VYPR

CVEs

38,011 total · page 21 of 761

  • CVE-2026-44807HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2026-44804HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2026-44803HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

  • CVE-2026-44802HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2026-44801HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-44799HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42993HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42992HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42991HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42989HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.02

    Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42987HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42986HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.02

    Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42985HigJun 9, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42984HigJun 9, 2026
    risk 0.45cvss 7.0epss 0.00

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42983HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42981HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42980HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.06

    Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42979HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42978HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42977HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42974HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42916HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42913HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42912HigJun 9, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42911HigJun 9, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42910HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42909HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42908HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-42905HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.02

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42902HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42837HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42836HigJun 9, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42835HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

  • CVE-2026-42829HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-42828HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42765HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL…

  • CVE-2026-42764HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server…

  • CVE-2026-42570HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than…

  • CVE-2026-42567HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.

  • CVE-2026-41108HigJun 9, 2026
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-41098HigJun 9, 2026
    risk 0.55cvss 8.4epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-41092HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

  • CVE-2026-40409HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

  • CVE-2026-40404HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

  • CVE-2026-40376HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-40371HigJun 9, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-34335HigJun 9, 2026
    risk 0.45cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-34183HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the…

  • CVE-2026-34181HigJun 9, 2026
    risk 0.41cvss 7.4epss 0.00

    Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery. Impact Summary: An attacker impersonating a user…

  • CVE-2026-34180HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application…