CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2026-49790

    Last Modified: 15 Jul 2026

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

    Published: 14 Jul 2026
    7.3
    High

    CVE-2026-49789

    Last Modified: 14 Jul 2026

    Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-49788

    Last Modified: 14 Jul 2026

    Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-49787

    Last Modified: 14 Jul 2026

    Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-49783

    Last Modified: 15 Jul 2026

    Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-49183

    Last Modified: 14 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.4
    High

    CVE-2026-49184

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-49181

    Last Modified: 29 Jul 2026

    Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-49180

    Last Modified: 14 Jul 2026

    Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-49178

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-45646

    Last Modified: 14 Jul 2026

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-48581

    Last Modified: 14 Jul 2026

    Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-48564

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-47632

    Last Modified: 18 Aug 2026

    Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-44800

    Last Modified: 15 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-40378

    Last Modified: 14 Jul 2026

    Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-44806

    Last Modified: 14 Jul 2026

    Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-34348

    Last Modified: 16 Jul 2026

    Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    8
    High

    CVE-2026-40400

    Last Modified: 14 Jul 2026

    Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-41087

    Last Modified: 15 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-40422

    Last Modified: 15 Jul 2026

    Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-34328

    Last Modified: 15 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-33842

    Last Modified: 14 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50653

    Last Modified: 22 Jul 2026

    Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50652

    Last Modified: 22 Jul 2026

    Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    8
    High

    CVE-2026-58647

    Last Modified: 15 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-58644

    Last Modified: 16 Jul 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.3
    High

    CVE-2026-58640

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58636

    Last Modified: 14 Jul 2026

    Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58635

    Last Modified: 15 Jul 2026

    Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58631

    Last Modified: 14 Jul 2026

    Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58618

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-58614

    Last Modified: 16 Jul 2026

    Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58610

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58609

    Last Modified: 14 Jul 2026

    Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-58608

    Last Modified: 15 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58602

    Last Modified: 14 Jul 2026

    Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-58601

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-50522

    Last Modified: 22 Jul 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-58595

    Last Modified: 16 Jul 2026

    Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-58526

    Last Modified: 14 Jul 2026

    Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-58279

    Last Modified: 14 Jul 2026

    Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55014

    Last Modified: 15 Jul 2026

    Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-57979

    Last Modified: 15 Jul 2026

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-57976

    Last Modified: 14 Jul 2026

    Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-57969

    Last Modified: 15 Jul 2026

    Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-57107

    Last Modified: 15 Jul 2026

    Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    6.4
    Medium

    CVE-2026-57097

    Last Modified: 14 Jul 2026

    Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-56185

    Last Modified: 15 Jul 2026

    Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    7.1
    High

    CVE-2026-56193

    Last Modified: 14 Jul 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026