CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-50486

    Last Modified: 14 Jul 2026

    Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    4.5
    Medium

    CVE-2026-50485

    Last Modified: 14 Jul 2026

    Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

    Published: 14 Jul 2026
    8
    High

    CVE-2026-50502

    Last Modified: 15 Jul 2026

    Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50493

    Last Modified: 14 Jul 2026

    Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50484

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50483

    Last Modified: 15 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    6.1
    Medium

    CVE-2026-50495

    Last Modified: 15 Jul 2026

    Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

    Published: 14 Jul 2026
    7.3
    High

    CVE-2026-50482

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50480

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50479

    Last Modified: 14 Jul 2026

    Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50478

    Last Modified: 16 Jul 2026

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-50477

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-50459

    Last Modified: 14 Jul 2026

    Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50470

    Last Modified: 15 Jul 2026

    Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-50406

    Last Modified: 15 Jul 2026

    Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50424

    Last Modified: 14 Jul 2026

    Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50450

    Last Modified: 15 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.2
    High

    CVE-2026-50429

    Last Modified: 15 Jul 2026

    Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50476

    Last Modified: 15 Jul 2026

    Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50475

    Last Modified: 16 Jul 2026

    Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50458

    Last Modified: 15 Jul 2026

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-50415

    Last Modified: 15 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50394

    Last Modified: 15 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-50444

    Last Modified: 15 Jul 2026

    Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50411

    Last Modified: 22 Jul 2026

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-50474

    Last Modified: 14 Jul 2026

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50362

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    6.2
    Medium

    CVE-2026-50420

    Last Modified: 16 Jul 2026

    Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-50438

    Last Modified: 15 Jul 2026

    Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-50447

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    9.1
    Critical

    CVE-2026-15747

    Last Modified: 27 Jul 2026

    Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. An attacker able to query it can recover the token and pass csrf_protect validation.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50417

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

    Published: 14 Jul 2026
    6.1
    Medium

    CVE-2026-50453

    Last Modified: 14 Jul 2026

    Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50431

    Last Modified: 15 Jul 2026

    Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50461

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50399

    Last Modified: 15 Jul 2026

    Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-50432

    Last Modified: 14 Jul 2026

    Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50456

    Last Modified: 15 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50389

    Last Modified: 16 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50442

    Last Modified: 15 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50473

    Last Modified: 14 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50457

    Last Modified: 15 Jul 2026

    Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50462

    Last Modified: 15 Jul 2026

    External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-50439

    Last Modified: 15 Jul 2026

    Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.1
    High

    CVE-2026-50465

    Last Modified: 16 Jul 2026

    Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50441

    Last Modified: 15 Jul 2026

    Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-50409

    Last Modified: 15 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50435

    Last Modified: 15 Jul 2026

    Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50402

    Last Modified: 15 Jul 2026

    Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50466

    Last Modified: 15 Jul 2026

    Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026