CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2026-20714

    Last Modified: 15 May 2026

    Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

    Published: 12 May 2026
    6.1
    Medium

    CVE-2026-42303

    Last Modified: 12 May 2026

    Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized deletion of a data subject's records across every integration configured in the affected deployment. This vulnerability is fixed in 2.83.2.

    Published: 12 May 2026
    4.3
    Medium

    CVE-2026-5146

    Last Modified: 26 May 2026

    Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.15.0 * Devolutions Server 2025.3.19.0 and earlier

    Published: 12 May 2026
    9.3
    Critical

    CVE-2026-42300

    Last Modified: 13 May 2026

    DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw string value as the authenticated userID when no Kratos session cookie is present. An unauthenticated attacker who knows or can guess a target user's Kratos identity UUID can issue requests as that user. Where the target user is an organisation admin or owner, this gives the attacker full control over that organisation's DevGuard resources. This vulnerability is fixed in 1.2.2.

    Published: 12 May 2026
    7.5
    High

    CVE-2026-44167

    Last Modified: 14 May 2026

    phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed in 1.0.29, 2.0.54, and 3.0.52.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34644

    Last Modified: 28 Aug 2026

    After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34643

    Last Modified: 13 May 2026

    After Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34642

    Last Modified: 28 Aug 2026

    After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 May 2026
    6.1
    Medium

    CVE-2026-44166

    Last Modified: 19 May 2026

    Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and link an unverified PocketBase user in advance by authenticating with one of the OAuth2 app providers, e.g. "A". When the victim gets invited or decides to sign up to your app on their own with provider "B" (PocketBase OAuth2 auth requires to be with a different provider because we don't allow multiple OAuth2 accounts from the same provider to be associated to a single PocketBase user), the user created previously by the attacker will be autolinked, upgraded to "verified" and its old password reset. This vulnerability is fixed in 0.22.42 and 0.37.4.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34640

    Last Modified: 13 May 2026

    Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34639

    Last Modified: 13 May 2026

    Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 May 2026
    7.7
    High

    CVE-2026-42141

    Last Modified: 13 May 2026

    Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal infrastructure, access local cloud metadata endpoints (e.g., AWS IMDS), interact with internal services that lack authentication, or exfiltrate data. This vulnerability is fixed in 4.4.1.

    Published: 12 May 2026
    5.3
    Medium

    CVE-2026-42177

    Last Modified: 13 May 2026

    linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + "/*", i.e. "https://login.microsoftonline.com/*". Chrome's urlFilter without a | or || anchor is substring-matched against the full request URL. The same applied rule action is modifyHeaders that attaches the Entra ID Primary Refresh Token cookie. The Firefox adapter in platform/firefox/js/platform-firefox.js:53 performs a belt-and-braces startsWith(Platform.SSO_URL) check before injecting the header; the Chrome adapter does not. When the extension holds broad host permissions through the optional_host_permissions: ["https://*/*"] declared in platform/chrome/manifest.json:34, a main-frame navigation to a URL whose path embeds https://login.microsoftonline.com/ causes Chrome to attach the PRT cookie to the request to the attacker-controlled host. This vulnerability is fixed in 1.8.1.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34637

    Last Modified: 13 May 2026

    Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34638

    Last Modified: 13 May 2026

    Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34636

    Last Modified: 13 May 2026

    Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 May 2026
    7.7
    High

    CVE-2026-33821

    Last Modified: 15 May 2026

    Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

    Published: 12 May 2026
    7.4
    High

    CVE-2026-42893

    Last Modified: 13 May 2026

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

    Published: 12 May 2026
    5.4
    Medium

    CVE-2026-42838

    Last Modified: 14 May 2026

    Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

    Published: 12 May 2026
    4.3
    Medium

    CVE-2026-40416

    Last Modified: 18 May 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 May 2026
    9.1
    Critical

    CVE-2026-42833

    Last Modified: 1 Jun 2026

    Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

    Published: 12 May 2026
    7.7
    High

    CVE-2026-42832

    Last Modified: 19 May 2026

    Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

    Published: 12 May 2026
    6.5
    Medium

    CVE-2026-42830

    Last Modified: 14 May 2026

    Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    9.9
    Critical

    CVE-2026-42823

    Last Modified: 14 May 2026

    Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-41613

    Last Modified: 12 May 2026

    Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

    Published: 12 May 2026
    9.1
    Critical

    CVE-2026-41103

    Last Modified: 16 May 2026

    Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40381

    Last Modified: 13 May 2026

    Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    6.7
    Medium

    CVE-2026-41097

    Last Modified: 15 May 2026

    Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-41086

    Last Modified: 15 May 2026

    Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-40420

    Last Modified: 1 Jun 2026

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-35436

    Last Modified: 1 Jun 2026

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40418

    Last Modified: 1 Jun 2026

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.4
    High

    CVE-2026-40413

    Last Modified: 1 Jun 2026

    Windows TCP/IP Denial of Service Vulnerability

    Published: 12 May 2026
    8.8
    High

    CVE-2026-40403

    Last Modified: 15 May 2026

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

    Published: 12 May 2026
    9.3
    Critical

    CVE-2026-40402

    Last Modified: 15 May 2026

    Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.1
    High

    CVE-2026-40401

    Last Modified: 1 Jun 2026

    Windows TCP/IP Denial of Service Vulnerability

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40398

    Last Modified: 15 May 2026

    Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    4.4
    Medium

    CVE-2026-32209

    Last Modified: 14 May 2026

    Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40397

    Last Modified: 1 Jun 2026

    Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40382

    Last Modified: 15 May 2026

    Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40369

    Last Modified: 1 Jun 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-40370

    Last Modified: 13 May 2026

    External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.

    Published: 12 May 2026
    8.4
    High

    CVE-2026-40367

    Last Modified: 1 Jun 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-40365

    Last Modified: 1 Jun 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40362

    Last Modified: 1 Jun 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    8.4
    High

    CVE-2026-40361

    Last Modified: 3 Jun 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40359

    Last Modified: 19 May 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    8.4
    High

    CVE-2026-40358

    Last Modified: 1 Jun 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-40357

    Last Modified: 13 May 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 12 May 2026
    7
    High

    CVE-2026-34341

    Last Modified: 14 May 2026

    Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026