Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,381
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 741 - 760 of 11,898 CVEs
CVE-2026-42902 HIGH - 7.8

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: powertoys
Published: Jun 09, 2026
Source: NVD
CVE-2026-42837 HIGH - 7.8

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1809
Published: Jun 09, 2026
Source: NVD
CVE-2026-42836 HIGH - 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42835 HIGH - 8.1

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Vendor: microsoft
Product: teams
Published: Jun 09, 2026
Source: NVD
CVE-2026-42829 HIGH - 7.8

Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_11_24h2
Published: Jun 09, 2026
Source: NVD
CVE-2026-42828 HIGH - 7.8

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1809
Published: Jun 09, 2026
Source: NVD
CVE-2026-42765 HIGH - 7.5

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can tri...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-42764 HIGH - 7.5

Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-41108 HIGH - 7.0

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-41098 HIGH - 8.4

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

Published: Jun 09, 2026
Source: NVD
CVE-2026-41092 HIGH - 7.8

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40409 HIGH - 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40404 HIGH - 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40376 HIGH - 7.5

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: visual_studio_code
Published: Jun 09, 2026
Source: NVD
CVE-2026-40371 HIGH - 8.8

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

Published: Jun 09, 2026
Source: NVD
CVE-2026-34335 HIGH - 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-34183 HIGH - 7.5

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUI...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-34181 HIGH - 7.4

Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery. Impact Summary: An attacker impersonating a user can cause a service r...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-34180 HIGH - 7.5

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to l...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-33828 HIGH - 7.8

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD