CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-48565

    Last Modified: 12 Jun 2026

    Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-48562

    Last Modified: 12 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-48560

    Last Modified: 8 Jul 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-47656

    Last Modified: 10 Jun 2026

    Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    8.8
    High

    CVE-2026-45484

    Last Modified: 12 Jun 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

    Published: 9 Jun 2026
    7.3
    High

    CVE-2026-45481

    Last Modified: 12 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    9.8
    Critical

    CVE-2026-47643

    Last Modified: 10 Jun 2026

    External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-47640

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    7.3
    High

    CVE-2026-47634

    Last Modified: 8 Jul 2026

    Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-42910

    Last Modified: 11 Jun 2026

    Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-47293

    Last Modified: 10 Jun 2026

    Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    6.5
    Medium

    CVE-2026-47284

    Last Modified: 15 Jun 2026

    Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

    Published: 9 Jun 2026
    9.6
    Critical

    CVE-2026-47281

    Last Modified: 8 Jul 2026

    Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45658

    Last Modified: 8 Jul 2026

    Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-45647

    Last Modified: 10 Jun 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.9
    High

    CVE-2026-45654

    Last Modified: 8 Jul 2026

    Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-45653

    Last Modified: 8 Jul 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    8
    High

    CVE-2026-45644

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.

    Published: 9 Jun 2026
    6.8
    Medium

    CVE-2026-45608

    Last Modified: 8 Jul 2026

    Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45637

    Last Modified: 11 Jun 2026

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-45603

    Last Modified: 8 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45638

    Last Modified: 1 Jul 2026

    Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    8.1
    High

    CVE-2026-45635

    Last Modified: 8 Jul 2026

    Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    9.1
    Critical

    CVE-2026-45602

    Last Modified: 16 Jun 2026

    No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45600

    Last Modified: 15 Jun 2026

    Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-45596

    Last Modified: 11 Jun 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45636

    Last Modified: 11 Jun 2026

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-45598

    Last Modified: 8 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-45601

    Last Modified: 8 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    8.1
    High

    CVE-2026-45599

    Last Modified: 11 Jun 2026

    Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-45597

    Last Modified: 11 Jun 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-45595

    Last Modified: 11 Jun 2026

    Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-45604

    Last Modified: 11 Jun 2026

    Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-45594

    Last Modified: 11 Jun 2026

    Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45593

    Last Modified: 15 Jun 2026

    Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45592

    Last Modified: 11 Jun 2026

    Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.5
    High

    CVE-2026-45591

    Last Modified: 10 Jun 2026

    Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45586

    Last Modified: 11 Jun 2026

    Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45482

    Last Modified: 8 Jul 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    8.2
    High

    CVE-2026-45476

    Last Modified: 10 Jun 2026

    Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-45465

    Last Modified: 8 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-45464

    Last Modified: 8 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45463

    Last Modified: 8 Jul 2026

    Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-45462

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    3.3
    Low

    CVE-2026-45459

    Last Modified: 11 Jun 2026

    Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45457

    Last Modified: 8 Jul 2026

    Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    3.3
    Low

    CVE-2026-45455

    Last Modified: 8 Jul 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 9 Jun 2026
    6.5
    Medium

    CVE-2026-45454

    Last Modified: 10 Jun 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 9 Jun 2026
    8.2
    High

    CVE-2026-44822

    Last Modified: 11 Jun 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

    Published: 9 Jun 2026
    7.5
    High

    CVE-2026-40376

    Last Modified: 11 Jun 2026

    Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

    Published: 9 Jun 2026