Export limit exceeded: 401140 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (8473 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-50351 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-07-16 | 7.8 High |
| Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50465 | 1 Microsoft | 7 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 4 more | 2026-07-16 | 7.1 High |
| Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||||
| CVE-2026-45313 | 1 Sandboxie-plus | 1 Sandboxie | 2026-07-16 | 7.7 High |
| Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the sandboxed process or that the function pointer is in the caller address space, and GuiServer::WndHookNotifySlave then calls OpenThread(THREAD_SET_CONTEXT, FALSE, whk->hthread) and QueueUserAPC((PAPCFUNC)whk->hproc, hThread, (ULONG_PTR)req->threadid) as SYSTEM, allowing a sandboxed process to execute arbitrary code in an unsandboxed host process. This issue is fixed in version 1.17.6. | ||||
| CVE-2026-46485 | 1 Lissy93 | 1 Dashy | 2026-07-15 | 8.2 High |
| Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8. | ||||
| CVE-2026-47164 | 1 Dani-garcia | 1 Vaultwarden | 2026-07-15 | 7.7 High |
| Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an attacker-controlled IdP identity asserting a victim email address to bind to and authenticate as that account. This issue is fixed in version 1.36.0. | ||||
| CVE-2026-58617 | 1 Microsoft | 3 365 Copilot, 365 Copilot Ios, 365 Copilot Ios | 2026-07-15 | 8.1 High |
| Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-50342 | 1 Microsoft | 6 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 3 more | 2026-07-15 | 8.8 High |
| Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-55014 | 1 Microsoft | 2 Remote Help, Windows-remote-help | 2026-07-15 | 7.8 High |
| Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50335 | 1 Microsoft | 14 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 11 more | 2026-07-15 | 7.8 High |
| Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50418 | 1 Microsoft | 8 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 5 more | 2026-07-15 | 5.1 Medium |
| Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. | ||||
| CVE-2026-50495 | 1 Microsoft | 14 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 11 more | 2026-07-15 | 6.1 Medium |
| Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | ||||
| CVE-2026-50423 | 1 Microsoft | 12 Windows 10 21h2, Windows 10 21h2, Windows 10 22h2 and 9 more | 2026-07-15 | 7.8 High |
| Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50373 | 1 Microsoft | 14 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 11 more | 2026-07-15 | 7.8 High |
| Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-20744 | 1 Hydro-québec | 1 Le Circuit Electrique Charging Station Backend | 2026-07-15 | 9.8 Critical |
| The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation. | ||||
| CVE-2026-57855 | 1 Agentejo | 1 Cockpit | 2026-07-14 | 8.8 High |
| Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only. | ||||
| CVE-2026-50325 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-07-14 | 7 High |
| Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-49805 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-07-14 | 7 High |
| Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50311 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-07-14 | 7.8 High |
| Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-50297 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-07-14 | 7 High |
| Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-15627 | 1 Nextlevelbuilder | 1 Goclaw | 2026-07-14 | 4.3 Medium |
| A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure. The attack may be performed from remote. The exploit is publicly available and might be used. | ||||