27395 | net: openvswitch: Fix Use-After-Free in ovs_ct_exit | HIGH | 7.8 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-35864 | smb: client: fix potential UAF in smb2_is_valid_lease_break() | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-35861 | smb: client: fix potential UAF in cifs_signal_cifsd_for_reconnect() | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-35863 | smb: client: fix potential UAF in is_valid_oplock_break() | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-35862 | smb: client: fix potential UAF in smb2_is_network_name_deleted() | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2023-52812 | drm/amd: check num of link levels when update pcie param | HIGH | 7.8 | 18%ile | Microsoft | 2024-05-14 |
| CVE-2024-35929 | rcu/nocb: Fix WARN_ON_ONCE() in the rcu_nocb_bypass_lock() | HIGH | 7.8 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-36012 | Bluetooth: msft: fix slab-use-after-free in msft_do_close() | HIGH | 7.8 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2023-52751 | smb: client: fix use-after-free in smb2_query_info_compound() | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-36898 | gpiolib: cdev: fix uninitialised kfifo | HIGH | 7.8 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26933 | USB: core: Fix deadlock in port "disable" sysfs attribute | HIGH | 7.8 | 8%ile | Microsoft | 2024-05-14 |
| CVE-2024-26934 | USB: core: Fix deadlock in usb_deauthorize_interface() | HIGH | 7.8 | 9%ile | Microsoft | 2024-05-14 |
| CVE-2024-26952 | ksmbd: fix potencial out-of-bounds when buffer offset is invalid | HIGH | 7.8 | 54%ile | Microsoft | 2024-05-14 |
| CVE-2024-26961 | mac802154: fix llsec key resources release in mac802154_llsec_key_del | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-27022 | fork: defer linking file vma until vma is fully initialized | HIGH | 7.8 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27061 | crypto: sun8i-ce - Fix use after free in unprepare | HIGH | 7.8 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35801 | x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD | HIGH | 7.8 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2023-52649 | drm/vkms: Avoid reading beyond LUT array | HIGH | 7.8 | 20%ile | Microsoft | 2024-05-14 |
| CVE-2023-52760 | gfs2: Fix slab-use-after-free in gfs2_qd_dealloc | HIGH | 7.8 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2023-52752 | smb: client: fix use-after-free bug in cifs_debug_data_proc_show() | HIGH | 7.8 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2022-48670 | peci: cpu: Fix use-after-free in adev_release() | HIGH | 7.8 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-1929 | Local Root Exploit via Configuration Dictionary | HIGH | 7.8 | 21%ile | Microsoft | 2024-05-14 |
| CVE-2023-52733 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | HIGH | 7.8 | — | Microsoft | 2024-05-14 |
| CVE-2024-36921 | wifi: iwlwifi: mvm: guard against invalid STA ID on removal | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-35949 | btrfs: make sure that WRITTEN is set on all metadata blocks | HIGH | 7.8 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-29996 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2024-05-14 |
| CVE-2024-30018 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 56%ile | Microsoft | 2024-05-14 |
| CVE-2024-30060 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2024-05-14 |
| CVE-2024-26238 | Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability | HIGH | 7.8 | 54%ile | Microsoft | 2024-05-14 |
| CVE-2024-29994 | Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability | HIGH | 7.8 | 49%ile | Microsoft | 2024-05-14 |
| CVE-2024-30025 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 90%ile | Microsoft | 2024-05-14 |
| CVE-2024-30027 | NTFS Elevation of Privilege Vulnerability | HIGH | 7.8 | 47%ile | Microsoft | 2024-05-14 |
| CVE-2024-30028 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2024-05-14 |
| CVE-2024-30030 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2024-05-14 |
| CVE-2024-30031 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2024-05-14 |
| CVE-2024-30032 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 91%ile | Microsoft | 2024-05-14 |
| CVE-2024-30035 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2024-05-14 |
| CVE-2024-30038 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 84%ile | Microsoft | 2024-05-14 |
| CVE-2024-30042 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 80%ile | Microsoft | 2024-05-14 |
| CVE-2024-30049 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2024-05-14 |
| CVE-2024-30051 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 92%ile | Microsoft | 2024-05-14 |
| CVE-2024-2410 | Use after free in C++ protobuf | HIGH | 7.6 | 26%ile | Microsoft | 2024-05-14 |
| CVE-2024-30047 | Dynamics 365 Customer Insights Spoofing Vulnerability | HIGH | 7.6 | 59%ile | Microsoft | 2024-05-14 |
| CVE-2024-30048 | Dynamics 365 Customer Insights Spoofing Vulnerability | HIGH | 7.6 | 59%ile | Microsoft | 2024-05-14 |
| CVE-2024-32609 | HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c. | HIGH | 7.5 | 53%ile | Microsoft | 2024-05-14 |
| CVE-2024-33601 | nscd: netgroup cache may terminate daemon on memory allocation failure | HIGH | 7.5 | 62%ile | Microsoft | 2024-05-14 |
| CVE-2024-34069 | Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution | HIGH | 7.5 | 88%ile | Microsoft | 2024-05-14 |
| CVE-2024-34459 | An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with | HIGH | 7.5 | 82%ile | Microsoft | 2024-05-14 |
| CVE-2024-4068 | Memory Exhaustion in braces | HIGH | 7.5 | 71%ile | Microsoft | 2024-05-14 |
| CVE-2024-4777 | Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidenc | HIGH | 7.5 | 42%ile | Microsoft | 2024-05-14 |
| CVE-2024-4773 | When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This | HIGH | 7.5 | 42%ile | Microsoft | 2024-05-14 |
| CVE-2024-30251 | Denial of service when trying to parse malformed POST requests in aiohttp | HIGH | 7.5 | 62%ile | Microsoft | 2024-05-14 |
| CVE-2023-52696 | powerpc/powernv: Add a null pointer check in opal_powercap_init() | HIGH | 7.5 | 54%ile | Microsoft | 2024-05-14 |
| CVE-2023-6349 | Heap overflow in libvpx | HIGH | 7.5 | 30%ile | Microsoft | 2024-05-14 |
| CVE-2024-30014 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2024-05-14 |
| CVE-2024-30015 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2024-05-14 |
| CVE-2024-30022 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2024-05-14 |
| CVE-2024-30023 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2024-05-14 |
| CVE-2024-30024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2024-05-14 |
| CVE-2024-30029 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 7.5 | 72%ile | Microsoft | 2024-05-14 |
| CVE-2024-29165 | HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32 resulting in the corruption of the instruction | HIGH | 7.4 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-32613 | HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c a | HIGH | 7.4 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-32619 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c resulting in the corruptio | HIGH | 7.4 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-29158 | HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc resulting in the corruption of the instruction p | HIGH | 7.4 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-29160 | HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize resulting in the corruption of the i | HIGH | 7.4 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-29162 | HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read resulting in denial of service or potent | HIGH | 7.4 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-29163 | HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find resulting in the corruption of the instruction poin | HIGH | 7.4 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-32612 | HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c resulting in t | HIGH | 7.4 | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-32616 | HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c. | HIGH | 7.4 | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-32618 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c resulting in th | HIGH | 7.4 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-32620 | HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c resulting in the c | HIGH | 7.4 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-32624 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__ | HIGH | 7.4 | 47%ile | Microsoft | 2024-05-14 |
| CVE-2024-32465 | Git's protections for cloning untrusted repositories can be bypassed | HIGH | 7.3 | 56%ile | Microsoft | 2024-05-14 |
| CVE-2024-30044 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 7.2 | 100%ile | Microsoft | 2024-05-14 |
| CVE-2024-36914 | drm/amd/display: Skip on writeback when it's not applicable | HIGH | 7.1 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-36915 | nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies | HIGH | 7.1 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2023-52827 | wifi: ath12k: fix possible out-of-bound read in ath12k_htt_pull_ppdu_stats() | HIGH | 7.1 | 18%ile | Microsoft | 2024-05-14 |
| CVE-2024-26982 | Squashfs: check the inode number is not the invalid value of zero | HIGH | 7.1 | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-35849 | btrfs: fix information leak in btrfs_ioctl_logical_to_ino() | HIGH | 7.1 | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-35937 | wifi: cfg80211: check A-MSDU format more carefully | HIGH | 7.1 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2023-50230 | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability | HIGH | 7.1 | 72%ile | Microsoft | 2024-05-14 |
| CVE-2023-50229 | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability | HIGH | 7.1 | 82%ile | Microsoft | 2024-05-14 |
| CVE-2024-30056 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | HIGH | 7.1 | 73%ile | Microsoft | 2024-05-14 |
| CVE-2024-27020 | netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() | HIGH | 7.0 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-36899 | gpiolib: cdev: Fix use after free in lineinfo_changed_notify | HIGH | 7.0 | 8%ile | Microsoft | 2024-05-14 |
| CVE-2024-30033 | Windows Search Service Elevation of Privilege Vulnerability | HIGH | 7.0 | 58%ile | Microsoft | 2024-05-14 |
| CVE-2024-36013 | Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() | MEDIUM | 6.8 | 38%ile | Microsoft | 2024-05-14 |
| CVE-2024-35843 | iommu/vt-d: Use device rbtree in iopf reporting path | MEDIUM | 6.8 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-29997 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-29998 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-29999 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-30000 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-30001 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 58%ile | Microsoft | 2024-05-14 |
| CVE-2024-30002 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-30003 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-30004 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 56%ile | Microsoft | 2024-05-14 |
| CVE-2024-30005 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-30012 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 55%ile | Microsoft | 2024-05-14 |
| CVE-2024-30021 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | MEDIUM | 6.8 | 54%ile | Microsoft | 2024-05-14 |
| CVE-2024-35887 | ax25: fix use-after-free bugs caused by ax25_ds_del_timer | MEDIUM | 6.7 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2023-52837 | nbd: fix uaf in nbd_open | MEDIUM | 6.7 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-27282 | An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler it i | MEDIUM | 6.6 | 47%ile | Microsoft | 2024-05-14 |
| CVE-2024-35866 | smb: client: fix potential UAF in cifs_dump_full_key() | MEDIUM | 6.6 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-35868 | smb: client: fix potential UAF in cifs_stats_proc_write() | MEDIUM | 6.6 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-35867 | smb: client: fix potential UAF in cifs_stats_proc_show() | MEDIUM | 6.6 | 18%ile | Microsoft | 2024-05-14 |
| CVE-2023-52670 | rpmsg: virtio: Free driver_override when rpmsg_remove() | MEDIUM | 6.6 | 21%ile | Microsoft | 2024-05-14 |
| CVE-2024-35826 | block: Fix page refcounts for unaligned buffers in __bio_release_pages() | MEDIUM | 6.6 | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-26944 | btrfs: zoned: fix use-after-free in do_zone_finish() | MEDIUM | 6.6 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-1930 | No Limit on Number of Open Sessions / Bad Session Close Behaviour | MEDIUM | 6.5 | 22%ile | Microsoft | 2024-05-14 |
| CVE-2024-27028 | spi: spi-mt65xx: Fix NULL pointer access in interrupt handler | MEDIUM | 6.5 | 64%ile | Microsoft | 2024-05-14 |
| CVE-2024-27982 | The team has identified a critical vulnerability in the http server of the most recent version of Node where malformed h | MEDIUM | 6.5 | 64%ile | Microsoft | 2024-05-14 |
| CVE-2023-43040 | IBM Spectrum Fusion HCI improper access control | MEDIUM | 6.5 | 83%ile | Microsoft | 2024-05-14 |
| CVE-2024-30011 | Windows Hyper-V Denial of Service Vulnerability | MEDIUM | 6.5 | 84%ile | Microsoft | 2024-05-14 |
| CVE-2024-30019 | DHCP Server Service Denial of Service Vulnerability | MEDIUM | 6.5 | 84%ile | Microsoft | 2024-05-14 |
| CVE-2024-30053 | Azure Migrate Cross-Site Scripting Vulnerability | MEDIUM | 6.5 | 58%ile | Microsoft | 2024-05-14 |
| CVE-2024-30036 | Windows Deployment Services Information Disclosure Vulnerability | MEDIUM | 6.5 | 82%ile | Microsoft | 2024-05-14 |
| CVE-2024-30043 | Microsoft SharePoint Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 99%ile | Microsoft | 2024-05-14 |
| CVE-2024-30054 | Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability | MEDIUM | 6.5 | 76%ile | Microsoft | 2024-05-14 |
| CVE-2024-35853 | mlxsw: spectrum_acl_tcam: Fix memory leak during rehash | MEDIUM | 6.4 | 51%ile | Microsoft | 2024-05-14 |
| CVE-2024-24787 | Arbitrary code execution during build on Darwin in cmd/go | MEDIUM | 6.4 | 52%ile | Microsoft | 2024-05-14 |
| CVE-2024-36039 | PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict | MEDIUM | 6.3 | 49%ile | Microsoft | 2024-05-14 |
| CVE-2024-27032 | f2fs: fix to avoid potential panic during recovery | MEDIUM | 6.3 | 21%ile | Microsoft | 2024-05-14 |
| CVE-2024-27005 | interconnect: Don't access req_list while it's being manipulated | MEDIUM | 6.3 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-30045 | .NET and Visual Studio Remote Code Execution Vulnerability | MEDIUM | 6.3 | 66%ile | Microsoft | 2024-05-14 |
| CVE-2024-34250 | A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote | MEDIUM | 6.2 | 26%ile | Microsoft | 2024-05-14 |
| CVE-2024-35799 | drm/amd/display: Prevent crash when disable stream | MEDIUM | 6.2 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-4418 | Libvirt: stack use-after-free in virnetclientioeventloop() | MEDIUM | 6.2 | 39%ile | Microsoft | 2024-05-14 |
| CVE-2024-36910 | uio_hv_generic: Don't free decrypted memory | MEDIUM | 6.2 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-26954 | ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16() | MEDIUM | 6.1 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-35794 | dm-raid: really frozen sync_thread during suspend | MEDIUM | 6.1 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-30059 | Microsoft Intune for Android Mobile Application Management Tampering Vulnerability | MEDIUM | 6.1 | 46%ile | Microsoft | 2024-05-14 |
| CVE-2024-1298 | Integer Overflow caused by divide by zero during S3 suspension | MEDIUM | 6.0 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-24788 | Malformed DNS message can cause infinite loop in net | MEDIUM | 5.9 | 60%ile | Microsoft | 2024-05-14 |
| CVE-2024-34403 | An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a l | MEDIUM | 5.9 | 68%ile | Microsoft | 2024-05-14 |
| CVE-2024-4772 | An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vuln | MEDIUM | 5.9 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-4775 | An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid | MEDIUM | 5.9 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-33394 | An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command | MEDIUM | 5.9 | 25%ile | Microsoft | 2024-05-14 |
| CVE-2024-26306 | iPerf3 before 3.17 when used with OpenSSL before 3.2.0 as a server with RSA authentication allows a timing side channel | MEDIUM | 5.9 | 62%ile | Microsoft | 2024-05-14 |
| CVE-2024-33600 | nscd: Null pointer crashes after notfound response | MEDIUM | 5.9 | 66%ile | Microsoft | 2024-05-14 |
| CVE-2024-30046 | Visual Studio Denial of Service Vulnerability | MEDIUM | 5.9 | 75%ile | Microsoft | 2024-05-14 |
| CVE-2024-32610 | HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c resulting in a corrupted instruction pointer. | MEDIUM | 5.7 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-33876 | HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c. | MEDIUM | 5.7 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-35808 | md/dm-raid: don't call md_reap_sync_thread() directly | MEDIUM | 5.7 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-29166 | HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode resulting in the corruption of the instruction point | MEDIUM | 5.7 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-32607 | HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c resulting in the corruption of the instruction pointer. | MEDIUM | 5.7 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-33875 | HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c resulting in the corru | MEDIUM | 5.7 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-35195 | Requests `Session` object does not verify requests after making first request with verify=False | MEDIUM | 5.6 | 27%ile | Microsoft | 2024-05-14 |
| CVE-2024-26949 | drm/amdgpu/pm: Fix NULL pointer dereference when get power limit | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-26953 | net: esp: fix bad handling of pages from page_pool | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26969 | clk: qcom: gcc-ipq8074: fix terminating of frequency table arrays | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-26977 | pci_iounmap(): Fix MMIO mapping leak | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-26984 | nouveau: fix instmem race condition around ptr stores | MEDIUM | 5.5 | 10%ile | Microsoft | 2024-05-14 |
| CVE-2024-26990 | KVM: x86/mmu: Write-protect L2 SPTEs in TDP MMU when clearing dirty status | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-27002 | clk: mediatek: Do a runtime PM get on controllers during probe | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-27063 | leds: trigger: netdev: Fix kernel panic on interface rename trig notify | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-27388 | SUNRPC: fix some memleaks in gssx_dec_option_array | MEDIUM | 5.5 | 22%ile | Microsoft | 2024-05-14 |
| CVE-2024-27418 | net: mctp: take ownership of skb in mctp_local_output | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-27435 | nvme: fix reconnection fail due to reserved tag allocation | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-35917 | s390/bpf: Fix bpf_plt pointer arithmetic | MEDIUM | 5.5 | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-35978 | Bluetooth: Fix memory leak in hci_req_sync_complete() | MEDIUM | 5.5 | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-35990 | dma: xilinx_dpdma: Fix locking | MEDIUM | 5.5 | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-35992 | phy: marvell: a3700-comphy: Fix out of bounds read | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-36009 | ax25: Fix netdev refcount issue | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-36893 | usb: typec: tcpm: Check for port partner validity before consuming it | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-36901 | ipv6: prevent NULL dereference in ip6_output() | MEDIUM | 5.5 | 18%ile | Microsoft | 2024-05-14 |
| CVE-2024-36925 | swiotlb: initialise restricted pool list_head when SWIOTLB_DYNAMIC=y | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-36930 | spi: fix null pointer dereference within spi_sync | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2023-52648 | drm/vmwgfx: Unmap the surface before resetting it on a plane state | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2022-48669 | powerpc/pseries: Fix potential memleak in papr_get_attr() | MEDIUM | 5.5 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27041 | drm/amd/display: fix NULL checks for adev->dm.dc in amdgpu_dm_fini() | MEDIUM | 5.5 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2021-47432 | lib/generic-radix-tree.c: Don't overflow in peek() | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-27062 | nouveau: lock the client object tree. | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-35999 | smb3: missing lock when picking channel | MEDIUM | 5.5 | 6%ile | Microsoft | 2024-05-14 |
| CVE-2024-26948 | drm/amd/display: Add a dc_state NULL check in dc_state_release | MEDIUM | 5.5 | 10%ile | Microsoft | 2024-05-14 |
| CVE-2024-36924 | scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() | MEDIUM | 5.5 | 9%ile | Microsoft | 2024-05-14 |
| CVE-2024-35784 | btrfs: fix deadlock with fiemap and extent locking | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-35931 | drm/amdgpu: Skip do PCI error slot reset during RAS recovery | MEDIUM | 5.5 | 8%ile | Microsoft | 2024-05-14 |
| CVE-2023-52737 | btrfs: lock the inode in shared mode before starting fiemap | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-35865 | smb: client: fix potential UAF in smb2_is_valid_oplock_break() | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2023-52757 | smb: client: fix potential deadlock when releasing mids | MEDIUM | 5.5 | 8%ile | Microsoft | 2024-05-14 |
| CVE-2023-52653 | SUNRPC: fix a memleak in gss_import_v2_context | MEDIUM | 5.5 | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-36917 | block: fix overflow in blk_ioctl_discard() | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-26938 | drm/i915/bios: Tolerate devdata==NULL in intel_bios_encoder_supports_dp_dual_mode() | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-27035 | f2fs: compress: fix to guarantee persisting compressed blocks by CP | MEDIUM | 5.5 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27389 | pstore: inode: Only d_invalidate() is needed | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2023-52682 | f2fs: fix to wait on block writeback for post_read case | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2023-52700 | tipc: fix kernel warning when sending SYN message | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2023-52761 | riscv: VMAP_STACK overflow detection thread-safe | MEDIUM | 5.5 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2023-52831 | cpu/hotplug: Don't offline the last non-isolated CPU | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-35932 | drm/vc4: don't check if plane->state->fb == state->fb | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-35956 | btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operations | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-36000 | mm/hugetlb: fix missing hugetlb_lock for resv uncharge | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35803 | x86/efistub: Call mixed mode boot services on the firmware's stack | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35904 | selinux: avoid dereference of garbage after mount failure | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35946 | wifi: rtw89: fix null pointer access when abort scan | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-35968 | pds_core: Fix pdsc_check_pci_health function to use work thread | MEDIUM | 5.5 | 5%ile | Microsoft | 2024-05-14 |
| CVE-2024-27010 | net/sched: Fix mirred deadlock on device recursion | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2022-48673 | net/smc: Fix possible access to freed memory in link clear | MEDIUM | 5.5 | 40%ile | Microsoft | 2024-05-14 |
| CVE-2024-26940 | drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26943 | nouveau/dmem: handle kcalloc() allocation failure | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-26947 | ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26950 | wireguard: netlink: access device through ctx instead of peer | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-26978 | serial: max310x: fix NULL pointer dereference in I2C instantiation | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-26986 | drm/amdkfd: Fix memory leak in create_process failure | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26987 | mm/memory-failure: fix deadlock when hugetlb_optimize_vmemmap is enabled | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-27012 | netfilter: nf_tables: restore set elements when delete set fails | MEDIUM | 5.5 | 18%ile | Microsoft | 2024-05-14 |
| CVE-2024-27013 | tun: limit printing rate when illegal packet received by tun dev | MEDIUM | 5.5 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27014 | net/mlx5e: Prevent deadlock while disabling aRFS | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-27015 | netfilter: flowtable: incorrect pppoe tuple | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-27016 | netfilter: flowtable: validate pppoe header | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-27017 | netfilter: nft_set_pipapo: walk over current view on netlink dump | MEDIUM | 5.5 | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-27037 | clk: zynq: Prevent null pointer dereference caused by kmalloc failure | MEDIUM | 5.5 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27038 | clk: Fix clk_core_get NULL dereference | MEDIUM | 5.5 | 22%ile | Microsoft | 2024-05-14 |
| CVE-2024-27050 | libbpf: Use OPTS_SET() macro in bpf_xdp_query() | MEDIUM | 5.5 | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27066 | virtio: packed: fix unmap leak for indirect desc table | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-27076 | media: imx: csc/scaler: fix v4l2_ctrl_handler memory leak | MEDIUM | 5.5 | 21%ile | Microsoft | 2024-05-14 |
| CVE-2024-27393 | xen-netfront: Add missing skb_mark_for_recycle | MEDIUM | 5.5 | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-35912 | wifi: iwlwifi: mvm: rfi: fix potential response leaks | MEDIUM | 5.5 | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-35972 | bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init() | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35982 | batman-adv: Avoid infinite loop trying to resize local TT | MEDIUM | 5.5 | 18%ile | Microsoft | 2024-05-14 |
| CVE-2024-35984 | i2c: smbus: fix NULL function pointer dereference | MEDIUM | 5.5 | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-35997 | HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-36008 | ipv4: check for NULL idev in ip_route_use_hint() | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-36023 | Julia Lawall reported this null pointer dereference this should fix it. | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-36891 | maple_tree: fix mas_empty_area_rev() null pointer dereference | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-36897 | drm/amd/display: Atom Integrated System Info v2_2 for DCN35 | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-36902 | ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action() | MEDIUM | 5.5 | 21%ile | Microsoft | 2024-05-14 |
| CVE-2024-36926 | powerpc/pseries/iommu: LPAR panics during boot up with a frozen PE | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-36938 | bpf skmsg: Fix NULL pointer dereference in sk_psock_skb_ingress_enqueue | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2023-52654 | io_uring/af_unix: disable sending io_uring over sockets | MEDIUM | 5.5 | 56%ile | Microsoft | 2024-05-14 |
| CVE-2024-27059 | USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-4693 | Qemu-kvm: virtio-pci: improper release of configure vector leads to guest triggerable crash | MEDIUM | 5.5 | 25%ile | Microsoft | 2024-05-14 |
| CVE-2024-27056 | wifi: iwlwifi: mvm: ensure offloading TID queue exists | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2023-52660 | media: rkisp1: Fix IRQ handling due to shared interrupts | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2023-52671 | drm/amd/display: Fix hang/underflow when transitioning to ODM4:1 | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2023-52676 | bpf: Guard stack limits against 32bit overflow | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2023-52732 | ceph: blocklist the kclient when receiving corrupted snap trace | MEDIUM | 5.5 | 41%ile | Microsoft | 2024-05-14 |
| CVE-2024-35839 | netfilter: bridge: replace physindev with physinif in nf_bridge_info | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35875 | x86/coco: Require seeding RNG with RDRAND on CoCo systems | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-35924 | usb: typec: ucsi: Limit read size on v1.2 | MEDIUM | 5.5 | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-35939 | dma-direct: Leak pages on dma_set_decrypted() failure | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-35951 | drm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr() | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-35965 | Bluetooth: L2CAP: Fix not validating setsockopt user input | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-35971 | net: ks8851: Handle softirqs at the end of IRQ thread to fix hang | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-35995 | ACPI: CPPC: Use access_width over bit_width for system memory accesses | MEDIUM | 5.5 | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-36021 | net: hns3: fix kernel crash when devlink reload during pf initialization | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-36900 | net: hns3: fix kernel crash when devlink reload during initialization | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-36909 | Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-36911 | hv_netvsc: Don't free decrypted memory | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-36951 | drm/amdkfd: range check cp bad op exception interrupts | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-27400 | drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-35945 | net: phy: phy_device: Prevent nullptr exceptions on ISR | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-35998 | smb3: fix lock ordering potential deadlock in cifs_sync_mid_result | MEDIUM | 5.5 | 6%ile | Microsoft | 2024-05-14 |
| CVE-2024-36903 | ipv6: Fix potential uninit-value access in __ip6_make_skb() | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26962 | dm-raid456, md/raid456: fix a deadlock for dm-raid456 while io concurrent with reshape | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-27079 | iommu/vt-d: Fix NULL domain on device release | MEDIUM | 5.5 | 16%ile | Microsoft | 2024-05-14 |
| CVE-2023-52664 | net: atlantic: eliminate double free in error handling logic | MEDIUM | 5.5 | 20%ile | Microsoft | 2024-05-14 |
| CVE-2023-52857 | drm/mediatek: Fix coverity issue with unintentional integer overflow | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2022-48703 | thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2022-48706 | vdpa: ifcvf: Do proper cleanup if IFCVF init fails | MEDIUM | 5.5 | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-30008 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 53%ile | Microsoft | 2024-05-14 |
| CVE-2024-30016 | Windows Cryptographic Services Information Disclosure Vulnerability | MEDIUM | 5.5 | 53%ile | Microsoft | 2024-05-14 |
| CVE-2024-30034 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | MEDIUM | 5.5 | 93%ile | Microsoft | 2024-05-14 |
| CVE-2024-30037 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | MEDIUM | 5.5 | 92%ile | Microsoft | 2024-05-14 |
| CVE-2024-30039 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 51%ile | Microsoft | 2024-05-14 |
| CVE-2023-4133 | CVE-2023-4133 | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2023-51592 | BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 5.4 | 53%ile | Microsoft | 2024-05-14 |
| CVE-2024-34064 | Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter | MEDIUM | 5.4 | 59%ile | Microsoft | 2024-05-14 |
| CVE-2023-51580 | BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 5.4 | 58%ile | Microsoft | 2024-05-14 |
| CVE-2023-51589 | BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability | MEDIUM | 5.4 | 53%ile | Microsoft | 2024-05-14 |
| CVE-2024-30050 | Windows Mark of the Web Security Feature Bypass Vulnerability | MEDIUM | 5.4 | 96%ile | Microsoft | 2024-05-14 |
| CVE-2024-30055 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 5.4 | 47%ile | Microsoft | 2024-05-14 |
| CVE-2024-30041 | Microsoft Bing Search Spoofing Vulnerability | MEDIUM | 5.4 | 51%ile | Microsoft | 2024-05-14 |
| CVE-2024-35857 | icmp: prevent possible NULL dereferences from icmp_build_probe() | MEDIUM | 5.3 | 56%ile | Microsoft | 2024-05-14 |
| CVE-2021-47482 | net: batman-adv: fix error handling | MEDIUM | 5.3 | 51%ile | Microsoft | 2024-05-14 |
| CVE-2024-35878 | of: module: prevent NULL pointer dereference in vsnprintf() | MEDIUM | 5.3 | 53%ile | Microsoft | 2024-05-14 |
| CVE-2024-27436 | ALSA: usb-audio: Stop parsing channels bits when all channels are found. | MEDIUM | 5.3 | 46%ile | Microsoft | 2024-05-14 |
| CVE-2024-35176 | REXML contains a denial of service vulnerability | MEDIUM | 5.3 | 80%ile | Microsoft | 2024-05-14 |
| CVE-2024-35823 | vt: fix unicode buffer corruption when deleting characters | MEDIUM | 5.3 | 56%ile | Microsoft | 2024-05-14 |
| CVE-2024-4603 | Excessive time spent checking DSA keys and parameters | MEDIUM | 5.3 | 63%ile | Microsoft | 2024-05-14 |
| CVE-2024-34397 | An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subs | MEDIUM | 5.2 | 52%ile | Microsoft | 2024-05-14 |
| CVE-2024-36922 | wifi: iwlwifi: read txq->read_ptr under lock | MEDIUM | 5.1 | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-32886 | Vitess vulnerable to infinite memory consumption and vtgate crash | MEDIUM | 4.9 | 51%ile | Microsoft | 2024-05-14 |
| CVE-2024-34062 | tqdm CLI arguments injection attack | MEDIUM | 4.8 | 36%ile | Microsoft | 2024-05-14 |
| CVE-2023-52749 | spi: Fix null dereference on suspend | MEDIUM | 4.7 | 8%ile | Microsoft | 2024-05-14 |
| CVE-2024-36024 | drm/amd/display: Disable idle reallow as part of command/gpint execution | MEDIUM | 4.7 | 6%ile | Microsoft | 2024-05-14 |
| CVE-2024-27408 | dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup | MEDIUM | 4.7 | 8%ile | Microsoft | 2024-05-14 |
| CVE-2024-36949 | amd/amdkfd: sync all devices to wait all processes being evicted | MEDIUM | 4.7 | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-36927 | ipv4: Fix uninit-value access in __ip_make_skb() | MEDIUM | 4.7 | 6%ile | Microsoft | 2024-05-14 |
| CVE-2024-27019 | netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() | MEDIUM | 4.7 | 10%ile | Microsoft | 2024-05-14 |
| CVE-2024-27058 | tmpfs: fix race on handling dquot rbtree | MEDIUM | 4.7 | 39%ile | Microsoft | 2024-05-14 |
| CVE-2024-27281 | An issue was discovered in RDoc 6.3.3 through 6.6.2 as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options | MEDIUM | 4.5 | 73%ile | Microsoft | 2024-05-14 |
| CVE-2024-35870 | smb: client: fix UAF in smb2_reconnect_server() | MEDIUM | 4.4 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-4317 | PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks | MEDIUM | 4.3 | 50%ile | Microsoft | 2024-05-14 |
| CVE-2024-32020 | Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at w | LOW | 3.9 | 41%ile | Microsoft | 2024-05-14 |
| CVE-2024-32021 | Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory | LOW | 3.9 | 58%ile | Microsoft | 2024-05-14 |
| CVE-2024-4853 | Mismatched Memory Management Routines in editcap | LOW | 3.6 | 34%ile | Microsoft | 2024-05-14 |
| CVE-2024-4855 | Use After Free in editcap | LOW | 3.6 | 30%ile | Microsoft | 2024-05-14 |
| CVE-2023-52656 | io_uring: drop any code related to SCM_RIGHTS | LOW | 3.3 | 23%ile | Microsoft | 2024-05-14 |
| CVE-2024-36920 | scsi: mpi3mr: Avoid memcpy field-spanning write WARNING | LOW | 3.3 | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26935 | scsi: core: Fix unremoved procfs host directory regression | UNKNOWN | — | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-26946 | kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address | UNKNOWN | — | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-26951 | wireguard: netlink: check for dangling peer via is_dead instead of empty list | UNKNOWN | — | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26963 | usb: dwc3-am62: fix module unload/reload behavior | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-26975 | powercap: intel_rapl: Fix a NULL pointer dereference | UNKNOWN | — | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26988 | init/main.c: Fix potential static_command_line memory overflow | UNKNOWN | — | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-27001 | comedi: vmk80xx: fix incomplete endpoint checking | UNKNOWN | — | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-27009 | s390/cio: fix race condition during online processing | UNKNOWN | — | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-27026 | vmxnet3: Fix missing reserved tailroom | UNKNOWN | — | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27031 | NFS: Fix nfs_netfs_issue_read() xarray locking for writeback interrupt | UNKNOWN | — | 10%ile | Microsoft | 2024-05-14 |
| CVE-2024-27045 | drm/amd/display: Fix a potential buffer overflow in 'dp_dsc_clock_en_read()' | UNKNOWN | — | 23%ile | Microsoft | 2024-05-14 |
| CVE-2024-27051 | cpufreq: brcmstb-avs-cpufreq: add check for cpufreq_cpu_get's return value | UNKNOWN | — | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-27075 | media: dvb-frontends: avoid stack overflow warnings with clang | UNKNOWN | — | 26%ile | Microsoft | 2024-05-14 |
| CVE-2024-27077 | media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity | UNKNOWN | — | 21%ile | Microsoft | 2024-05-14 |
| CVE-2024-35786 | drm/nouveau: fix stale locked mutex in nouveau_gem_ioctl_pushbuf | UNKNOWN | — | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-35792 | crypto: rk3288 - Fix use after free in unprepare | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35795 | drm/amdgpu: fix deadlock while reading mqd from debugfs | UNKNOWN | — | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-35816 | firewire: ohci: prevent leak of left-over IRQ on unbind | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35827 | io_uring/net: fix overflow check in io_recvmsg_mshot_prep() | UNKNOWN | — | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-35852 | mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work | UNKNOWN | — | 17%ile | Microsoft | 2024-05-14 |
| CVE-2023-52650 | drm/tegra: dsi: Add missing check for of_find_device_by_node | UNKNOWN | — | 23%ile | Microsoft | 2024-05-14 |
| CVE-2023-52659 | x86/mm: Ensure input to pfn_to_kaddr() is treated as a 64-bit type | UNKNOWN | — | 12%ile | Microsoft | 2024-05-14 |
| CVE-2023-52661 | drm/tegra: rgb: Fix missing clk_put() in the error handling paths of tegra_dc_rgb_probe() | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2023-52802 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | Microsoft | 2024-05-14 |
| CVE-2024-27011 | netfilter: nf_tables: fix memleak in map from abort path | UNKNOWN | — | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-26939 | drm/i915/vma: Fix UAF on destroy against retire race | UNKNOWN | — | 15%ile | Microsoft | 2024-05-14 |
| CVE-2024-26965 | clk: qcom: mmcc-msm8974: fix terminating of frequency table arrays | UNKNOWN | — | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-26966 | clk: qcom: mmcc-apq8084: fix terminating of frequency table arrays | UNKNOWN | — | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-26968 | clk: qcom: gcc-ipq9574: fix terminating of frequency table arrays | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-26973 | fat: fix uninitialized field in nostale filehandles | UNKNOWN | — | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-26974 | crypto: qat - resolve race condition during AER recovery | UNKNOWN | — | 9%ile | Microsoft | 2024-05-14 |
| CVE-2024-26979 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | Microsoft | 2024-05-14 |
| CVE-2024-26993 | fs: sysfs: Fix reference leak in sysfs_break_active_protection() | UNKNOWN | — | 18%ile | Microsoft | 2024-05-14 |
| CVE-2024-27000 | serial: mxs-auart: add spinlock around changing cts state | UNKNOWN | — | 25%ile | Microsoft | 2024-05-14 |
| CVE-2024-27003 | clk: Get runtime PM before walking tree for clk_summary | UNKNOWN | — | 7%ile | Microsoft | 2024-05-14 |
| CVE-2024-27004 | clk: Get runtime PM before walking tree during disable_unused | UNKNOWN | — | 11%ile | Microsoft | 2024-05-14 |
| CVE-2024-27030 | octeontx2-af: Use separate handlers for interrupts | UNKNOWN | — | 10%ile | Microsoft | 2024-05-14 |
| CVE-2024-27033 | f2fs: fix to remove unnecessary f2fs_bug_on() to avoid panic | UNKNOWN | — | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27046 | nfp: flower: handle acti_netdevs allocation failure | UNKNOWN | — | 22%ile | Microsoft | 2024-05-14 |
| CVE-2024-27047 | net: phy: fix phy_get_internal_delay accessing an empty array | UNKNOWN | — | 20%ile | Microsoft | 2024-05-14 |
| CVE-2024-27067 | xen/evtchn: avoid WARN() when unbinding an event channel | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-27068 | thermal/drivers/mediatek/lvts_thermal: Fix a memory leak in an error handling path | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-27074 | media: go7007: fix a memleak in go7007_load_encoder | UNKNOWN | — | 21%ile | Microsoft | 2024-05-14 |
| CVE-2024-27078 | media: v4l2-tpg: fix some memleaks in tpg_alloc | UNKNOWN | — | 21%ile | Microsoft | 2024-05-14 |
| CVE-2024-27391 | wifi: wilc1000: do not realloc workqueue everytime an interface is added | UNKNOWN | — | 19%ile | Microsoft | 2024-05-14 |
| CVE-2024-27396 | net: gtp: Fix Use-After-Free in gtp_dellink | UNKNOWN | — | 16%ile | Microsoft | 2024-05-14 |
| CVE-2024-27397 | netfilter: nf_tables: use timestamp to check for set element timeout | UNKNOWN | — | 17%ile | Microsoft | 2024-05-14 |
| CVE-2024-27432 | net: ethernet: mtk_eth_soc: fix PPE hanging issue | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-27433 | clk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe() | UNKNOWN | — | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-27434 | wifi: iwlwifi: mvm: don't set the MFP flag for the GTK | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35787 | md/md-bitmap: fix incorrect usage for sb_index | UNKNOWN | — | 12%ile | Microsoft | 2024-05-14 |
| CVE-2024-35790 | usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35810 | drm/vmwgfx: Fix the lifetime of the bo cursor memory | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-35830 | media: tc358743: register v4l2 async device only after successful setup | UNKNOWN | — | 14%ile | Microsoft | 2024-05-14 |
| CVE-2024-35848 | eeprom: at24: fix memory corruption race condition | UNKNOWN | — | 9%ile | Microsoft | 2024-05-14 |
| CVE-2024-35856 | Bluetooth: btusb: mediatek: Fix double free of skb in coredump | UNKNOWN | — | 16%ile | Microsoft | 2024-05-14 |
| CVE-2023-52647 | media: nxp: imx8-isi: Check whether crossbar pad is non-NULL before access | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2023-52652 | NTB: fix possible name leak in ntb_register_device() | UNKNOWN | — | 19%ile | Microsoft | 2024-05-14 |
| CVE-2023-52662 | drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node | UNKNOWN | — | 15%ile | Microsoft | 2024-05-14 |
| CVE-2023-52663 | ASoC: SOF: amd: Fix memory leak in amd_sof_acp_probe() | UNKNOWN | — | 13%ile | Microsoft | 2024-05-14 |
| CVE-2024-34251 | An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a r | UNKNOWN | — | 52%ile | Microsoft | 2024-05-14 |
| CVE-2024-36923 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | Microsoft | 2024-05-14 |
| CVE-2024-4558 | Chromium: CVE-2024-4558 Use after free in ANGLE | UNKNOWN | — | 69%ile | Microsoft | 2024-05-14 |
| CVE-2024-4559 | Chromium: CVE-2024-4559 Heap buffer overflow in WebAudio | UNKNOWN | — | 60%ile | Microsoft | 2024-05-14 |
| CVE-2024-4671 | Chromium: CVE-2024-4671 Use after free in Visuals | UNKNOWN | — | 94%ile | Microsoft | 2024-05-14 |
| CVE-2024-4947 | Chromium: CVE-2024-4947 Type Confusion in V8 | UNKNOWN | — | 96%ile | Microsoft | 2024-05-14 |
| CVE-2024-4949 | Chromium: CVE-2024-4949 Use after free in V8 | UNKNOWN | — | 58%ile | Microsoft | 2024-05-14 |
| CVE-2024-4948 | Chromium: CVE-2024-4948 Use after free in Dawn | UNKNOWN | — | 58%ile | Microsoft | 2024-05-14 |
| CVE-2024-4950 | Chromium: CVE-2024-4950 Inappropriate implementation in Downloads | UNKNOWN | — | 57%ile | Microsoft | 2024-05-14 |
| CVE-2024-5159 | Chromium: CVE-2024-5159 Heap buffer overflow in ANGLE | UNKNOWN | — | 47%ile | Microsoft | 2024-05-14 |
| CVE-2024-5157 | Chromium: CVE-2024-5157 Use after free in Scheduling | UNKNOWN | — | 52%ile | Microsoft | 2024-05-14 |
| CVE-2024-5158 | Chromium: CVE-2024-5158 Type Confusion in V8 | UNKNOWN | — | 46%ile | Microsoft | 2024-05-14 |
| CVE-2024-5274 | Chromium: CVE-2024-5274 Type Confusion in V8 | UNKNOWN | — | 95%ile | Microsoft | 2024-05-14 |
| CVE-2024-4331 | Chromium: CVE-2024-4331 Use after free in Picture In Picture | UNKNOWN | — | 66%ile | Microsoft | 2024-05-14 |
| CVE-2024-4368 | Chromium: CVE-2024-4368 Use after free in Dawn | UNKNOWN | — | 61%ile | Microsoft | 2024-05-14 |
| CVE-2024-4761 | Chromium: CVE-2024-4761 Out of bounds write in V8 | UNKNOWN | — | 96%ile | Microsoft | 2024-05-14 |
| CVE-2024-5160 | Chromium: CVE-2024-5160 Heap buffer overflow in Dawn | UNKNOWN | — | 46%ile | Microsoft | 2024-05-14 |
| CVE-2024-4067 | CVE-2024-4067 | UNKNOWN | — | 70%ile | Microsoft | 2024-05-14 |
| CVE-2024-24576 | Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows | CRITICAL | 10.0 | 97%ile | Microsoft | 2024-04-09 |
| CVE-2024-3660 | Arbitrary code injection vulnerability in Keras framework < 2.13 | CRITICAL | 9.8 | 76%ile | Microsoft | 2024-04-09 |
| CVE-2024-3566 | Command injection vulnerability in programing languages on Microsoft Windows operating system. | CRITICAL | 9.8 | 93%ile | Microsoft | 2024-04-09 |
| CVE-2024-3817 | HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches | CRITICAL | 9.8 | 68%ile | Microsoft | 2024-04-09 |
| CVE-2024-1874 | Command injection via array-ish $command parameter of proc_open() | CRITICAL | 9.4 | 98%ile | Microsoft | 2024-04-09 |
| CVE-2024-29990 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | CRITICAL | 9.0 | 97%ile | Microsoft | 2024-04-09 |
| CVE-2024-27322 | R Language Vulnerable to Arbitrary Code Execution via Malicious RDS Files (v1.4.0–<4.4.0) | HIGH | 8.8 | 98%ile | Microsoft | 2024-04-09 |
| CVE-2024-20678 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | HIGH | 8.8 | 83%ile | Microsoft | 2024-04-09 |
| CVE-2024-26179 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 76%ile | Microsoft | 2024-04-09 |
| CVE-2024-26200 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 76%ile | Microsoft | 2024-04-09 |
| CVE-2024-26205 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH | 8.8 | 76%ile | Microsoft | 2024-04-09 |
| CVE-2024-28906 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28908 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28909 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28910 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 85%ile | Microsoft | 2024-04-09 |
| CVE-2024-28911 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-28912 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-28913 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28914 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28915 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-28929 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28931 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28932 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28936 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28939 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-28942 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28945 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-29043 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29047 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29988 | SmartScreen Prompt Security Feature Bypass Vulnerability | HIGH | 8.8 | 99%ile | Microsoft | 2024-04-09 |
| CVE-2024-21323 | Microsoft Defender for IoT Remote Code Execution Vulnerability | HIGH | 8.8 | 87%ile | Microsoft | 2024-04-09 |
| CVE-2024-26210 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 78%ile | Microsoft | 2024-04-09 |
| CVE-2024-26244 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 78%ile | Microsoft | 2024-04-09 |
| CVE-2024-26214 | Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 79%ile | Microsoft | 2024-04-09 |
| CVE-2024-28926 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-28927 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28930 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28933 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28934 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28935 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28937 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28938 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28940 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28941 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-28943 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-28944 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29044 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29046 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29048 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29053 | Microsoft Defender for IoT Remote Code Execution Vulnerability | HIGH | 8.8 | 87%ile | Microsoft | 2024-04-09 |
| CVE-2024-29982 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29983 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29984 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29985 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29993 | Azure CycleCloud Elevation of Privilege Vulnerability | HIGH | 8.8 | 79%ile | Microsoft | 2024-04-09 |
| CVE-2024-32487 | less through 653 allows OS command execution via a newline character in the name of a file because quoting is mishandled | HIGH | 8.6 | 47%ile | Microsoft | 2024-04-09 |
| CVE-2024-29050 | Windows Cryptographic Services Remote Code Execution Vulnerability | HIGH | 8.4 | 66%ile | Microsoft | 2024-04-09 |
| CVE-2024-29989 | Azure Monitor Agent Elevation of Privilege Vulnerability | HIGH | 8.4 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-27983 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets | HIGH | 8.2 | 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-3864 | Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory c | HIGH | 8.1 | 54%ile | Microsoft | 2024-04-09 |
| CVE-2024-3865 | Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that w | HIGH | 8.1 | 39%ile | Microsoft | 2024-04-09 |
| CVE-2024-20670 | Outlook for Windows Spoofing Vulnerability | HIGH | 8.1 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-26180 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 8.0 | 71%ile | Microsoft | 2024-04-09 |
| CVE-2024-26189 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 8.0 | 69%ile | Microsoft | 2024-04-09 |
| CVE-2024-26240 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 8.0 | 61%ile | Microsoft | 2024-04-09 |
| CVE-2024-28925 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 8.0 | 66%ile | Microsoft | 2024-04-09 |
| CVE-2024-26884 | bpf: Fix hashtab overflow check on 32-bit arches | HIGH | 7.8 | 16%ile | Microsoft | 2024-04-09 |
| CVE-2024-26898 | aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts | HIGH | 7.8 | 23%ile | Microsoft | 2024-04-09 |
| CVE-2024-26907 | RDMA/mlx5: Fix fortify source warning while accessing Eth segment | HIGH | 7.8 | 18%ile | Microsoft | 2024-04-09 |
| CVE-2024-31083 | Xorg-x11-server: use-after-free in procrenderaddglyphs | HIGH | 7.8 | 77%ile | Microsoft | 2024-04-09 |
| CVE-2024-31583 | Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpre | HIGH | 7.8 | 18%ile | Microsoft | 2024-04-09 |
| CVE-2024-26928 | smb: client: fix potential UAF in cifs_debug_files_proc_show() | HIGH | 7.8 | 20%ile | Microsoft | 2024-04-09 |
| CVE-2024-26836 | platform/x86: think-lmi: Fix password opcode ordering for workstations | HIGH | 7.8 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-26699 | drm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr | HIGH | 7.8 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26914 | drm/amd/display: fix incorrect mpc_combine array size | HIGH | 7.8 | 12%ile | Microsoft | 2024-04-09 |
| CVE-2024-26800 | tls: fix use-after-free on failed backlog decryption | HIGH | 7.8 | 20%ile | Microsoft | 2024-04-09 |
| CVE-2024-26739 | net/sched: act_mirred: don't override retval if we already lost the skb | HIGH | 7.8 | 20%ile | Microsoft | 2024-04-09 |
| CVE-2024-26792 | btrfs: fix double free of anonymous device after snapshot creation failure | HIGH | 7.8 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26865 | rds: tcp: Fix use-after-free of net in reqsk_timer_handler(). | HIGH | 7.8 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-26882 | net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() | HIGH | 7.8 | 54%ile | Microsoft | 2024-04-09 |
| CVE-2024-26883 | bpf: Fix stackmap overflow check on 32-bit arches | HIGH | 7.8 | 16%ile | Microsoft | 2024-04-09 |
| CVE-2024-26885 | bpf: Fix DEVMAP_HASH overflow check on 32-bit arches | HIGH | 7.8 | 16%ile | Microsoft | 2024-04-09 |
| CVE-2024-26913 | drm/amd/display: Fix dcn35 8k30 Underflow/Corruption Issue | HIGH | 7.8 | 16%ile | Microsoft | 2024-04-09 |
| CVE-2024-20693 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 54%ile | Microsoft | 2024-04-09 |
| CVE-2024-21447 | Windows Authentication Elevation of Privilege Vulnerability | HIGH | 7.8 | 69%ile | Microsoft | 2024-04-09 |
| CVE-2024-26256 | Libarchive Remote Code Execution Vulnerability | HIGH | 7.8 | 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-26158 | Microsoft Install Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 96%ile | Microsoft | 2024-04-09 |
| CVE-2024-28920 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2024-04-09 |
| CVE-2024-28905 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2024-04-09 |
| CVE-2024-26175 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 47%ile | Microsoft | 2024-04-09 |
| CVE-2024-26218 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 96%ile | Microsoft | 2024-04-09 |
| CVE-2024-26241 | Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-26229 | Windows CSC Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 95%ile | Microsoft | 2024-04-09 |
| CVE-2024-26235 | Windows Update Stack Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2024-04-09 |
| CVE-2024-26237 | Windows Defender Credential Guard Elevation of Privilege Vulnerability | HIGH | 7.8 | 49%ile | Microsoft | 2024-04-09 |
| CVE-2024-26245 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 7.8 | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-26211 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | HIGH | 7.8 | 90%ile | Microsoft | 2024-04-09 |
| CVE-2024-26228 | Windows Cryptographic Services Security Feature Bypass Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2024-04-09 |
| CVE-2024-26230 | Windows Telephony Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 98%ile | Microsoft | 2024-04-09 |
| CVE-2024-26239 | Windows Telephony Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2024-04-09 |
| CVE-2024-26257 | Microsoft Excel Remote Code Execution Vulnerability | HIGH | 7.8 | 59%ile | Microsoft | 2024-04-09 |
| CVE-2024-28904 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2024-04-09 |
| CVE-2024-28907 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2024-04-09 |
| CVE-2024-29052 | Windows Storage Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2024-04-09 |
| CVE-2024-29061 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.8 | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-31755 | cJSON v1.7.17 was discovered to contain a segmentation violation which can trigger through the second parameter of funct | HIGH | 7.6 | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-27316 | Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames | HIGH | 7.5 | 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-31744 | In Jasper 4.2.2 the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerab | HIGH | 7.5 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-32650 | Rustls vulnerable to an infinite loop in rustls::conn::ConnectionCommon::complete_io() with proper client input | HIGH | 7.5 | 58%ile | Microsoft | 2024-04-09 |
| CVE-2023-45288 | HTTP/2 CONTINUATION flood in net/http | HIGH | 7.5 | 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-21090 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that ar | HIGH | 7.5 | 50%ile | Microsoft | 2024-04-09 |
| CVE-2024-3858 | It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects F | HIGH | 7.5 | 44%ile | Microsoft | 2024-04-09 |
| CVE-2024-20380 | ClamAV HTML Parser Denial of Service Vulnerability | HIGH | 7.5 | 62%ile | Microsoft | 2024-04-09 |
| CVE-2024-22189 | QUIC's Connection ID Mechanism vulnerable to Memory Exhaustion Attack | HIGH | 7.5 | 63%ile | Microsoft | 2024-04-09 |
| CVE-2024-2757 | PHP mb_encode_mimeheader runs endlessly for some inputs | HIGH | 7.5 | 78%ile | Microsoft | 2024-04-09 |
| CVE-2024-34088 | In FRRouting (FRR) through 9.1 it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NU | HIGH | 7.5 | 49%ile | Microsoft | 2024-04-09 |
| CVE-2024-31578 | FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function. | HIGH | 7.5 | 58%ile | Microsoft | 2024-04-09 |
| CVE-2024-26254 | Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability | HIGH | 7.5 | 87%ile | Microsoft | 2024-04-09 |
| CVE-2024-28896 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.5 | 58%ile | Microsoft | 2024-04-09 |
| CVE-2024-29045 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | HIGH | 7.5 | 76%ile | Microsoft | 2024-04-09 |
| CVE-2024-26219 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 87%ile | Microsoft | 2024-04-09 |
| CVE-2024-26248 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 7.5 | 60%ile | Microsoft | 2024-04-09 |
| CVE-2024-26212 | DHCP Server Service Denial of Service Vulnerability | HIGH | 7.5 | 99%ile | Microsoft | 2024-04-09 |
| CVE-2024-26215 | DHCP Server Service Denial of Service Vulnerability | HIGH | 7.5 | 84%ile | Microsoft | 2024-04-09 |
| CVE-2022-1708 | CVE-2022-1708 | HIGH | 7.5 | 86%ile | Microsoft | 2024-04-09 |
| CVE-2022-27649 | CVE-2022-27649 | HIGH | 7.5 | 70%ile | Microsoft | 2024-04-09 |
| CVE-2023-42821 | CVE-2023-42821 | HIGH | 7.5 | 61%ile | Microsoft | 2024-04-09 |
| CVE-2022-38178 | CVE-2022-38178 | HIGH | 7.5 | 83%ile | Microsoft | 2024-04-09 |
| CVE-2022-38177 | CVE-2022-38177 | HIGH | 7.5 | 84%ile | Microsoft | 2024-04-09 |
| CVE-2022-48666 | scsi: core: Fix a use-after-free | HIGH | 7.4 | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-26194 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.4 | 28%ile | Microsoft | 2024-04-09 |
| CVE-2024-31080 | Xorg-x11-server: heap buffer overread/data leakage in procxigetselectedevents | HIGH | 7.3 | 41%ile | Microsoft | 2024-04-09 |
| CVE-2023-38709 | Apache HTTP Server: HTTP response splitting | HIGH | 7.3 | 89%ile | Microsoft | 2024-04-09 |
| CVE-2024-31081 | Xorg-x11-server: heap buffer overread/data leakage in procxipassivegrabdevice | HIGH | 7.3 | 41%ile | Microsoft | 2024-04-09 |
| CVE-2024-31082 | Xorg-x11-server: heap buffer overread/data leakage in procappledricreatepixmap | HIGH | 7.3 | 26%ile | Microsoft | 2024-04-09 |
| CVE-2024-2961 | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 | HIGH | 7.3 | 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-26232 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 7.3 | 57%ile | Microsoft | 2024-04-09 |
| CVE-2024-29063 | Azure AI Search Information Disclosure Vulnerability | HIGH | 7.3 | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-26216 | Windows File Server Resource Management Service Elevation of Privilege Vulnerability | HIGH | 7.3 | 55%ile | Microsoft | 2024-04-09 |
| CVE-2024-21409 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | HIGH | 7.3 | 83%ile | Microsoft | 2024-04-09 |
| CVE-2024-3154 | Cri-o: arbitrary command injection via pod annotation | HIGH | 7.2 | 70%ile | Microsoft | 2024-04-09 |
| CVE-2024-29066 | Windows Distributed File System (DFS) Remote Code Execution Vulnerability | HIGH | 7.2 | 69%ile | Microsoft | 2024-04-09 |
| CVE-2024-21322 | Microsoft Defender for IoT Remote Code Execution Vulnerability | HIGH | 7.2 | 86%ile | Microsoft | 2024-04-09 |
| CVE-2024-21324 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | HIGH | 7.2 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-26195 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 7.2 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-26202 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 7.2 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-26221 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.2 | 77%ile | Microsoft | 2024-04-09 |
| CVE-2024-26222 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.2 | 76%ile | Microsoft | 2024-04-09 |
| CVE-2024-26223 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.2 | 73%ile | Microsoft | 2024-04-09 |
| CVE-2024-26224 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.2 | 73%ile | Microsoft | 2024-04-09 |
| CVE-2024-26227 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.2 | 72%ile | Microsoft | 2024-04-09 |
| CVE-2024-26231 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.2 | 72%ile | Microsoft | 2024-04-09 |
| CVE-2024-26233 | Windows DNS Server Remote Code Execution Vulnerability | HIGH | 7.2 | 73%ile | Microsoft | 2024-04-09 |
| CVE-2024-26208 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH | 7.2 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2024-29055 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | HIGH | 7.2 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-29054 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | HIGH | 7.2 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-26672 | drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()' | HIGH | 7.1 | 12%ile | Microsoft | 2024-04-09 |
| CVE-2024-26669 | net/sched: flower: Fix chain template offload | HIGH | 7.1 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26789 | crypto: arm64/neonbs - fix out-of-bounds access on short input | HIGH | 7.1 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-20688 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.1 | 67%ile | Microsoft | 2024-04-09 |
| CVE-2024-20689 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.1 | 67%ile | Microsoft | 2024-04-09 |
| CVE-2024-29062 | Secure Boot Security Feature Bypass Vulnerability | HIGH | 7.1 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2022-2995 | CVE-2022-2995 | HIGH | 7.1 | 29%ile | Microsoft | 2024-04-09 |
| CVE-2024-26243 | Windows USB Print Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 32%ile | Microsoft | 2024-04-09 |
| CVE-2024-26236 | Windows Update Stack Elevation of Privilege Vulnerability | HIGH | 7.0 | 32%ile | Microsoft | 2024-04-09 |
| CVE-2024-26242 | Windows Telephony Server Elevation of Privilege Vulnerability | HIGH | 7.0 | 27%ile | Microsoft | 2024-04-09 |
| CVE-2024-26213 | Microsoft Brokering File System Elevation of Privilege Vulnerability | HIGH | 7.0 | 44%ile | Microsoft | 2024-04-09 |
| CVE-2024-26252 | Windows rndismp6.sys Remote Code Execution Vulnerability | MEDIUM | 6.8 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-26253 | Windows rndismp6.sys Remote Code Execution Vulnerability | MEDIUM | 6.8 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-26168 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 58%ile | Microsoft | 2024-04-09 |
| CVE-2024-26251 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.8 | 70%ile | Microsoft | 2024-04-09 |
| CVE-2024-28897 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 55%ile | Microsoft | 2024-04-09 |
| CVE-2022-27651 | CVE-2022-27651 | MEDIUM | 6.8 | 66%ile | Microsoft | 2024-04-09 |
| CVE-2024-26828 | cifs: fix underflow in parse_server_interfaces() | MEDIUM | 6.7 | 34%ile | Microsoft | 2024-04-09 |
| CVE-2024-2312 | GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI syst | MEDIUM | 6.7 | 30%ile | Microsoft | 2024-04-09 |
| CVE-2024-20669 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 46%ile | Microsoft | 2024-04-09 |
| CVE-2024-26250 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 47%ile | Microsoft | 2024-04-09 |
| CVE-2024-28921 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-28919 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 46%ile | Microsoft | 2024-04-09 |
| CVE-2024-28903 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-23593 | Lenovo: CVE-2024-23593 Modify Boot Manager and Escalate Privileges | MEDIUM | 6.7 | 26%ile | Microsoft | 2024-04-09 |
| CVE-2024-26171 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 47%ile | Microsoft | 2024-04-09 |
| CVE-2024-26234 | Proxy Driver Spoofing Vulnerability | MEDIUM | 6.7 | 91%ile | Microsoft | 2024-04-09 |
| CVE-2024-28924 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.7 | 44%ile | Microsoft | 2024-04-09 |
| CVE-2022-26691 | CVE-2022-26691 | MEDIUM | 6.7 | 45%ile | Microsoft | 2024-04-09 |
| CVE-2024-2756 | __Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix | MEDIUM | 6.5 | 98%ile | Microsoft | 2024-04-09 |
| CVE-2024-31950 | In FRRouting (FRR) through 9.1 there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets | MEDIUM | 6.5 | 41%ile | Microsoft | 2024-04-09 |
| CVE-2024-3652 | IKEv1 default AH/ESP responder can cause libreswan to abort and restart | MEDIUM | 6.5 | 53%ile | Microsoft | 2024-04-09 |
| CVE-2024-3096 | PHP function password_verify can erroneously return true when argument contains NUL | MEDIUM | 6.5 | 71%ile | Microsoft | 2024-04-09 |
| CVE-2024-31951 | In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1 there can be a buffer overflow and daemon crash in | MEDIUM | 6.5 | 43%ile | Microsoft | 2024-04-09 |
| CVE-2024-26886 | Bluetooth: af_bluetooth: Fix deadlock | MEDIUM | 6.5 | 40%ile | Microsoft | 2024-04-09 |
| CVE-2024-21424 | Azure Compute Gallery Elevation of Privilege Vulnerability | MEDIUM | 6.5 | 78%ile | Microsoft | 2024-04-09 |
| CVE-2024-26183 | Windows Kerberos Denial of Service Vulnerability | MEDIUM | 6.5 | 80%ile | Microsoft | 2024-04-09 |
| CVE-2024-26226 | Windows Distributed File System (DFS) Information Disclosure Vulnerability | MEDIUM | 6.5 | 76%ile | Microsoft | 2024-04-09 |
| CVE-2024-29987 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | MEDIUM | 6.5 | 65%ile | Microsoft | 2024-04-09 |
| CVE-2024-26875 | media: pvrusb2: fix uaf in pvr2_context_set_notify | MEDIUM | 6.4 | 16%ile | Microsoft | 2024-04-09 |
| CVE-2024-32884 | gix-transport indirect code execution via malicious username | MEDIUM | 6.4 | 41%ile | Microsoft | 2024-04-09 |
| CVE-2024-26193 | Azure Migrate Remote Code Execution Vulnerability | MEDIUM | 6.4 | 55%ile | Microsoft | 2024-04-09 |
| CVE-2024-23594 | Lenovo: CVE-2024-23594 Stack buffer overflow in Lenovo system recovery boot manager | MEDIUM | 6.4 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26830 | i40e: Do not allow untrusted VF to remove administratively set MAC | MEDIUM | 6.3 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-24795 | Apache HTTP Server: HTTP Response Splitting in multiple modules | MEDIUM | 6.3 | 85%ile | Microsoft | 2024-04-09 |
| CVE-2024-28898 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 6.3 | 54%ile | Microsoft | 2024-04-09 |
| CVE-2022-48646 | sfc/siena: fix null pointer dereference in efx_hard_start_xmit | MEDIUM | 6.2 | 10%ile | Microsoft | 2024-04-09 |
| CVE-2024-3860 | An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently tra | MEDIUM | 6.2 | 7%ile | Microsoft | 2024-04-09 |
| CVE-2022-48635 | fsdax: Fix infinite loop in dax_iomap_rw() | MEDIUM | 6.2 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-2905 | Rpm-ostree: world-readable /etc/shadow file | MEDIUM | 6.2 | 25%ile | Microsoft | 2024-04-09 |
| CVE-2024-29064 | Windows Hyper-V Denial of Service Vulnerability | MEDIUM | 6.2 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-28917 | Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | MEDIUM | 6.2 | 56%ile | Microsoft | 2024-04-09 |
| CVE-2024-27306 | aiohttp vulnerable to XSS on index pages for static file handling | MEDIUM | 6.1 | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-20665 | BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.1 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2023-6237 | Excessive time spent checking invalid RSA public keys | MEDIUM | 5.9 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-2511 | Unbounded memory growth with session handling in TLSv1.3 | MEDIUM | 5.9 | 99%ile | Microsoft | 2024-04-09 |
| CVE-2024-31852 | LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack and | MEDIUM | 5.9 | 59%ile | Microsoft | 2024-04-09 |
| CVE-2024-3859 | On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by | MEDIUM | 5.9 | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-20685 | Azure Private 5G Core Denial of Service Vulnerability | MEDIUM | 5.9 | 92%ile | Microsoft | 2024-04-09 |
| CVE-2024-26901 | do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak | MEDIUM | 5.5 | 54%ile | Microsoft | 2024-04-09 |
| CVE-2024-26811 | ksmbd: validate payload size in ipc response | MEDIUM | 5.5 | 18%ile | Microsoft | 2024-04-09 |
| CVE-2024-26687 | xen/events: close evtchn after mapping cleanup | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-3567 | Qemu-kvm: net: assertion failure in update_sctp_checksum() | MEDIUM | 5.5 | 37%ile | Microsoft | 2024-04-09 |
| CVE-2024-26841 | LoongArch: Update cpu_sibling_map when disabling nonboot CPUs | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26853 | igc: avoid returning frame twice in XDP_REDIRECT | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26662 | drm/amd/display: Fix 'panel_cntl' could be null in 'dcn21_set_backlight_level()' | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26757 | md: Don't ignore read-only array in md_check_recovery() | MEDIUM | 5.5 | 11%ile | Microsoft | 2024-04-09 |
| CVE-2024-26758 | md: Don't ignore suspended array in md_check_recovery() | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-04-09 |
| CVE-2024-26893 | firmware: arm_scmi: Fix double free in SMC transport cleanup path | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-26866 | spi: lpspi: Avoid potential use-after-free in probe() | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-04-09 |
| CVE-2024-26677 | rxrpc: Fix delayed ACKs to not set the reference serial number | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26770 | HID: nvidia-shield: Add missing null pointer checks to LED initialization | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26714 | interconnect: qcom: sc8180x: Mark CO0 BCM keepalive | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2023-52634 | drm/amd/display: Fix disable_otg_wa logic | MEDIUM | 5.5 | 9%ile | Microsoft | 2024-04-09 |
| CVE-2024-26756 | md: Don't register sync_thread for reshape directly | MEDIUM | 5.5 | 11%ile | Microsoft | 2024-04-09 |
| CVE-2024-26740 | net/sched: act_mirred: use the backlog for mirred ingress | MEDIUM | 5.5 | 8%ile | Microsoft | 2024-04-09 |
| CVE-2024-26726 | btrfs: don't drop extent_map for free space inode on write error | MEDIUM | 5.5 | 17%ile | Microsoft | 2024-04-09 |
| CVE-2024-26759 | mm/swap: fix race when skipping swapcache | MEDIUM | 5.5 | 17%ile | Microsoft | 2024-04-09 |
| CVE-2023-52632 | drm/amdkfd: Fix lock dependency warning with srcu | MEDIUM | 5.5 | 6%ile | Microsoft | 2024-04-09 |
| CVE-2024-26765 | LoongArch: Disable IRQ before init_fn() for nonboot CPUs | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26767 | drm/amd/display: fixed integer types and null check locations | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26896 | wifi: wfx: fix memory leak when starting AP | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26775 | aoe: avoid potential deadlock at set_capacity | MEDIUM | 5.5 | 8%ile | Microsoft | 2024-04-09 |
| CVE-2024-26881 | net: hns3: fix kernel crash when 1588 is received on HIP08 devices | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-26900 | md: fix kmemleak of rdev->serial | MEDIUM | 5.5 | 21%ile | Microsoft | 2024-04-09 |
| CVE-2024-26902 | perf: RISCV: Fix panic on pmu overflow handler | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26903 | Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security | MEDIUM | 5.5 | 20%ile | Microsoft | 2024-04-09 |
| CVE-2024-26909 | soc: qcom: pmic_glink_altmode: fix drm bridge use-after-free | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-31584 | Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader. | MEDIUM | 5.5 | 31%ile | Microsoft | 2024-04-09 |
| CVE-2024-27437 | vfio/pci: Disable auto-enable of exclusive INTx IRQ | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26812 | vfio/pci: Create persistent INTx handler | MEDIUM | 5.5 | 15%ile | Microsoft | 2024-04-09 |
| CVE-2024-26718 | dm-crypt, dm-verity: disable tasklets | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26785 | iommufd: Fix protection fault in iommufd_test_syz_conv_iova | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-26686 | fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats | MEDIUM | 5.5 | 12%ile | Microsoft | 2024-04-09 |
| CVE-2024-26656 | drm/amdgpu: fix use-after-free bug | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26661 | drm/amd/display: Add NULL test for 'timing generator' in 'dcn21_set_pipe()' | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26706 | parisc: Fix random data corruption from exception handler | MEDIUM | 5.5 | 17%ile | Microsoft | 2024-04-09 |
| CVE-2024-26680 | net: atlantic: Fix DMA mapping for PTP hwts ring | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-26691 | KVM: arm64: Fix circular locking dependency | MEDIUM | 5.5 | 8%ile | Microsoft | 2024-04-09 |
| CVE-2024-26920 | tracing/trigger: Fix to return error if failed to alloc snapshot | MEDIUM | 5.5 | 17%ile | Microsoft | 2024-04-09 |
| CVE-2024-26700 | drm/amd/display: Fix MST Null Ptr for RV | MEDIUM | 5.5 | 14%ile | Microsoft | 2024-04-09 |
| CVE-2024-26719 | nouveau: offload fence uevents work to workqueue | MEDIUM | 5.5 | 7%ile | Microsoft | 2024-04-09 |
| CVE-2024-26876 | drm/bridge: adv7511: fix crash on irq during probe | MEDIUM | 5.5 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-26255 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-26172 | Windows DWM Core Library Information Disclosure Vulnerability | MEDIUM | 5.5 | 50%ile | Microsoft | 2024-04-09 |
| CVE-2024-28901 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 49%ile | Microsoft | 2024-04-09 |
| CVE-2024-28902 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-26209 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | MEDIUM | 5.5 | 96%ile | Microsoft | 2024-04-09 |
| CVE-2024-26207 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-26217 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 49%ile | Microsoft | 2024-04-09 |
| CVE-2024-28900 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 49%ile | Microsoft | 2024-04-09 |
| CVE-2024-29992 | Azure Identity Library for .NET Information Disclosure Vulnerability | MEDIUM | 5.5 | 50%ile | Microsoft | 2024-04-09 |
| CVE-2021-3602 | CVE-2021-3602 | MEDIUM | 5.5 | 25%ile | Microsoft | 2024-04-09 |
| CVE-2024-29986 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | MEDIUM | 5.4 | 41%ile | Microsoft | 2024-04-09 |
| CVE-2024-0874 | Coredns: cd bit response is cached and served later | MEDIUM | 5.3 | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-28182 | Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage | MEDIUM | 5.3 | 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-24856 | NULL pointer deference in acpi_db_convert_to_package of Linux acpi module | MEDIUM | 5.3 | 7%ile | Microsoft | 2024-04-09 |
| CVE-2022-2795 | CVE-2022-2795 | MEDIUM | 5.3 | 75%ile | Microsoft | 2024-04-09 |
| CVE-2024-26220 | Windows Mobile Hotspot Information Disclosure Vulnerability | MEDIUM | 5.0 | 63%ile | Microsoft | 2024-04-09 |
| CVE-2024-29991 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | MEDIUM | 5.0 | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-21096 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a | MEDIUM | 4.9 | 35%ile | Microsoft | 2024-04-09 |
| CVE-2024-26837 | net: bridge: switchdev: Skip MDB replays of deferred events on offload | MEDIUM | 4.7 | 6%ile | Microsoft | 2024-04-09 |
| CVE-2024-26869 | f2fs: fix to truncate meta inode pages forcely | MEDIUM | 4.7 | 7%ile | Microsoft | 2024-04-09 |
| CVE-2023-52639 | KVM: s390: vsie: fix race during shadow creation | MEDIUM | 4.7 | 7%ile | Microsoft | 2024-04-09 |
| CVE-2024-26671 | blk-mq: fix IO hang from sbitmap wakeup race | MEDIUM | 4.7 | 8%ile | Microsoft | 2024-04-09 |
| CVE-2022-0001 | Intel: CVE-2022-0001 Branch History Injection | MEDIUM | 4.7 | 41%ile | Microsoft | 2024-04-09 |
| CVE-2021-3636 | CVE-2021-3636 | MEDIUM | 4.6 | 21%ile | Microsoft | 2024-04-09 |
| CVE-2024-30260 | Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch request stream pipeline | MEDIUM | 4.3 | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-29981 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | MEDIUM | 4.3 | 50%ile | Microsoft | 2024-04-09 |
| CVE-2024-29056 | Windows Authentication Elevation of Privilege Vulnerability | MEDIUM | 4.3 | 60%ile | Microsoft | 2024-04-09 |
| CVE-2024-28922 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM | 4.1 | 50%ile | Microsoft | 2024-04-09 |
| CVE-2024-29049 | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | MEDIUM | 4.1 | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-31580 | PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_fu | MEDIUM | 4.0 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-3861 | If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and l | MEDIUM | 4.0 | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-3302 | There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to cre | LOW | 3.7 | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-30261 | Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect | LOW | 3.5 | 53%ile | Microsoft | 2024-04-09 |
| CVE-2022-48667 | smb3: fix temporary data corruption in insert range | LOW | 3.3 | 9%ile | Microsoft | 2024-04-09 |
| CVE-2022-48668 | smb3: fix temporary data corruption in collapse range | LOW | 3.3 | 9%ile | Microsoft | 2024-04-09 |
| CVE-2024-3177 | Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin | LOW | 2.7 | 81%ile | Microsoft | 2024-04-09 |
| CVE-2022-48633 | drm/gma500: Fix WARN_ON(lock->magic != lock) error | LOW | 2.3 | 9%ile | Microsoft | 2024-04-09 |
| CVE-2024-26904 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | Microsoft | 2024-04-09 |
| CVE-2024-26908 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | Microsoft | 2024-04-09 |
| CVE-2024-26814 | vfio/fsl-mc: Block calling interrupt handler without trigger | UNKNOWN | — | 13%ile | Microsoft | 2024-04-09 |
| CVE-2024-21506 | Rejected reason: Duplicate of CVE-2024-5629. | UNKNOWN | — | — | Microsoft | 2024-04-09 |
| CVE-2024-3156 | Chromium: CVE-2024-3156 Inappropriate implementation in V8 | UNKNOWN | — | 96%ile | Microsoft | 2024-04-09 |
| CVE-2024-3158 | Chromium: CVE-2024-3158 Use after free in Bookmarks | UNKNOWN | — | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-3159 | Chromium: CVE-2024-3159 Out of bounds memory access in V8 | UNKNOWN | — | 73%ile | Microsoft | 2024-04-09 |
| CVE-2024-3157 | Chromium: CVE-2024-3157 Out of bounds write in Compositing | UNKNOWN | — | 54%ile | Microsoft | 2024-04-09 |
| CVE-2024-3515 | Chromium: CVE-2024-3515 Use after free in Dawn | UNKNOWN | — | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-3516 | Chromium: CVE-2024-3516 Heap buffer overflow in ANGLE | UNKNOWN | — | 59%ile | Microsoft | 2024-04-09 |
| CVE-2024-3832 | Chromium: CVE-2024-3832 Object corruption in V8 | UNKNOWN | — | 66%ile | Microsoft | 2024-04-09 |
| CVE-2024-3914 | Chromium: CVE-2024-3914 Use after free in V8 | UNKNOWN | — | 60%ile | Microsoft | 2024-04-09 |
| CVE-2024-3833 | Chromium: CVE-2024-3833 Object corruption in WebAssembly | UNKNOWN | — | 96%ile | Microsoft | 2024-04-09 |
| CVE-2024-3834 | Chromium: CVE-2024-3834 Use after free in Downloads | UNKNOWN | — | 60%ile | Microsoft | 2024-04-09 |
| CVE-2024-3837 | Chromium: CVE-2024-3837 Use after free in QUIC | UNKNOWN | — | 58%ile | Microsoft | 2024-04-09 |
| CVE-2024-3838 | Chromium: CVE-2024-3838 Inappropriate implementation in Autofill | UNKNOWN | — | 29%ile | Microsoft | 2024-04-09 |
| CVE-2024-3839 | Chromium: CVE-2024-3839 Out of bounds read in Fonts | UNKNOWN | — | 49%ile | Microsoft | 2024-04-09 |
| CVE-2024-3840 | Chromium: CVE-2024-3840 Insufficient policy enforcement in Site Isolation | UNKNOWN | — | 51%ile | Microsoft | 2024-04-09 |
| CVE-2024-3844 | Chromium: CVE-2024-3844 Inappropriate implementation in Extensions | UNKNOWN | — | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-3841 | Chromium: CVE-2024-3841 Insufficient data validation in Browser Switcher | UNKNOWN | — | 48%ile | Microsoft | 2024-04-09 |
| CVE-2024-3845 | Chromium: CVE-2024-3845 Inappropriate implementation in Network | UNKNOWN | — | 52%ile | Microsoft | 2024-04-09 |
| CVE-2024-3843 | Chromium: CVE-2024-3843 Insufficient data validation in Downloads | UNKNOWN | — | 44%ile | Microsoft | 2024-04-09 |
| CVE-2024-3847 | Chromium: CVE-2024-3847 Insufficient policy enforcement in WebUI | UNKNOWN | — | 53%ile | Microsoft | 2024-04-09 |
| CVE-2024-3846 | Chromium: CVE-2024-3846 Inappropriate implementation in Prompts | UNKNOWN | — | 50%ile | Microsoft | 2024-04-09 |
| CVE-2024-4058 | Chromium: CVE-2024-4058 Type Confusion in ANGLE | UNKNOWN | — | 95%ile | Microsoft | 2024-04-09 |
| CVE-2024-4060 | Chromium: CVE-2024-4060 Use after free in Dawn | UNKNOWN | — | 60%ile | Microsoft | 2024-04-09 |
| CVE-2024-4059 | Chromium: CVE-2024-4059 Out of bounds read in V8 API | UNKNOWN | — | 56%ile | Microsoft | 2024-04-09 |
| CVE-2024-28923 | Secure Boot Security Feature Bypass Vulnerability | UNKNOWN | — | 39%ile | Microsoft | 2024-04-09 |
| CVE-2022-24963 | Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions | CRITICAL | 9.8 | 71%ile | Microsoft | 2023-01-10 |
| CVE-2022-4338 | An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch. | CRITICAL | 9.8 | 68%ile | Microsoft | 2023-01-10 |
| CVE-2022-3515 | A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can | CRITICAL | 9.8 | 74%ile | Microsoft | 2023-01-10 |
| CVE-2022-41903 | Integer overflow in `git archive` `git log --format` leading to RCE in git | CRITICAL | 9.8 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2022-4337 | An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch. | CRITICAL | 9.8 | 68%ile | Microsoft | 2023-01-10 |
| CVE-2022-47629 | CVE-2022-47629 | CRITICAL | 9.8 | 73%ile | Microsoft | 2023-01-10 |
| CVE-2022-36760 | Apache HTTP Server: mod_proxy_ajp Possible request smuggling | CRITICAL | 9.0 | 77%ile | Microsoft | 2023-01-10 |
| CVE-2022-2196 | Speculative execution attacks in KVM VMX | HIGH | 8.8 | 21%ile | Microsoft | 2023-01-10 |
| CVE-2023-21549 | Windows SMB Witness Service Elevation of Privilege Vulnerability | HIGH | 8.8 | 70%ile | Microsoft | 2023-01-10 |
| CVE-2023-21674 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | HIGH | 8.8 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2023-21676 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | HIGH | 8.8 | 72%ile | Microsoft | 2023-01-10 |
| CVE-2023-21681 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | HIGH | 8.8 | 69%ile | Microsoft | 2023-01-10 |
| CVE-2023-21732 | Microsoft ODBC Driver Remote Code Execution Vulnerability | HIGH | 8.8 | 69%ile | Microsoft | 2023-01-10 |
| CVE-2023-21742 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2023-21744 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 85%ile | Microsoft | 2023-01-10 |
| CVE-2023-21796 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | HIGH | 8.3 | 59%ile | Microsoft | 2023-01-10 |
| CVE-2023-21775 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH | 8.3 | 59%ile | Microsoft | 2023-01-10 |
| CVE-2023-21795 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | HIGH | 8.3 | 56%ile | Microsoft | 2023-01-10 |
| CVE-2023-21712 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | HIGH | 8.1 | 59%ile | Microsoft | 2023-01-10 |
| CVE-2023-21535 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | HIGH | 8.1 | 62%ile | Microsoft | 2023-01-10 |
| CVE-2023-21546 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | HIGH | 8.1 | 62%ile | Microsoft | 2023-01-10 |
| CVE-2023-21543 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | HIGH | 8.1 | 75%ile | Microsoft | 2023-01-10 |
| CVE-2023-21548 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | HIGH | 8.1 | 62%ile | Microsoft | 2023-01-10 |
| CVE-2023-21555 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | HIGH | 8.1 | 62%ile | Microsoft | 2023-01-10 |
| CVE-2023-21556 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | HIGH | 8.1 | 71%ile | Microsoft | 2023-01-10 |
| CVE-2023-21679 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | HIGH | 8.1 | 62%ile | Microsoft | 2023-01-10 |
| CVE-2022-47943 | CVE-2022-47943 | HIGH | 8.1 | 88%ile | Microsoft | 2023-01-10 |
| CVE-2022-47940 | CVE-2022-47940 | HIGH | 8.1 | 70%ile | Microsoft | 2023-01-10 |
| CVE-2023-21762 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.0 | 73%ile | Microsoft | 2023-01-10 |
| CVE-2023-21745 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.0 | 72%ile | Microsoft | 2023-01-10 |
| CVE-2023-0051 | Heap-based Buffer Overflow in vim/vim | HIGH | 7.8 | 41%ile | Microsoft | 2023-01-10 |
| CVE-2023-0288 | Heap-based Buffer Overflow in vim/vim | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2023-0512 | Divide By Zero in vim/vim | HIGH | 7.8 | 40%ile | Microsoft | 2023-01-10 |
| CVE-2022-3650 | A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root | HIGH | 7.8 | 25%ile | Microsoft | 2023-01-10 |
| CVE-2022-41953 | Git clone remote code execution vulnerability in git-for-windows | HIGH | 7.8 | 93%ile | Microsoft | 2023-01-10 |
| CVE-2018-25078 | man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because / | HIGH | 7.8 | 31%ile | Microsoft | 2023-01-10 |
| CVE-2022-45639 | OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a cra | HIGH | 7.8 | 91%ile | Microsoft | 2023-01-10 |
| CVE-2022-47021 | A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 | HIGH | 7.8 | 32%ile | Microsoft | 2023-01-10 |
| CVE-2023-0049 | Out-of-bounds Read in vim/vim | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2023-0054 | Out-of-bounds Write in vim/vim | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2023-0266 | Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel | HIGH | 7.8 | 89%ile | Microsoft | 2023-01-10 |
| CVE-2023-0433 | Heap-based Buffer Overflow in vim/vim | HIGH | 7.8 | 43%ile | Microsoft | 2023-01-10 |
| CVE-2023-23559 | In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5 there is an integer overflow i | HIGH | 7.8 | 22%ile | Microsoft | 2023-01-10 |
| CVE-2023-22809 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen | HIGH | 7.8 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2022-4139 | An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memor | HIGH | 7.8 | 17%ile | Microsoft | 2023-01-10 |
| CVE-2022-3715 | A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue ma | HIGH | 7.8 | 28%ile | Microsoft | 2023-01-10 |
| CVE-2022-4378 | A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters a | HIGH | 7.8 | 36%ile | Microsoft | 2023-01-10 |
| CVE-2022-4696 | There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If | HIGH | 7.8 | 33%ile | Microsoft | 2023-01-10 |
| CVE-2023-21552 | Windows GDI Elevation of Privilege Vulnerability | HIGH | 7.8 | 88%ile | Microsoft | 2023-01-10 |
| CVE-2023-21524 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | HIGH | 7.8 | 33%ile | Microsoft | 2023-01-10 |
| CVE-2023-21541 | Windows Task Scheduler Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21551 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2023-01-10 |
| CVE-2023-21558 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2023-21561 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 36%ile | Microsoft | 2023-01-10 |
| CVE-2023-21678 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21680 | Windows Win32k Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2023-01-10 |
| CVE-2023-21724 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2023-01-10 |
| CVE-2023-21726 | Windows Credential Manager User Interface Elevation of Privilege Vulnerability | HIGH | 7.8 | 39%ile | Microsoft | 2023-01-10 |
| CVE-2023-21730 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 41%ile | Microsoft | 2023-01-10 |
| CVE-2023-21734 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21735 | Microsoft Office Remote Code Execution Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-21736 | Microsoft Office Visio Remote Code Execution Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-21737 | Microsoft Office Visio Remote Code Execution Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-21738 | Microsoft Office Visio Remote Code Execution Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-21746 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 7.8 | 83%ile | Microsoft | 2023-01-10 |
| CVE-2023-21747 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 54%ile | Microsoft | 2023-01-10 |
| CVE-2023-21748 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 54%ile | Microsoft | 2023-01-10 |
| CVE-2023-21749 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 53%ile | Microsoft | 2023-01-10 |
| CVE-2023-21754 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2023-21755 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 40%ile | Microsoft | 2023-01-10 |
| CVE-2023-21763 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 45%ile | Microsoft | 2023-01-10 |
| CVE-2023-21764 | Microsoft Exchange Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21765 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2023-21767 | Windows Overlay Filter Elevation of Privilege Vulnerability | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2023-21768 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2023-21772 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-21773 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-21774 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-21781 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21782 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 58%ile | Microsoft | 2023-01-10 |
| CVE-2023-21784 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 58%ile | Microsoft | 2023-01-10 |
| CVE-2023-21786 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21791 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21793 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21537 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | HIGH | 7.8 | 42%ile | Microsoft | 2023-01-10 |
| CVE-2023-21675 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 54%ile | Microsoft | 2023-01-10 |
| CVE-2023-21779 | Visual Studio Code Remote Code Execution Vulnerability | HIGH | 7.8 | 81%ile | Microsoft | 2023-01-10 |
| CVE-2023-21783 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 62%ile | Microsoft | 2023-01-10 |
| CVE-2023-21785 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21787 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21788 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21789 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21790 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 57%ile | Microsoft | 2023-01-10 |
| CVE-2023-21792 | 3D Builder Remote Code Execution Vulnerability | HIGH | 7.8 | 58%ile | Microsoft | 2023-01-10 |
| CVE-2022-25881 | This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request | HIGH | 7.5 | 74%ile | Microsoft | 2023-01-10 |
| CVE-2022-3094 | An UPDATE message flood may cause named to exhaust all available memory | HIGH | 7.5 | 96%ile | Microsoft | 2023-01-10 |
| CVE-2022-3924 | named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota | HIGH | 7.5 | 97%ile | Microsoft | 2023-01-10 |
| CVE-2022-41860 | In freeradius when an EAP-SIM supplicant sends an unknown SIM option the server will try to look that option up in the i | HIGH | 7.5 | 64%ile | Microsoft | 2023-01-10 |
| CVE-2022-25927 | Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regul | HIGH | 7.5 | 75%ile | Microsoft | 2023-01-10 |
| CVE-2023-22895 | The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an int | HIGH | 7.5 | 66%ile | Microsoft | 2023-01-10 |
| CVE-2022-25882 | Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tenso | HIGH | 7.5 | 74%ile | Microsoft | 2023-01-10 |
| CVE-2022-3736 | named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries | HIGH | 7.5 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2022-38725 | An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a | HIGH | 7.5 | 82%ile | Microsoft | 2023-01-10 |
| CVE-2022-41721 | Request smuggling due to improper request handling in golang.org/x/net/http2/h2c | HIGH | 7.5 | 76%ile | Microsoft | 2023-01-10 |
| CVE-2022-4379 | A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allow | HIGH | 7.5 | 93%ile | Microsoft | 2023-01-10 |
| CVE-2023-21538 | .NET Denial of Service Vulnerability | HIGH | 7.5 | 85%ile | Microsoft | 2023-01-10 |
| CVE-2023-21547 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | HIGH | 7.5 | 100%ile | Microsoft | 2023-01-10 |
| CVE-2023-21539 | Windows Authentication Remote Code Execution Vulnerability | HIGH | 7.5 | 64%ile | Microsoft | 2023-01-10 |
| CVE-2023-21557 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | HIGH | 7.5 | 79%ile | Microsoft | 2023-01-10 |
| CVE-2023-21677 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | HIGH | 7.5 | 78%ile | Microsoft | 2023-01-10 |
| CVE-2023-21683 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | HIGH | 7.5 | 78%ile | Microsoft | 2023-01-10 |
| CVE-2023-21728 | Windows Netlogon Denial of Service Vulnerability | HIGH | 7.5 | 78%ile | Microsoft | 2023-01-10 |
| CVE-2023-21757 | Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability | HIGH | 7.5 | 79%ile | Microsoft | 2023-01-10 |
| CVE-2023-21758 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | HIGH | 7.5 | 100%ile | Microsoft | 2023-01-10 |
| CVE-2023-21761 | Microsoft Exchange Server Information Disclosure Vulnerability | HIGH | 7.5 | 73%ile | Microsoft | 2023-01-10 |
| CVE-2023-21527 | Windows iSCSI Service Denial of Service Vulnerability | HIGH | 7.5 | 78%ile | Microsoft | 2023-01-10 |
| CVE-2022-48285 | loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive. | HIGH | 7.3 | 70%ile | Microsoft | 2023-01-10 |
| CVE-2022-41858 | A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach | HIGH | 7.1 | 20%ile | Microsoft | 2023-01-10 |
| CVE-2023-21741 | Microsoft Office Visio Information Disclosure Vulnerability | HIGH | 7.1 | 76%ile | Microsoft | 2023-01-10 |
| CVE-2023-21750 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.1 | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-21752 | Windows Backup Service Elevation of Privilege Vulnerability | HIGH | 7.1 | 92%ile | Microsoft | 2023-01-10 |
| CVE-2023-21760 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH | 7.1 | 42%ile | Microsoft | 2023-01-10 |
| CVE-2023-21531 | Azure Service Fabric Container Elevation of Privilege Vulnerability | HIGH | 7.0 | 46%ile | Microsoft | 2023-01-10 |
| CVE-2023-21542 | Windows Installer Elevation of Privilege Vulnerability | HIGH | 7.0 | 20%ile | Microsoft | 2023-01-10 |
| CVE-2023-21733 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 21%ile | Microsoft | 2023-01-10 |
| CVE-2023-21739 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | HIGH | 7.0 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21771 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | HIGH | 7.0 | 32%ile | Microsoft | 2023-01-10 |
| CVE-2023-21532 | Windows GDI Elevation of Privilege Vulnerability | HIGH | 7.0 | 37%ile | Microsoft | 2023-01-10 |
| CVE-2023-21563 | BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 73%ile | Microsoft | 2023-01-10 |
| CVE-2023-21560 | Windows Boot Manager Security Feature Bypass Vulnerability | MEDIUM | 6.6 | 63%ile | Microsoft | 2023-01-10 |
| CVE-2022-25147 | Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functions | MEDIUM | 6.5 | 70%ile | Microsoft | 2023-01-10 |
| CVE-2022-3437 | A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines | MEDIUM | 6.5 | 89%ile | Microsoft | 2023-01-10 |
| CVE-2022-41861 | A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which ca | MEDIUM | 6.5 | 62%ile | Microsoft | 2023-01-10 |
| CVE-2022-47015 | MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbas | MEDIUM | 6.5 | 72%ile | Microsoft | 2023-01-10 |
| CVE-2023-21719 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | MEDIUM | 6.5 | 76%ile | Microsoft | 2023-01-10 |
| CVE-2023-22745 | Buffer Overlow in TSS2_RC_Decode in tpm2-tss | MEDIUM | 6.4 | 41%ile | Microsoft | 2023-01-10 |
| CVE-2023-21725 | Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability | MEDIUM | 6.3 | 30%ile | Microsoft | 2023-01-10 |
| CVE-2022-46456 | NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c. | MEDIUM | 6.1 | 28%ile | Microsoft | 2023-01-10 |
| CVE-2023-22742 | libgit2 fails to verify SSH keys by default | MEDIUM | 5.9 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21875 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions | MEDIUM | 5.9 | 71%ile | Microsoft | 2023-01-10 |
| CVE-2022-46176 | Cargo did not verify SSH host keys | MEDIUM | 5.9 | 48%ile | Microsoft | 2023-01-10 |
| CVE-2023-21877 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are | MEDIUM | 5.5 | 53%ile | Microsoft | 2023-01-10 |
| CVE-2023-24056 | In pkgconf through 1.9.3 variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf | MEDIUM | 5.5 | 41%ile | Microsoft | 2023-01-10 |
| CVE-2022-4543 | A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local atta | MEDIUM | 5.5 | 58%ile | Microsoft | 2023-01-10 |
| CVE-2022-35977 | Integer overflow in certain command arguments can drive Redis to OOM panic | MEDIUM | 5.5 | 98%ile | Microsoft | 2023-01-10 |
| CVE-2022-4415 | A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not | MEDIUM | 5.5 | 55%ile | Microsoft | 2023-01-10 |
| CVE-2022-48303 | GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jum | MEDIUM | 5.5 | 91%ile | Microsoft | 2023-01-10 |
| CVE-2023-0394 | A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in | MEDIUM | 5.5 | 60%ile | Microsoft | 2023-01-10 |
| CVE-2023-0469 | A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Lin | MEDIUM | 5.5 | 24%ile | Microsoft | 2023-01-10 |
| CVE-2023-21880 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are | MEDIUM | 5.5 | 54%ile | Microsoft | 2023-01-10 |
| CVE-2023-22458 | Integer overflow in multiple Redis commands can lead to denial-of-service | MEDIUM | 5.5 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2023-23454 | cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (sla | MEDIUM | 5.5 | 24%ile | Microsoft | 2023-01-10 |
| CVE-2023-23455 | atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service be | MEDIUM | 5.5 | 19%ile | Microsoft | 2023-01-10 |
| CVE-2022-4285 | An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version i | MEDIUM | 5.5 | 36%ile | Microsoft | 2023-01-10 |
| CVE-2022-46457 | NASM v2.16 was discovered to contain a segmentation violation in the component ieee_write_file at /output/outieee.c. | MEDIUM | 5.5 | 26%ile | Microsoft | 2023-01-10 |
| CVE-2022-47929 | In the Linux kernel before 6.1.6 a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged | MEDIUM | 5.5 | 58%ile | Microsoft | 2023-01-10 |
| CVE-2022-48281 | processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g. "WRITE of size | MEDIUM | 5.5 | 36%ile | Microsoft | 2023-01-10 |
| CVE-2023-21540 | Windows Cryptographic Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21550 | Windows Cryptographic Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21559 | Windows Cryptographic Information Disclosure Vulnerability | MEDIUM | 5.5 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21753 | Event Tracing for Windows Information Disclosure Vulnerability | MEDIUM | 5.5 | 49%ile | Microsoft | 2023-01-10 |
| CVE-2023-21776 | Windows Kernel Information Disclosure Vulnerability | MEDIUM | 5.5 | 60%ile | Microsoft | 2023-01-10 |
| CVE-2021-4235 | CVE-2021-4235 | MEDIUM | 5.5 | 34%ile | Microsoft | 2023-01-10 |
| CVE-2022-4662 | CVE-2022-4662 | MEDIUM | 5.5 | 24%ile | Microsoft | 2023-01-10 |
| CVE-2023-22466 | Tokio's reject_remote_clients configuration may get dropped when creating a Windows named pipe | MEDIUM | 5.4 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-21830 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serializati | MEDIUM | 5.3 | 61%ile | Microsoft | 2023-01-10 |
| CVE-2022-37436 | Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting | MEDIUM | 5.3 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2023-21682 | Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability | MEDIUM | 5.3 | 69%ile | Microsoft | 2023-01-10 |
| CVE-2023-21743 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | MEDIUM | 5.3 | 63%ile | Microsoft | 2023-01-10 |
| CVE-2023-21525 | Remote Procedure Call Runtime Denial of Service Vulnerability | MEDIUM | 5.3 | 72%ile | Microsoft | 2023-01-10 |
| CVE-2022-46392 | CVE-2022-46392 | MEDIUM | 5.3 | 53%ile | Microsoft | 2023-01-10 |
| CVE-2023-21876 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 55%ile | Microsoft | 2023-01-10 |
| CVE-2023-21879 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 55%ile | Microsoft | 2023-01-10 |
| CVE-2023-21881 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 55%ile | Microsoft | 2023-01-10 |
| CVE-2023-21878 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 55%ile | Microsoft | 2023-01-10 |
| CVE-2023-21883 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | MEDIUM | 4.9 | 55%ile | Microsoft | 2023-01-10 |
| CVE-2023-21887 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affecte | MEDIUM | 4.9 | 99%ile | Microsoft | 2023-01-10 |
| CVE-2023-0468 | A use-after-free flaw was found in io_uring/poll.c in io_poll_check_events in the io_uring subcomponent in the Linux Ker | MEDIUM | 4.7 | 20%ile | Microsoft | 2023-01-10 |
| CVE-2021-36647 | Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS | MEDIUM | 4.7 | 6%ile | Microsoft | 2023-01-10 |
| CVE-2023-21766 | Windows Overlay Filter Information Disclosure Vulnerability | MEDIUM | 4.7 | 55%ile | Microsoft | 2023-01-10 |
| CVE-2023-21536 | Event Tracing for Windows Information Disclosure Vulnerability | MEDIUM | 4.7 | 32%ile | Microsoft | 2023-01-10 |
| CVE-2022-4344 | Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of servic | MEDIUM | 4.3 | 44%ile | Microsoft | 2023-01-10 |
| CVE-2018-14628 | An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authen | MEDIUM | 4.3 | 64%ile | Microsoft | 2023-01-10 |
| CVE-2023-21843 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Sound). Su | LOW | 3.7 | 69%ile | Microsoft | 2023-01-10 |
| CVE-2023-21759 | Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | LOW | 3.3 | 45%ile | Microsoft | 2023-01-10 |
| CVE-2023-21882 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a | LOW | 2.7 | 47%ile | Microsoft | 2023-01-10 |
| CVE-2022-28331 | Apache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv function | UNKNOWN | — | 73%ile | Microsoft | 2023-01-10 |
| CVE-2022-4743 | A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerab | UNKNOWN | — | 67%ile | Microsoft | 2023-01-10 |
| CVE-2023-0129 | Chromium:CVE-2023-0129: Heap buffer overflow in Network Service | UNKNOWN | — | 40%ile | Microsoft | 2023-01-10 |
| CVE-2023-0130 | Chromium:CVE-2023-0130: Inappropriate implementation in Fullscreen API | UNKNOWN | — | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-0131 | Chromium:CVE-2023-0131: Inappropriate implementation in iframe Sandbox | UNKNOWN | — | 45%ile | Microsoft | 2023-01-10 |
| CVE-2023-0132 | Chromium:CVE-2023-0132: Inappropriate implementation in Permission prompts | UNKNOWN | — | 40%ile | Microsoft | 2023-01-10 |
| CVE-2023-0133 | Chromium:CVE-2023-0133: Inappropriate implementation in Permission prompts | UNKNOWN | — | 44%ile | Microsoft | 2023-01-10 |
| CVE-2023-0134 | Chromium:CVE-2023-0134: Use after free in Cart | UNKNOWN | — | 37%ile | Microsoft | 2023-01-10 |
| CVE-2023-0135 | Chromium:CVE-2023-0135: Use after free in Cart | UNKNOWN | — | 37%ile | Microsoft | 2023-01-10 |
| CVE-2023-0136 | Chromium:CVE-2023-0136: Inappropriate implementation in Fullscreen API | UNKNOWN | — | 48%ile | Microsoft | 2023-01-10 |
| CVE-2023-0138 | Chromium:CVE-2023-0138: Heap buffer overflow in libphonenumber | UNKNOWN | — | 50%ile | Microsoft | 2023-01-10 |
| CVE-2023-0139 | Chromium:CVE-2023-0139: Insufficient validation of untrusted input in Downloads | UNKNOWN | — | 45%ile | Microsoft | 2023-01-10 |
| CVE-2023-0140 | Chromium:CVE-2023-0140: Inappropriate implementation in File System API | UNKNOWN | — | 45%ile | Microsoft | 2023-01-10 |
| CVE-2023-0141 | Chromium:CVE-2023-0141: Insufficient policy enforcement in CORS | UNKNOWN | — | 45%ile | Microsoft | 2023-01-10 |
| CVE-2023-0471 | Chromium: CVE-2023-0471 Use after free in WebTransport | UNKNOWN | — | 51%ile | Microsoft | 2023-01-10 |
| CVE-2023-0472 | Chromium: CVE-2023-0472 Use after free in WebRTC | UNKNOWN | — | 49%ile | Microsoft | 2023-01-10 |
| CVE-2023-0473 | Chromium: CVE-2023-0473: Type Confusion in ServiceWorker | UNKNOWN | — | 49%ile | Microsoft | 2023-01-10 |
| CVE-2023-0474 | Chromium: CVE-2023-0474 Use after free in GuestView | UNKNOWN | — | 40%ile | Microsoft | 2023-01-10 |