| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-25172 | Hig | 0.52 | 8.0 | 0.01 | Mar 10, 2026 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-25171 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-25170 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-25167 | Hig | 0.48 | 7.4 | 0.00 | Mar 10, 2026 | Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-25166 | Hig | 0.51 | 7.8 | 0.02 | Mar 10, 2026 | Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally. | ||
| CVE-2026-25165 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24296 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24295 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24294 | Hig | 0.51 | 7.8 | 0.05 | Mar 10, 2026 | Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24293 | Hig | 0.51 | 7.8 | 0.01 | Mar 10, 2026 | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24292 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24291 | Hig | 0.51 | 7.8 | 0.03 | Mar 10, 2026 | Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24290 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24289 | Hig | 0.51 | 7.8 | 0.04 | Mar 10, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24287 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24285 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24283 | Hig | 0.57 | 8.8 | 0.00 | Mar 10, 2026 | Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-24018 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root. | ||
| CVE-2026-24017 | Hig | 0.53 | 8.1 | 0.01 | Mar 10, 2026 | An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote… | ||
| CVE-2026-23674 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-23673 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23672 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | ||
| CVE-2026-23671 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23669 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Use after free in RPC Runtime allows an authorized attacker to execute code over a network. | ||
| CVE-2026-23668 | Hig | 0.46 | 7.0 | 0.04 | Mar 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23667 | Hig | 0.46 | 7.0 | 0.00 | Mar 10, 2026 | Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23665 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23664 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-23662 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-23661 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-23660 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23654 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-23239 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths… | ||
| CVE-2026-22627 | Hig | 0.57 | 8.8 | 0.00 | Mar 10, 2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a… | ||
| CVE-2026-22572 | Hig | 0.47 | 7.2 | 0.01 | Mar 10, 2026 | An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2… | ||
| CVE-2026-21262 | Hig | 0.57 | 8.8 | 0.02 | Mar 10, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20967 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-1261 | Hig | 0.47 | 7.2 | 0.00 | Mar 10, 2026 | The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | ||
| CVE-2025-68648 | Hig | 0.47 | 7.2 | 0.01 | Mar 10, 2026 | A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7,… | ||
| CVE-2025-66178 | Hig | 0.47 | 7.2 | 0.02 | Mar 10, 2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may… | ||
| CVE-2025-56421 | Hig | 0.42 | 7.5 | 0.00 | Mar 10, 2026 | SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database. | ||
| CVE-2025-54820 | Hig | 0.53 | 8.1 | 0.01 | Mar 10, 2026 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests,… | ||
| CVE-2025-13957 | Hig | 0.49 | — | 0.01 | Mar 10, 2026 | CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default. | ||
| CVE-2025-11739 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization. | ||
| CVE-2026-3585 | Hig | 0.42 | 7.5 | 0.00 | Mar 10, 2026 | The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of… | ||
| CVE-2026-30925 | Hig | 0.42 | 7.5 | 0.00 | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtracking, blocking the Node.js… | ||
| CVE-2026-30920 | Hig | 0.56 | 8.6 | 0.00 | Mar 10, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is… | ||
| CVE-2026-30919 | Hig | 0.49 | 7.6 | 0.00 | Mar 10, 2026 | facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from an untrusted source and includes that data in its subsequent HTTP responses in… | ||
| CVE-2026-30918 | Hig | 0.49 | 7.6 | 0.00 | Mar 10, 2026 | facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabilities. It is possible to… | ||
| CVE-2026-30917 | Hig | 0.57 | — | 0.00 | Mar 10, 2026 | Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute whenever a user views that table's corresponding Bucket namespace page. This… |
- risk 0.52cvss 8.0epss 0.01
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.02
Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.05
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.04
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.00
Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
- risk 0.53cvss 8.1epss 0.01
An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote…
- risk 0.49cvss 7.5epss 0.01
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.01
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
- risk 0.46cvss 7.0epss 0.04
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.01
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.01
Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths…
- risk 0.57cvss 8.8epss 0.00
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a…
- risk 0.47cvss 7.2epss 0.01
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2…
- risk 0.57cvss 8.8epss 0.02
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
- risk 0.47cvss 7.2epss 0.00
The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
- risk 0.47cvss 7.2epss 0.01
A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7,…
- risk 0.47cvss 7.2epss 0.02
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may…
- risk 0.42cvss 7.5epss 0.00
SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.
- risk 0.53cvss 8.1epss 0.01
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests,…
- risk 0.49cvss —epss 0.01
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.
- risk 0.51cvss 7.8epss 0.00
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
- risk 0.42cvss 7.5epss 0.00
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of…
- risk 0.42cvss 7.5epss 0.00
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtracking, blocking the Node.js…
- risk 0.56cvss 8.6epss 0.00
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is…
- risk 0.49cvss 7.6epss 0.00
facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from an untrusted source and includes that data in its subsequent HTTP responses in…
- risk 0.49cvss 7.6epss 0.00
facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabilities. It is possible to…
- risk 0.57cvss —epss 0.00
Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute whenever a user views that table's corresponding Bucket namespace page. This…