Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.0
CVE-2026-48571
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.22631.7376 / 10.0.26100.8875+
HIGH 7.0
CVE-2026-48572
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to…
Windows 11 23h2
10.0.22631.7376 / 10.0.26100.8875+
HIGH 7.0
CVE-2026-49162
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.8875 / 10.0.26100.33158+
CRITICAL 9.6
CVE-2026-48561
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
365 Copilot
Mitigation only
HIGH 8.8
CVE-2026-47632
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Azure Connected Machine Agent
Mitigation only
HIGH 8.8
CVE-2026-48564
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.5
CVE-2026-45646
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Asp.net Core Odata
7.8.0 / 9.5.0+
HIGH 7.5
CVE-2026-47296
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…
Sql Server 2016
13.0.6500.1 / 13.0.7095.1+
MEDIUM 6.5
CVE-2026-47282
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Visual Studio Code
1.128.1+
MEDIUM 5.5
CVE-2026-45496
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a secu…
Visual Studio Code
1.128.1+
CRITICAL 9.8
CVE-2026-42990
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-42975
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-42982
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-44800
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…
Windows 11 23h2
10.0.22631.7376 / 10.0.26100.8875+
HIGH 7.5
CVE-2026-44806
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.1
CVE-2026-42900
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to e…
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.0
CVE-2026-40400
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.5
CVE-2026-40378
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny ser…
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-40422
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-41087
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 6.5
CVE-2026-34348
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
MEDIUM 5.5
CVE-2026-33842
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-34328
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
MEDIUM 5.5
CVE-2026-34346
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose informatio…
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-34349
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 8.3
CVE-2026-58596
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Edge Chromium
150.0.4078.48+
HIGH 8.3
CVE-2026-58281
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
150.0.4078.48+
MEDIUM 6.1
CVE-2026-47646
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t…
Dynamics 365 Customer Voice
Mitigation only
HIGH 8.2
CVE-2026-58525
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Edge Chromium
150.0.4078.50+
MEDIUM 6.5
CVE-2026-58523
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
Edge Chromium
150.0.4078.48+