CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2026-58547

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58536

    Last Modified: 7 Aug 2026

    Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-58534

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58537

    Last Modified: 7 Aug 2026

    Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58532

    Last Modified: 7 Aug 2026

    Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-58531

    Last Modified: 7 Aug 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58540

    Last Modified: 7 Aug 2026

    Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-58539

    Last Modified: 7 Aug 2026

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-58546

    Last Modified: 7 Aug 2026

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-58535

    Last Modified: 7 Aug 2026

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-58533

    Last Modified: 7 Aug 2026

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58538

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58530

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    6.8
    Medium

    CVE-2026-58528

    Last Modified: 7 Aug 2026

    Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58527

    Last Modified: 7 Aug 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-58277

    Last Modified: 14 Jul 2026

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-57982

    Last Modified: 7 Aug 2026

    Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    6.3
    Medium

    CVE-2026-57973

    Last Modified: 15 Jul 2026

    Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-57968

    Last Modified: 14 Jul 2026

    Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-57108

    Last Modified: 17 Jul 2026

    Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-57102

    Last Modified: 14 Jul 2026

    Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

    Published: 14 Jul 2026
    7.1
    High

    CVE-2026-57101

    Last Modified: 14 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-57096

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-57093

    Last Modified: 7 Aug 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-57088

    Last Modified: 7 Aug 2026

    Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-57087

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    9.9
    Critical

    CVE-2026-57092

    Last Modified: 7 Aug 2026

    Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-57085

    Last Modified: 7 Aug 2026

    Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-57089

    Last Modified: 7 Aug 2026

    Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-57091

    Last Modified: 7 Aug 2026

    Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-57094

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-57090

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    6.2
    Medium

    CVE-2026-57095

    Last Modified: 7 Aug 2026

    Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-56650

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-57084

    Last Modified: 7 Aug 2026

    Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-57083

    Last Modified: 7 Aug 2026

    Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.9
    Medium

    CVE-2026-56649

    Last Modified: 7 Aug 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-56648

    Last Modified: 7 Aug 2026

    Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-56647

    Last Modified: 7 Aug 2026

    Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-56194

    Last Modified: 7 Aug 2026

    Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-54124

    Last Modified: 7 Aug 2026

    Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-56644

    Last Modified: 7 Aug 2026

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-56643

    Last Modified: 7 Aug 2026

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-56642

    Last Modified: 15 Jul 2026

    Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-56178

    Last Modified: 14 Jul 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-56197

    Last Modified: 14 Jul 2026

    Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-56196

    Last Modified: 14 Jul 2026

    Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-56195

    Last Modified: 14 Jul 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-56192

    Last Modified: 7 Aug 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50665

    Last Modified: 15 Jul 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026