cve
Vulnerability watch Full archive
idvulnerabilityseveritypublished
CVE-2026-50471Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50474Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50476Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50477Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50478Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50479Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50480Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50482Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50484Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50486Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 CVE-2026-50487Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 Critical CVSS 9.8 CVE-2026-50488Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50489Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50490Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50491Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50493Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50494Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50496Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50497Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50498Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityMicrosoft Windows 10 1607 High CVSS 7.8 CVE-2026-50499Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50500Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50501Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50502Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50503Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50504Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50505Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50506Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.Microsoft Asp.net Core Odata High CVSS 7.5 CVE-2026-50509Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50510Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.Microsoft Github Copilot High CVSS 7.8 CVE-2026-50518Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-50520Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.Microsoft Visual Studio Code High CVSS 8.4 CVE-2026-50524Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.Microsoft .net High CVSS 7.5 CVE-2026-50525Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50527Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50528Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.Microsoft .net High CVSS 8.2 CVE-2026-50646Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.Microsoft .net Framework High CVSS 7.8 CVE-2026-50647Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50648Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50649Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.Microsoft .net Framework High CVSS 7.8 CVE-2026-50650Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.Microsoft .net Framework High CVSS 7.8 CVE-2026-50651Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.Microsoft .net High CVSS 7.5 CVE-2026-50652Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50653Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.Microsoft .net Framework High CVSS 7.5 CVE-2026-50655Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50658Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.Microsoft Defender For Endpoint High CVSS 7 CVE-2026-50663Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.Microsoft Age Of Empires Ii High CVSS 8.8 CVE-2026-50666Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50667Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50669Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50670Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50672Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-50673Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50674Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50675Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-50676Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50677Use after free in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50679Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50680Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50682Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.Microsoft Windows 10 21h2 High CVSS 7.1 CVE-2026-50683Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.Microsoft Windows 10 1607 High CVSS 8 CVE-2026-50685Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50686Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 CVE-2026-50687Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50688Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-50689Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50692Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50694Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 CVE-2026-50695Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-50696Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1809 High CVSS 7.5 CVE-2026-50697Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-51105Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler. High CVSS 7.5 CVE-2026-51807Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_length[128]. A crafted JPEG 2000 codestream containing malformed PPM packet headers can trigger a heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp due to missing bounds validation for the j2k_codeblock::pass_length[128] array which can lead to heap corruption and process termination. Critical CVSS 9.8 CVE-2026-51808Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp Critical CVSS 9.8 CVE-2026-52100Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function High CVSS 7.5 CVE-2026-52101An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go Critical CVSS 9.1 CVE-2026-5269In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.NVD analysis in progress Critical CVSS 9.8 CVE-2026-5270An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls.NVD analysis in progress Critical CVSS 9.8 CVE-2026-53486The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.NVD analysis in progress Critical CVSS 9.1 CVE-2026-53565Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows.
This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.NVD analysis in progress High CVSS 8.5 CVE-2026-53633Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta.NVD analysis in progress Critical CVSS 9.8 CVE-2026-54058Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.NVD analysis in progress High CVSS 8.3 CVE-2026-54107Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-54109Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-54111Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-54112Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-54114Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-54115Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-54117Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.Microsoft Sql Server 2016 High CVSS 8.8 CVE-2026-54118Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.Microsoft Sql Server 2016 High CVSS 8.8 CVE-2026-54119Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-54121Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-54122Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 8.4 CVE-2026-54124Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.Microsoft Terminal High CVSS 7.8 CVE-2026-54125Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-54127Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 8.4 CVE-2026-54128Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 8.4 CVE-2026-54129Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-54131Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-54429A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application becomes inaccessible and requires a manual restart; no project data is lost. Successful exploitation requires a specific project configuration to be already active on the targeted instance. High CVSS 7.4 2901–3000 / 5155 CVE