Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2026-61353
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.0
CVE-2026-61348
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-61347
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.0
CVE-2026-61346
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9115 / 10.0.19044.7663+
MEDIUM 6.5
CVE-2026-59138
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 6.5
CVE-2026-61345
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-59136
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-59137
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 8.8
CVE-2026-59133
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a n…
Windows App
2.0.1193.0+
HIGH 8.1
CVE-2026-59134
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.5
CVE-2026-59132
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.6
CVE-2026-59130
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.6
CVE-2026-59131
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-59135
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
CRITICAL 9.8
CVE-2026-59124
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
Windows App
2.0.1314.0+
HIGH 7.8
CVE-2026-59127
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
Windows 10 1607
Fix available
HIGH 7.0
CVE-2026-59122
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacke…
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.0
CVE-2026-59125
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.0
CVE-2026-59126
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized att…
Windows 10 21h2
10.0.19044.7663 / 10.0.19045.7663+
MEDIUM 5.5
CVE-2026-59128
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 8.8
CVE-2026-59113
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Visual Studio Code
No fix yet
HIGH 7.8
CVE-2026-58641
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
.net
8.0.30 / 9.0.19+
HIGH 7.8
CVE-2026-58650
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Visual Studio Code
Fix available
HIGH 7.8
CVE-2026-58651
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.3
CVE-2026-59119
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Powershell
No fix yet
MEDIUM 6.5
CVE-2026-58639
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20522+
CRITICAL 9.6
CVE-2026-57104
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to ele…
Azure Storage Explorer
No fix yet
HIGH 8.3
CVE-2026-56179
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Windows 11 24h2
10.0.26100.9106 / 10.0.26100.33222+
HIGH 7.8
CVE-2026-56174
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9115 / 10.0.19044.7663+
HIGH 7.5
CVE-2026-58612
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
Powershell
No fix yet