Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-21251
Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.
Windows Server 2016
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.3
CVE-2026-21247
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.3
CVE-2026-21248
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21245
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.7781 / 10.0.26100.32313+
HIGH 7.5
CVE-2026-21243
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
Windows Server 2019
10.0.17763.8389 / 10.0.20348.4711+
HIGH 7.3
CVE-2026-21244
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.0
CVE-2026-21241
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.20348.4711 / 10.0.22631.6649+
HIGH 7.0
CVE-2026-21242
Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.6937 / 10.0.19045.6937+
HIGH 7.8
CVE-2026-21236
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21238
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21239
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.3
CVE-2026-21235
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.0
CVE-2026-21237
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attac…
Windows 10 21h2
10.0.19044.6937 / 10.0.19045.6937+
HIGH 7.0
CVE-2026-21240
Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8389 / 10.0.19044.6937+
HIGH 8.8
CVE-2026-21229
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Power Bi Report Server
15.0.1120.113+
HIGH 8.1
CVE-2026-21228
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
Azure Local
2510.0.3002+
HIGH 7.8
CVE-2026-21231
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21232
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.22631.6649 / 10.0.25398.2149+
HIGH 7.0
CVE-2026-21234
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an a…
Windows 10 1809
10.0.17763.8389 / 10.0.19044.6937+
MEDIUM 5.5
CVE-2026-21222
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-20841EPSS 12%
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute…
Windows Notepad
11.2510+
HIGH 7.5
CVE-2026-20846
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.5
CVE-2026-21218
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
.net
8.0.24 / 9.0.13+
CRITICAL 9.8
CVE-2026-24300
Azure Front Door Elevation of Privilege Vulnerability
Azure Front Door
No fix yet
CRITICAL 9.8
CVE-2026-24302
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Azure Arc
Mitigation only
HIGH 8.2
CVE-2026-21532
Azure Function Information Disclosure Vulnerability
Azure Functions
No fix yet
MEDIUM 6.5
CVE-2026-0391
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over …
Edge Chromium
143.0.3650.66+
CRITICAL 9.8
CVE-2026-24888
Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject`…
Maker.js
after 0.19.1
HIGH 7.8
CVE-2026-21509 KEVEPSS 72%
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
365 Apps
Mitigation only
CRITICAL 9.9
CVE-2026-24304
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Azure Resource Manager
Mitigation only