Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2026-50512
Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Pc Manager
3.21.6.0+
HIGH 7.8
CVE-2026-50511
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Pc Manager
3.21.6.0+
HIGH 7.5
CVE-2026-50508EPSS 9%
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Windows 10 1607
10.0.14393.9234 / 10.0.19045.7417+
MEDIUM 6.8
CVE-2026-50507EPSS 5%
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-49161
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
Pc Manager
3.21.6.0+
HIGH 7.9
CVE-2026-48576
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.9
CVE-2026-48578
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.9
CVE-2026-48575
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-48574
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-48583
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.5
CVE-2026-49160EPSS 54%
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.9
CVE-2026-48573
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.9
CVE-2026-48568
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.9
CVE-2026-48570
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-48565
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Windows Narrator Braille
Mitigation only
MEDIUM 5.5
CVE-2026-48566
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.8390 / 10.0.26100.32772+
MEDIUM 5.5
CVE-2026-48569
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Visual Studio Code
1.123.2+
HIGH 7.5
CVE-2026-48563
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows 10 1809
10.0.17763.8880 / 10.0.19044.7417+
MEDIUM 5.4
CVE-2026-48560
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20384+
HIGH 7.9
CVE-2026-47656
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
CRITICAL 9.8
CVE-2026-47643
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
Azure Stack Edge
3.3.2604.3097+
HIGH 8.8
CVE-2026-47653
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 8.2
CVE-2026-47652
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Windows 11 23h2
10.0.20348.5256 / 10.0.22631.7219+
HIGH 7.5
CVE-2026-47654
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows Server 2016
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.0
CVE-2026-47648
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
MEDIUM 5.4
CVE-2026-47641
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-47640
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20384+
HIGH 8.4
CVE-2026-47635
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Office 2024
Mitigation only
HIGH 8.0
CVE-2026-47298
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-47634
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorize…
Sharepoint Server
16.0.19725.20384+