CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-40377

    Last Modified: 14 May 2026

    Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    6.5
    Medium

    CVE-2026-40374

    Last Modified: 12 May 2026

    Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.

    Published: 12 May 2026
    8
    High

    CVE-2026-40368

    Last Modified: 13 May 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 12 May 2026
    8.4
    High

    CVE-2026-40366

    Last Modified: 1 Jun 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    8.4
    High

    CVE-2026-40364

    Last Modified: 19 May 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    8.4
    High

    CVE-2026-40363

    Last Modified: 22 May 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-40360

    Last Modified: 19 May 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 12 May 2026
    5.5
    Medium

    CVE-2026-35440

    Last Modified: 19 May 2026

    Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-35439

    Last Modified: 13 May 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 12 May 2026
    8.3
    High

    CVE-2026-35438

    Last Modified: 13 May 2026

    Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

    Published: 12 May 2026
    7.3
    High

    CVE-2026-35433

    Last Modified: 17 Jun 2026

    Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.5
    High

    CVE-2026-35424

    Last Modified: 14 May 2026

    Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

    Published: 12 May 2026
    5.4
    Medium

    CVE-2026-35423

    Last Modified: 14 May 2026

    Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.

    Published: 12 May 2026
    6.5
    Medium

    CVE-2026-35422

    Last Modified: 14 May 2026

    Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-35421

    Last Modified: 14 May 2026

    Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-35420

    Last Modified: 14 May 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    5.5
    Medium

    CVE-2026-35419

    Last Modified: 14 May 2026

    Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-35418

    Last Modified: 14 May 2026

    Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-35417

    Last Modified: 1 Jun 2026

    Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7
    High

    CVE-2026-35416

    Last Modified: 1 Jun 2026

    Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-35415

    Last Modified: 14 May 2026

    Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34351

    Last Modified: 14 May 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    6.5
    Medium

    CVE-2026-34350

    Last Modified: 13 May 2026

    Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.

    Published: 12 May 2026
    7
    High

    CVE-2026-34347

    Last Modified: 14 May 2026

    Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7
    High

    CVE-2026-34345

    Last Modified: 1 Jun 2026

    Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34344

    Last Modified: 14 May 2026

    Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34343

    Last Modified: 14 May 2026

    Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7
    High

    CVE-2026-34342

    Last Modified: 14 May 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34333

    Last Modified: 14 May 2026

    Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7
    High

    CVE-2026-34331

    Last Modified: 14 May 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-34330

    Last Modified: 1 Jun 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    8.8
    High

    CVE-2026-34329

    Last Modified: 14 May 2026

    Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-33841

    Last Modified: 17 Jun 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-33840

    Last Modified: 9 Jun 2026

    Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7
    High

    CVE-2026-33839

    Last Modified: 14 May 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-33834

    Last Modified: 14 May 2026

    Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    9.1
    Critical

    CVE-2026-33117

    Last Modified: 22 May 2026

    The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.

    Published: 12 May 2026
    6.7
    Medium

    CVE-2026-21530

    Last Modified: 9 Jun 2026

    Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.3
    High

    CVE-2026-32177

    Last Modified: 26 May 2026

    Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

    Published: 12 May 2026
    7.8
    High

    CVE-2026-32204

    Last Modified: 13 May 2026

    External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

    Published: 12 May 2026
    9.3
    Critical

    CVE-2026-40379

    Last Modified: 21 May 2026

    Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 May 2026
    7.5
    High

    CVE-2026-43891

    Last Modified: 15 May 2026

    changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files. The vulnerable flow starts in the backup restore logic. When a backup ZIP is restored, the application extracts the archive and copies each restored watch UUID directory directly into the live datastore using shutil.copytree(entry.path, dst_dir). This preserves attacker-controlled files inside the restored watch directory, including history.txt. After restore, the application parses history.txt in the watch history property and returns the contents of the targeted local file. This vulnerability is fixed in 0.55.1.

    Published: 12 May 2026
    6.7
    Medium

    CVE-2025-53870

    Last Modified: 15 May 2026

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.

    Published: 12 May 2026
    6.7
    Medium

    CVE-2025-53680

    Last Modified: 15 May 2026

    An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-U 7.0.0 through 7.0.5, FortiAP-U 6.2 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.

    Published: 12 May 2026
    5.3
    Medium

    CVE-2025-67604

    Last Modified: 15 May 2026

    A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.

    Published: 12 May 2026
    7.2
    High

    CVE-2025-53681

    Last Modified: 15 May 2026

    An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.

    Published: 12 May 2026
    4.3
    Medium

    CVE-2026-25690

    Last Modified: 18 May 2026

    An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.

    Published: 12 May 2026
    8.8
    High

    CVE-2025-53844

    Last Modified: 9 Jun 2026

    A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.

    Published: 12 May 2026
    5.5
    Medium

    CVE-2026-44279

    Last Modified: 26 Jun 2026

    An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI.

    Published: 12 May 2026
    2.3
    Low

    CVE-2026-44278

    Last Modified: 16 May 2026

    A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

    Published: 12 May 2026