High · CVSS 8.7
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Published Jul 3, 2026 · Updated Jul 24, 2026
High · CVSS 8.8
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published Jul 3, 2026 · Updated Jul 24, 2026
Medium · CVSS 6.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.8
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 6.4
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 6.5
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.1
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.4
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.1
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.5
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.1
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 5.3 · CISA KEV
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8 · CISA KEV
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 4.2
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
Published Jul 3, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 6.1
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 6.6
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 6.5
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.4
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.1
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.8
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.8
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.5
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 5.4
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Property Manager accessible data as well as unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published Jul 21, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.2
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
Critical · CVSS 9.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.8
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.4
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.1
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
Published Jul 14, 2026 · Updated Jul 24, 2026
Medium · CVSS 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.5
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.8
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 8.4
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026
High · CVSS 7.8
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Jul 24, 2026