VYPR

CVEs

345,753 total · page 126 of 6,916

  • CVE-2026-42914MedJun 9, 2026
    risk 0.34cvss 5.3epss 0.01

    Windows Kerberos Denial of Service Vulnerability

  • CVE-2026-42913HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42912HigJun 9, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42911HigJun 9, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42910HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42909HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42908HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-42907MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

  • CVE-2026-42906MedJun 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

  • CVE-2026-42905HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.02

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42904CriJun 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

  • CVE-2026-42903MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.01

    Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

  • CVE-2026-42902HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42837HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42836HigJun 9, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42835HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

  • CVE-2026-42829HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-42828HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42771MedJun 9, 2026
    risk 0.33cvss 6.2epss 0.00

    Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen. Impact summary: This out of bounds read will not directly exfiltrate the data read…

  • CVE-2026-42770LowJun 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small…

  • CVE-2026-42769MedJun 9, 2026
    risk 0.27cvss 5.3epss 0.00

    Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration…

  • CVE-2026-42768LowJun 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output. Impact summary: The Bleichenbacher-style attack allows an…

  • CVE-2026-42767MedJun 9, 2026
    risk 0.31cvss 5.9epss 0.00

    Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker…

  • CVE-2026-42766MedJun 9, 2026
    risk 0.31cvss 5.9epss 0.01

    Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service. The CMS PasswordRecipientInfo.keyDerivationAlgori…

  • CVE-2026-42765HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL…

  • CVE-2026-42764HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server…

  • CVE-2026-42599MedJun 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element…

  • CVE-2026-42573MedJun 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.

  • CVE-2026-42570HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than…

  • CVE-2026-42567HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.

  • CVE-2026-41108HigJun 9, 2026
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-41098HigJun 9, 2026
    risk 0.55cvss 8.4epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-41092HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

  • CVE-2026-40409HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

  • CVE-2026-40404HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

  • CVE-2026-40376HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-40371HigJun 9, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-3088MedJun 9, 2026
    risk 0.32cvss epss 0.00

    Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

  • CVE-2026-38615CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.01

    DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

  • CVE-2026-35188MedJun 9, 2026
    risk 0.26cvss 5.0epss 0.00

    Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path. Impact summary: Successful exploitation allows an attacker to corrupt…

  • CVE-2026-34692MedJun 9, 2026
    risk 0.35cvss 5.4epss 0.00

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the…

  • CVE-2026-34335HigJun 9, 2026
    risk 0.45cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-34183HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the…

  • CVE-2026-34182CriJun 9, 2026
    risk 0.52cvss 9.1epss 0.00

    Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these…

  • CVE-2026-34181HigJun 9, 2026
    risk 0.41cvss 7.4epss 0.00

    Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery. Impact Summary: An attacker impersonating a user…

  • CVE-2026-34180HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application…

  • CVE-2026-33828HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

  • CVE-2026-33113MedJun 9, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-32193HigJun 9, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

  • CVE-2026-28301MedJun 9, 2026
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.