EN
en direct
cve

Archive complète

Veille des vulnérabilités
identifiantvulnérabilitésévéritépublié
CVE-2026-49853Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6. Élevée CVSS 7.7 14/07 CVE-2026-49855Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6. Élevée CVSS 7.5 14/07 CVE-2026-49981Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.Symfony Twig Élevée CVSS 8.2 14/07 CVE-2026-50130Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.Analyse NVD en cours Élevée CVSS 8.8 14/07 CVE-2026-50293Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 14/07 CVE-2026-50296Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 14/07 CVE-2026-50297Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 14/07 CVE-2026-50301Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 14/07 CVE-2026-50304Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 14/07 CVE-2026-50305Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50306Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50307Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 14/07 CVE-2026-50308Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50309Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50311Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50312Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50313Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50314Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 14/07 CVE-2026-50315Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50317Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 14/07 CVE-2026-50318Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50321Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 14/07 CVE-2026-50322Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 14/07 CVE-2026-50323Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 14/07 CVE-2026-50325Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 14/07 CVE-2026-50326Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 14/07 CVE-2026-50327Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50328Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 14/07 CVE-2026-50329Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 14/07 CVE-2026-50330Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 14/07 CVE-2026-50331Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50332Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50333Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50335Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 14/07 CVE-2026-50336Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50337Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50338Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.Microsoft Azure Spring Cloud Élevée CVSS 8.2 14/07 CVE-2026-50340Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 Élevée CVSS 8.8 14/07 CVE-2026-50342Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 8.8 14/07 CVE-2026-50343Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 14/07 CVE-2026-50344Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50345Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 14/07 CVE-2026-50346Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50347Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50348Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1809 Élevée CVSS 8.1 14/07 CVE-2026-50351Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50353Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50354Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.1 14/07 CVE-2026-50355Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 14/07 CVE-2026-50356Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 14/07 CVE-2026-50357Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50358Use after free in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50359Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50360Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 21h2 Élevée CVSS 8.8 14/07 CVE-2026-50361Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50362Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50363Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50364Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.3 14/07 CVE-2026-50365Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.Microsoft Windows 10 1607 Élevée CVSS 8 14/07 CVE-2026-50367Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 14/07 CVE-2026-50368Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 14/07 CVE-2026-50369Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 14/07 CVE-2026-50370Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.Microsoft Windows 10 1607 Élevée CVSS 8.8 14/07 CVE-2026-50371Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 14/07 CVE-2026-50372Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 14/07 CVE-2026-50373Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 14/07 CVE-2026-50375Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 14/07 CVE-2026-50377Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50378Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7 14/07 CVE-2026-50379Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 Élevée CVSS 7.5 14/07 CVE-2026-50380Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.6 14/07 CVE-2026-50382Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.Microsoft Windows 10 1809 Élevée CVSS 8.8 14/07 CVE-2026-50384Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7 14/07 CVE-2026-50385Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 8.8 14/07 CVE-2026-50386Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50387Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.Microsoft 365 Copilot Élevée CVSS 7.8 14/07 CVE-2026-50388Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50390Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50391Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50392Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 14/07 CVE-2026-50393Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50396Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50397Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 14/07 CVE-2026-50398Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 Élevée CVSS 7.5 14/07 CVE-2026-50399Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 14/07 CVE-2026-5040TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.Analyse NVD en cours Élevée CVSS 7.1 14/07 CVE-2026-50400Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50402Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50403Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 14/07 CVE-2026-50404Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 14/07 CVE-2026-50405Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50406Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 14/07 CVE-2026-50407Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50410Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7 14/07 CVE-2026-50411Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 14/07 CVE-2026-50412Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07 CVE-2026-50413Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 14/07 CVE-2026-50414Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 Élevée CVSS 8.8 14/07 CVE-2026-50415Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1809 Élevée CVSS 7.5 14/07 CVE-2026-50417Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 14/07
8901–9000 / 11286 CVE

Tapez au moins deux caractères.

naviguer ouvrir esc fermer