CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2026-54127

    Last Modified: 15 Jul 2026

    Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-50694

    Last Modified: 15 Jul 2026

    Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-56170

    Last Modified: 17 Jul 2026

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-56169

    Last Modified: 15 Jul 2026

    Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    5.3
    Medium

    CVE-2026-56164

    Last Modified: 14 Jul 2026

    Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-56155

    Last Modified: 14 Jul 2026

    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55948

    Last Modified: 14 Jul 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55899

    Last Modified: 16 Jul 2026

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    6.1
    Medium

    CVE-2026-54988

    Last Modified: 16 Jul 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026
    6.6
    Medium

    CVE-2026-50678

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50675

    Last Modified: 16 Jul 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-54108

    Last Modified: 14 Jul 2026

    External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 14 Jul 2026
    8.4
    High

    CVE-2026-50520

    Last Modified: 14 Jul 2026

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.1
    High

    CVE-2026-55144

    Last Modified: 14 Jul 2026

    Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-55002

    Last Modified: 3 Aug 2026

    External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-54118

    Last Modified: 20 Aug 2026

    Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-54117

    Last Modified: 20 Aug 2026

    Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55012

    Last Modified: 15 Jul 2026

    Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55011

    Last Modified: 14 Jul 2026

    Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    8.2
    High

    CVE-2026-50338

    Last Modified: 14 Jul 2026

    Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55009

    Last Modified: 14 Jul 2026

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    9.6
    Critical

    CVE-2026-55008

    Last Modified: 15 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55006

    Last Modified: 14 Jul 2026

    Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-55005

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

    Published: 14 Jul 2026
    8.4
    High

    CVE-2026-54122

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    8.1
    High

    CVE-2026-54995

    Last Modified: 14 Jul 2026

    Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    6.5
    Medium

    CVE-2026-55003

    Last Modified: 14 Jul 2026

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-54999

    Last Modified: 15 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.

    Published: 14 Jul 2026
    5.5
    Medium

    CVE-2026-54997

    Last Modified: 16 Jul 2026

    Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-54119

    Last Modified: 14 Jul 2026

    Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-54996

    Last Modified: 14 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-54114

    Last Modified: 15 Jul 2026

    Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-54982

    Last Modified: 15 Jul 2026

    Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-54109

    Last Modified: 15 Jul 2026

    Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

    Published: 14 Jul 2026
    8.4
    High

    CVE-2026-54992

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55004

    Last Modified: 15 Jul 2026

    Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-54112

    Last Modified: 15 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-55001

    Last Modified: 15 Jul 2026

    Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-54993

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-54986

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    8.8
    High

    CVE-2026-54107

    Last Modified: 15 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    6.8
    Medium

    CVE-2026-54132

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-54991

    Last Modified: 15 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-54111

    Last Modified: 14 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    6.4
    Medium

    CVE-2026-55000

    Last Modified: 14 Jul 2026

    Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-50697

    Last Modified: 14 Jul 2026

    Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    9.8
    Critical

    CVE-2026-54990

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 14 Jul 2026
    7.5
    High

    CVE-2026-50696

    Last Modified: 14 Jul 2026

    Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

    Published: 14 Jul 2026
    7.8
    High

    CVE-2026-54987

    Last Modified: 15 Jul 2026

    Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026
    7
    High

    CVE-2026-54989

    Last Modified: 14 Jul 2026

    Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.

    Published: 14 Jul 2026