Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-24291
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate…
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 8.8
CVE-2026-24283
Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.25398.2207 / 10.0.26100.7979+
HIGH 7.8
CVE-2026-24287
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8511 / 10.0.19044.7058+
HIGH 7.0
CVE-2026-24285
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
365 Copilot
10.0.14393.8957 / 10.0.17763.8511+
MEDIUM 6.8
CVE-2026-24288
Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.
Windows 10 21h2
10.0.19044.7058 / 10.0.19045.7058+
MEDIUM 5.5
CVE-2026-24282
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.8
CVE-2026-23673
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.5
CVE-2026-23674
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 8.8
CVE-2026-23669
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.8
CVE-2026-23672
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.0
CVE-2026-23668
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.0
CVE-2026-23671
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an auth…
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.8
CVE-2026-23660
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
Windows Admin Center
2.6.4+
HIGH 7.8
CVE-2026-23665
Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.
Linux Diagnostic Extension
2.1.24+
HIGH 7.5
CVE-2026-23661
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Azure Iot Explorer
0.15.13+
HIGH 7.5
CVE-2026-23662
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Azure Iot Explorer
0.15.13+
HIGH 7.5
CVE-2026-23664
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information ove…
Azure Iot Explorer
0.15.13+
HIGH 7.0
CVE-2026-23667
Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8511 / 10.0.19044.7058+
HIGH 8.8
CVE-2026-23654
Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.
Zero Shot Scfoundation
0.1.1+
MEDIUM 5.9
CVE-2026-23656
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.
Windows App
2.0.964.0+
HIGH 8.8
CVE-2026-21262
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Sql Server 2016
13.0.6480.4 / 13.0.7075.5+
HIGH 8.8
CVE-2026-20967
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
System Center Operations Manager
Mitigation only
CRITICAL 9.8
CVE-2026-26125
Payment Orchestrator Service Elevation of Privilege Vulnerability
Payment Orchestrator Service
No fix yet
MEDIUM 6.7
CVE-2026-23651
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
Aci Confidential Containers
Mitigation only
MEDIUM 6.7
CVE-2026-26124
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
Aci Confidential Containers
No fix yet
MEDIUM 6.5
CVE-2026-26122
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
Aci Confidential Containers
No fix yet
CRITICAL 9.8
CVE-2026-21536
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Devices Pricing Program
No fix yet
HIGH 7.5
CVE-2026-21535
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
Teams
Mitigation only
CRITICAL 9.9
CVE-2026-26030
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…
Semantic Kernel
1.39.4+
HIGH 8.8
CVE-2026-26119
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
2511+