By severity

High-severity vulnerabilities

CVEs rated High by CVSS, with SEC.co remediation and prioritization guidance.

2469 published vulnerabilities · page 25 of 25

  • CVE-2026-49134HIGH 7.1

    CodexBar versions before 0.32.0 contain a local privilege escalation flaw in the CLI installer. An attacker with access to the same system can intercept and modify the installer's temporary files during the installation process, tricking the system into running malicious commands with root-level privileges. This requires the attacker to be on the same machine and to time their interference with an active installation, but once successful, grants complete system control.

  • CVE-2026-49135HIGH 7.1

    CodexBar versions before 0.32.0 have a serious flaw in how they handle temporary files during the app release and notarization process. An attacker with access to the same machine can steal the App Store Connect API credentials or sabotage the build artifacts before they're submitted to Apple. The vulnerability exists because CodexBar writes sensitive files to predictable, fixed locations that any local user can read or manipulate.

  • CVE-2026-49141HIGH 7.1

    WACRM contains an authorization flaw that allows someone with valid login credentials to view and change contact records from other customers. The vulnerability exists in the automation engine and doesn't properly verify that the attacker owns the contact they're modifying. An attacker needs only to know a contact's ID number to change things like names, email addresses, and company information across different customer accounts.

  • CVE-2026-49295HIGH 7.1

    libde265, an open-source H.265 video codec library, contains a flaw where a specially crafted video file can cause the decoder to write data beyond the boundaries of an internal array. This happens during the processing of reference picture sets—a critical step in decoding H.265 video. The vulnerability can lead to application crashes or memory corruption, affecting any system that uses libde265 to decode H.265 video streams. The issue was patched in version 1.0.20.

  • CVE-2026-49338HIGH 7.1

    Gonic is an open-source music streaming server that implements the Subsonic API. Before version 0.21.0, two API endpoints failed to properly check which user is asking for access to playlists. This means any logged-in user—even with limited privileges—could delete playlists belonging to any other user, including administrators, and read the contents of private playlists if they could guess or find the playlist ID. The vulnerability stems from the fact that playlist IDs are predictable (based on user IDs and filenames) and sometimes publicly exposed before being marked private. This breaks the isolation between user accounts that the system is supposed to maintain.

  • CVE-2026-49339HIGH 7.1

    Gonic, a free software Subsonic server implementation, contains a path traversal vulnerability that undermines a previously-patched access control check. An authenticated user can craft a malicious playlist ID containing path traversal sequences to bypass ownership verification, allowing them to read, delete, or probe other users' playlists and arbitrary files on the server. The vulnerability was introduced when the maintainer attempted to fix a related issue by checking playlist ownership—but failed to sanitize the playlist ID parameter itself, leaving the door open to directory traversal attacks. Version 0.21.0 and later contain the fix.

  • CVE-2026-49346HIGH 7.1

    libde265 is a video codec library used to decode H.265 video streams. A flaw in versions before 1.1.0 occurs when processing specially crafted video files with specific dimension and bit-depth properties. The vulnerability allows an attacker to trigger a memory overflow that corrupts the heap, potentially crashing applications or enabling further compromise. An attacker would need to trick a user into opening a malicious video file, but no special privileges are required.

  • CVE-2026-49371HIGH 7.1

    JetBrains TeamCity versions prior to 2026.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the keyword filter feature. An attacker can craft a malicious URL containing unsanitized input that, when visited by a TeamCity user, executes arbitrary JavaScript in the victim's browser within the context of the TeamCity application. This allows session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.

  • CVE-2026-49373HIGH 7.1

    JetBrains TeamCity versions prior to 2026.1 contain a remote code execution vulnerability accessible through the Perforce connection configuration interface. An authenticated user with permissions to modify Perforce settings can execute arbitrary code on the TeamCity server. This requires valid credentials and access to TeamCity's configuration features, but does not require user interaction or special system conditions once access is gained.

  • CVE-2026-49396HIGH 7.1

    Nezha Monitoring, a self-hosted server and website monitoring tool, contains a cross-site request forgery (CSRF) vulnerability that allows attackers to trick users into executing malicious cron commands on connected agents. An attacker can craft a specially designed webpage or email that, when visited by an authenticated Nezha administrator, silently triggers unwanted scheduled tasks on monitored servers. This happens because the application doesn't properly validate requests coming from external sources. The vulnerability affects all versions from 1.0.0 through 2.0.13, and has been resolved in version 2.0.14 and later.

  • CVE-2026-50146HIGH 7.1

    Astro, a popular web framework, contains a reflected cross-site scripting (XSS) vulnerability in versions before 6.3.3. When components use client-side directives, Astro fails to properly escape slot names before inserting them into HTML attributes. An attacker can exploit this by crafting a malicious slot name that breaks out of the attribute context and injects arbitrary HTML code. The vulnerability occurs during server-side rendering (SSR), meaning the injected content is reflected back to users without proper sanitization, allowing attackers to steal session tokens, redirect users, or perform actions on their behalf.

  • CVE-2026-5230HIGH 7.1

    CVE-2026-5230 is a high-severity access control flaw in MIA Technology Inc.'s Pizzy Library that allows authenticated users to bypass authorization checks and access data or functionality they shouldn't have permission to reach. The vulnerability stems from incorrectly configured security levels that fail to properly validate user privileges. Versions 1.0.0.26250 through 1.3.8.26250 are affected; upgrading to 1.3.9.26250 or later resolves the issue.

  • CVE-2026-5233HIGH 7.1

    CVE-2026-5233 is a flaw in MIA Technology Inc.'s Pizzy Library that allows authenticated users to overwhelm the system by making requests at abnormally high frequencies. An attacker with valid credentials can trigger excessive interactions that degrade service availability and may corrupt or modify data in transit. The vulnerability affects versions 1.0.0.26250 through 1.3.8.26250. While it requires authentication to exploit, the damage potential—particularly availability and integrity impacts—makes this a material risk for any system using vulnerable versions.

  • CVE-2026-52719HIGH 7.1

    A flaw in GStreamer's JPEG decoder allows an attacker to craft a malicious JPEG file that, when opened, causes the application to read data outside the bounds of the file buffer. This can crash the application or potentially leak sensitive information from memory. The vulnerability requires user interaction—someone must open the specially crafted file—but requires no special privileges and spreads easily via email, messaging, or web downloads.

  • CVE-2026-52722HIGH 7.1

    GStreamer, a widely-used multimedia framework, contains a flaw in how it processes VMnc video streams—a format used for remote desktop and screen recording. An attacker can craft a malicious VMnc file with artificially large cursor dimensions that causes the decoder to mishandle size calculations. This integer overflow bypasses safety checks meant to prevent reading beyond allocated memory, potentially allowing the attacker to crash the application or extract sensitive data from memory. The attack requires user interaction: a victim must be tricked into opening the malicious file.

  • CVE-2026-53674HIGH 7.1

    BuddyPress 14.4.0 has a flaw in how it processes @mention names when a specific username compatibility feature is enabled. Attackers can craft malicious mention text containing special regex characters that slip past the software's input sanitization, allowing them to probe the database for usernames or crash the system through resource exhaustion. The vulnerability requires an attacker to be logged in but poses meaningful risk to information disclosure and availability.

  • CVE-2026-53689HIGH 7.1

    A vulnerability in libnfs (an open-source NFS client library) allows attackers to trigger an integer overflow by connecting to a malicious NFS server that sends specially crafted data. The flaw stems from insufficient validation of string sizes during data parsing, potentially allowing an attacker to cause memory corruption, information disclosure, or limited system unavailability. An attacker would need to trick a user into connecting to a compromised or attacker-controlled NFS server, making this a network-based but not trivially exploitable threat.

  • CVE-2026-53703HIGH 7.1

    GStreamer's RealMedia file parser has a buffer-reading flaw that can crash applications or leak memory contents. When a malicious or malformed RealMedia (.rm) file contains an undersized audio header, the parser reads past the end of its data buffer, potentially accessing uninitialized or sensitive memory. The vulnerability requires user interaction—someone must open a crafted file—but poses a meaningful risk to applications that automatically process media files or expose the parser to untrusted sources.

  • CVE-2026-53704HIGH 7.1

    GStreamer, a popular multimedia framework, contains a vulnerability in its RealMedia file parser that can be triggered by opening a malicious .rm file. The parser fails to properly validate boundaries when reading metadata, allowing crafted files to cause the application to hang indefinitely, crash, or leak memory. An attacker simply needs to trick a user into opening a specially constructed RealMedia file—no special network access or authentication is required. The flaw affects the gst-plugins-ugly package, which is commonly installed alongside GStreamer for handling restricted multimedia formats.

  • CVE-2026-53840HIGH 7.1

    OpenClaw versions before 2026.5.12 inadvertently leak sensitive authentication headers—such as API keys and tenant-routing credentials—when handling cross-origin redirects through its streamable-http Model Context Protocol (MCP) servers. An attacker who controls or compromises an MCP endpoint can exploit this by redirecting requests to an attacker-controlled domain, capturing those headers in transit. This is a credential exfiltration risk that requires authentication to trigger but carries significant impact once exploited.

  • CVE-2026-53842HIGH 7.1

    OpenClaw versions before 2026.5.2 contain a flaw that allows attackers with repository access to inject malicious environment variables into workspace configuration files. When users run Gmail setup commands through gcloud, the tool may be tricked into using an attacker-controlled Python interpreter instead of the legitimate one, potentially leading to arbitrary code execution on the developer's machine. The vulnerability requires user interaction (a developer running the setup process) but no special system privileges.

  • CVE-2026-53846HIGH 7.1

    OpenClaw before version 2026.4.29 contains a vulnerability that allows attackers to hijack the package manager used during dependency installation. An attacker with access to a workspace can craft a malicious .env file that tricks the install process into running an unauthorized package manager executable. This could enable them to inject malicious code into the build environment and compromise software artifacts.

  • CVE-2026-53858HIGH 7.1

    OpenClaw versions before 2026.5.2 contain a vulnerability that allows attackers to manipulate how the application loads software dependencies. By controlling an environment variable called STATE_DIRECTORY in a workspace configuration file, an attacker can trick OpenClaw into loading malicious code from attacker-controlled locations on the same computer. This attack requires local access and user interaction (such as a developer opening a project), but if successful, it can lead to arbitrary code execution during the dependency resolution process.

  • CVE-2026-53863HIGH 7.1

    OpenClaw versions before 2026.4.25 have a flaw in how they validate group identifiers when making access control decisions for tool invocations. An attacker with basic authentication credentials can supply a crafted group ID that the system fails to properly validate, leading to incorrect policy enforcement. This could allow the attacker to invoke tools or perform actions they should not have permission to access, effectively bypassing the intended security controls that restrict who can use what tools.

  • CVE-2026-53865HIGH 7.1

    OpenClaw versions before 2026.5.2 contain a vulnerability that allows a local attacker with user-level access to execute arbitrary executables on the system. The flaw exists in how the maintenance task system handles file paths: an attacker can manipulate workspace-derived environment paths to trick the system into running their chosen command instead of the intended maintenance cleanup utility. This gives an attacker the ability to run code with the privileges of the OpenClaw process during routine maintenance operations.

  • CVE-2026-53915HIGH 7.1

    JetBrains GoLand before version 2026.1.3 contains a remote code execution vulnerability triggered when developers open untrusted project configurations. An attacker can craft a malicious project file that executes arbitrary code on a developer's machine without requiring any special permissions or complex user interaction beyond opening the project. This affects GoLand across all network environments.

  • CVE-2026-54198HIGH 7.1

    Media Library Assistant versions 3.35 and earlier contain an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the application without requiring a login. An attacker can craft a malicious link and trick a user into clicking it, causing the victim's browser to execute the injected code within the context of the Media Library Assistant application. This could lead to session hijacking, credential theft, or malware distribution.

  • CVE-2026-54290HIGH 7.1

    Hono, a JavaScript web framework supporting multiple runtimes, has a cross-origin request forgery vulnerability in its CORS middleware. When CORS is configured to allow credentials (a common requirement for authenticated APIs) without explicitly restricting which origins can access the application, the middleware will mirror back whatever origin made the request and grant it credential access. This means any website can trick a user's browser into making authenticated requests to a Hono application and read the responses—essentially stealing the user's session. The flaw affects versions before 4.12.25 and is particularly dangerous because the vulnerable configuration may feel like a reasonable default to developers unfamiliar with CORS security nuances.

  • CVE-2026-56209HIGH 7.1

    A critical flaw exists in libaom, the open-source reference implementation of the AV1 video codec. An attacker can craft malicious video frames that exploit a missing validation check in the Scalable Video Coding layer, allowing them to write data to arbitrary memory locations on a system running a vulnerable encoder. This could crash the encoder (denial of service) or potentially allow the attacker to execute arbitrary code. The vulnerability is particularly dangerous because it requires no prior information disclosure to exploit—an attacker who can feed frames to a network-accessible encoder, such as in a transcoding service or live stream ingestion pipeline, can trigger the flaw reliably.

  • CVE-2026-56210HIGH 7.1

    A bounds-checking flaw in libaom, the reference implementation of the AV1 video codec, allows attackers to read unintended memory from the heap. An attacker who can send specially crafted video encoding parameters—particularly by setting an SVC (Scalable Video Coding) layer identifier beyond the legitimate range—can trigger the vulnerability. The result is either exposure of sensitive data resident in heap memory or a crash of the encoder process. This matters most to services that accept untrusted video input and run libaom on network-facing infrastructure.

  • CVE-2026-56211HIGH 7.1

    A vulnerability in libaom, the open-source AV1 video codec library, allows an attacker to execute arbitrary code on systems that process untrusted video files with scalable video coding (SVC) features enabled. An attacker crafts malicious video frames that bypass safety checks in the encoder, allowing them to corrupt memory structures that control how the encoder operates. In services that spawn separate processes to handle video encoding, this memory corruption can be leveraged to discover the process layout in memory and ultimately redirect execution to attacker-controlled code. Exploitation requires that the target application uses libaom with SVC encoding active and processes video frames from an untrusted source.

  • CVE-2026-56275HIGH 7.1

    Flowise versions before 3.1.0 contain a server-side request forgery (SSRF) vulnerability in the Execute Flow node. An authenticated attacker can manipulate the base URL field to bypass security controls and force the application to make HTTP requests to internal network addresses, cloud metadata endpoints, and other sensitive systems that should not be directly accessible. This allows reconnaissance and potential lateral movement within your infrastructure.

  • CVE-2026-56280HIGH 7.1

    Cap-go versions before 12.128.2 contain a privilege escalation flaw in their build log streaming feature. An attacker with a read-only API key—which should only permit viewing logs—can actually cancel active native builds by connecting to the log stream and then disconnecting. This happens because the server uses its own privileged credentials to clean up when clients disconnect, rather than checking whether the client itself has permission to cancel builds. The vulnerability allows repeated disruption of build pipelines and CI/CD workflows without requiring elevated API credentials.

  • CVE-2026-56314HIGH 7.1

    Capgo, a mobile app deployment and update platform, contains a flaw that allows attackers with valid credentials to push outdated or intentionally removed app versions to end-user devices. The vulnerability stems from incomplete data filtering when retrieving available app versions during update checks. An authenticated attacker can exploit this by deploying bundles that were previously deleted, potentially exposing users to known bugs, security issues, or malicious code embedded in those older versions. This is a moderate-to-significant risk because it requires authentication but can affect the integrity of deployed software at scale.

  • CVE-2026-8035HIGH 7.1

    CVE-2026-8035 is a denial-of-service vulnerability in National Instruments' PAL kernel driver that allows authenticated local users to crash the system. The flaw stems from inadequate input validation that fails to check for NULL pointers before dereferencing them in memory. An attacker with local system access can exploit this by supplying malformed input to the driver, causing an immediate kernel panic. The vulnerability affects NI-PAL version 26.3.0 and all earlier releases across both Windows and Linux platforms.

  • CVE-2026-8036HIGH 7.1

    NI-PAL, National Instruments' process abstraction layer, contains an input validation flaw that allows authenticated local users to read and modify arbitrary memory regions on affected systems. An attacker with local access could exploit this to escalate their privileges. The vulnerability affects NI-PAL version 26.3.0 and earlier on both Windows and Linux platforms.

  • CVE-2026-8089HIGH 7.1

    The weMail WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to trick authenticated users—including administrators—into clicking malicious links. When a victim clicks a crafted URL, malicious JavaScript executes in their browser with their privileges, potentially allowing attackers to perform actions on their behalf, steal session tokens, or modify site content. The vulnerability exists because user input is not properly sanitized before being inserted into HTML attributes in AJAX responses, and the vulnerable endpoint lacks nonce protection to validate legitimate requests.

  • CVE-2026-8874HIGH 7.1

    Securly Chrome Extension version 3.0.7 downloads security configuration files—specifically crisis alert keywords and filtering rules—over plain HTTP instead of the encrypted HTTPS protocol. While the same extension correctly uses HTTPS for other sensitive data (IWF and CIPA filtering data), this inconsistency leaves downloaded crisis alert configurations vulnerable to interception and modification by network-positioned attackers. An attacker on the same network could intercept these files and inject malicious keywords or rules, potentially disrupting the extension's security functionality or causing it to behave unexpectedly.

  • CVE-2026-9570HIGH 7.1

    The Taskbuilder WordPress plugin before version 5.0.8 contains a reflected cross-site scripting (XSS) vulnerability in its frontend shortcode functionality. An attacker can craft a malicious URL containing JavaScript code that, when visited by a logged-in user, executes in the context of that user's browser session. The vulnerability stems from inadequate sanitization of a URL parameter before it is output directly into inline JavaScript code on the page. This allows an attacker to hijack user sessions, steal sensitive data, or perform actions on behalf of the victim within WordPress.

  • CVE-2026-9808HIGH 7.1

    Mautic 7's API has a flaw where user permission restrictions aren't being honored properly. Specifically, permissions designed to let users only see or edit their own resources (called 'owner-scope' restrictions) are being bypassed. An attacker with low-level API access can exploit this to view or modify other users' data, even though they shouldn't have that permission.

  • CVE-2024-38487HIGH 7.0

    CVE-2024-38487 is a container escape vulnerability affecting api-gateway containers that run with root privileges. An attacker with local access to a system running a vulnerable api-gateway container could break out of the container and gain access to the underlying host system, potentially allowing them to modify, delete, or disable critical services and data. The vulnerability requires local access and some effort to exploit, but the consequences—full host compromise—are severe.

  • CVE-2026-0083HIGH 7.0

    A race condition in Android's NFC (Near Field Communication) event handling code allows a local attacker with basic system access to escalate their privileges to access sensitive data or modify system files. The vulnerability requires precise timing exploitation but no special permissions or user interaction to trigger, making it a significant local security concern.

  • CVE-2026-0125HIGH 7.0

    CVE-2026-0125 is a race condition vulnerability in Android's VPU (Video Processing Unit) driver that allows a local attacker to escalate their privileges. An attacker with a low-privilege local account can trigger a use-after-free condition in the vpu_ioctl.c file by timing requests carefully, potentially gaining higher-level access to the device without needing special permissions or user interaction. This is a serious flaw because it requires only local access and basic user privileges to exploit.

  • CVE-2026-34335HIGH 7.0

    A use-after-free memory vulnerability exists in Windows Ancillary Function Driver for WinSock (AFD.sys), affecting Windows 10 and Windows 11 across multiple versions, as well as Windows Server 2012 through 2025. An authenticated local attacker can exploit this flaw to escalate their privileges to SYSTEM level. The vulnerability requires local access and specific conditions to trigger, but once exploited, grants complete control over the affected system.

  • CVE-2026-41108HIGH 7.0

    A memory safety flaw in Windows DNS could allow someone with local system access to break out of normal restrictions and gain full control of the computer. The vulnerability exists because DNS processes input in a way that can overflow a memory buffer, and an attacker positioned locally—such as a low-privilege user or service—could exploit this to run code with elevated permissions. This is not a remote vulnerability, but it poses a significant risk in multi-user or shared-system environments.

  • CVE-2026-42462HIGH 7.0

    Fedify, a TypeScript library for building federated applications using ActivityPub, contains a vulnerability that allows attackers to manipulate cryptographically signed activities without invalidating the signatures. By exploiting JSON-LD (JSON Linked Data) restructuring techniques, an attacker who receives a validly signed activity from a third party can alter its meaning and content while the Linked Data Signature remains valid. This breaks the integrity guarantee that signatures are supposed to provide, enabling attackers to forge or modify federated messages in a way that appears authentic.

  • CVE-2026-42836HIGH 7.0

    A race condition in Windows' Function Discovery Service (fdwsd.dll) allows a user already logged into a machine to escalate their privileges to administrator level. The vulnerability exists because the service does not properly synchronize access to shared resources when multiple processes run concurrently, creating a narrow window where an attacker can manipulate the process. An authorized user would need local access and specific timing to exploit this, but successful exploitation grants full system-level permissions.

  • CVE-2026-42911HIGH 7.0

    A use-after-free memory vulnerability exists in Windows' Ancillary Function Driver for WinSock (AFD.sys). An attacker who already has local access to a machine can exploit this flaw to gain elevated privileges, potentially running code with system-level permissions. The vulnerability requires specific conditions to trigger—it is not trivially exploitable—but once successful grants significant control over the affected system.

  • CVE-2026-42912HIGH 7.0

    A race condition in Windows Telephony Service allows an attacker who already has local user access to exploit improper synchronization of shared resources and gain system-level privileges. The vulnerability requires the attacker to perform specific timing-dependent actions during concurrent operations—making it moderately difficult to exploit in practice, but reliably escalatable once triggered. No user interaction is required beyond the attacker's ability to run code as a local user.

  • CVE-2026-42984HIGH 7.0

    A use-after-free memory vulnerability exists in the Windows Kernel that allows an authorized local user to escalate their privileges to a higher level of access. An attacker with standard user permissions could exploit this flaw to gain system-level control on an affected machine. The vulnerability requires local access and specific conditions to trigger, but successful exploitation would grant complete compromise of the target system.

  • CVE-2026-44495HIGH 7.0

    Axios, a widely-used HTTP client library for JavaScript applications, contains prototype-pollution gadgets that can be exploited if another vulnerability in the same process has already poisoned JavaScript's Object.prototype. The issue affects versions 0.19.0 through 0.31.0 in the 0.x branch and version 1.15.1 in the 1.x branch. By itself, Axios does not cause the initial prototype pollution; instead, it becomes a secondary target once an attacker has already compromised Object.prototype through a separate vulnerability. When this occurs, Axios may incorrectly interpret inherited properties as legitimate request configuration, leading to potential code execution or data exposure. The vulnerability is addressed in Axios 0.31.1 and 1.15.2.

  • CVE-2026-44604HIGH 7.0

    A flaw in RPM's archive extraction tool allows an attacker to run arbitrary commands on a system by crafting a malicious archive with shell metacharacters embedded in its folder name. When a user extracts such an archive using the rpmuncompress utility, the unsanitized folder name is passed directly into a shell command, enabling code execution with the privileges of the extracting user. The vulnerability affects ZIP, 7z, and GEM archive formats.

  • CVE-2026-44818HIGH 7.0

    A race condition vulnerability in Microsoft Office Excel could allow an attacker to execute code on a user's computer. The flaw arises from improper synchronization when multiple processes access shared resources simultaneously. An attacker would need to trick a user into opening a malicious Excel file, but once triggered, the vulnerability can grant full control over the affected system. The vulnerability affects multiple versions of Excel and Office across 365 subscriptions, on-premises deployments, and older perpetual licenses.

  • CVE-2026-45596HIGH 7.0

    A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD) allows an authenticated attacker to elevate their privileges on a local system. The vulnerability requires the attacker to already have user-level access and involves a race condition during memory management. Successfully exploiting it grants the attacker full system-level control.

  • CVE-2026-45597HIGH 7.0

    A race condition vulnerability in Windows UI Automation Manager allows an authorized local user to escalate privileges on affected systems. The flaw arises from improper synchronization when multiple processes access shared resources simultaneously. An attacker with existing local access can exploit timing windows to gain system-level privileges. This is not a remote vulnerability and requires prior authentication or local access, which narrows but does not eliminate the risk in shared computing environments.

  • CVE-2026-45598HIGH 7.0

    A race condition in Windows' Ancillary Function Driver for WinSock (AFD.sys) allows an attacker who already has local access to a system to escalate their privileges to a higher level. The vulnerability stems from improper synchronization when the driver handles shared resources, meaning that under specific timing conditions, an attacker can exploit the flaw to gain elevated permissions. This is not a remote attack—the attacker must already have a foothold on the machine, such as a low-privileged user account or compromised application context.

  • CVE-2026-45601HIGH 7.0

    A race condition in the Windows Ancillary Function Driver for WinSock allows someone already logged into a Windows system to escalate their privileges to a higher level of access. The vulnerability arises from improper synchronization of shared resources, meaning two processes can interfere with each other when accessing the same data simultaneously. An attacker with local user privileges can exploit this timing-dependent flaw to gain elevated system rights, though doing so requires specific conditions and is not trivial to reproduce reliably.

  • CVE-2026-45603HIGH 7.0

    A race condition vulnerability exists in Windows' Ancillary Function Driver for WinSock (AFD) that allows an authorized local user to escalate privileges to a higher level on the system. The flaw arises from improper synchronization when multiple processes access a shared resource simultaneously, creating a narrow window of opportunity for an attacker to manipulate the driver's behavior. An authenticated user with basic local access can exploit this to gain elevated privileges, potentially achieving full system compromise. This is not a remote vulnerability and requires the attacker already has some level of access to the target machine.

  • CVE-2026-45640HIGH 7.0

    A use-after-free vulnerability in the Windows Bluetooth Port Driver permits a user with local system access to escalate their privileges to a higher level. The flaw exists because the driver fails to properly manage memory when Bluetooth port operations conclude, leaving a freed memory region accessible for malicious manipulation. An attacker must already have some level of local authentication and user rights to exploit this issue, but successful exploitation grants full system control.

  • CVE-2026-45653HIGH 7.0

    A heap-based buffer overflow vulnerability in the Windows Kernel allows a user with local system access to overflow a memory buffer, enabling them to execute code with elevated privileges. The attack requires an authenticated user account and moderate technical effort to exploit, but if successful grants attacker control over the affected system. This is a local privilege escalation issue, not a remote attack vector.

  • CVE-2026-46154HIGH 7.0

    A race condition exists in the Linux kernel's scheduler extension (sched_ext) cgroup interface that can lead to use-after-free memory access. When system administrators adjust cgroup scheduling parameters like weight, idle status, or bandwidth, the kernel reads a pointer to the scheduler without proper synchronization. If another process simultaneously disables and re-enables a different scheduler, the cached pointer becomes stale and points to freed memory. When the original operation tries to use this pointer, it dereferences already-freed kernel memory, potentially allowing local privilege escalation.

  • CVE-2026-46164HIGH 7.0

    A memory management bug in the Linux kernel's Btrfs filesystem can cause the same memory region to be freed twice when a sysfs initialization step fails. This double-free condition can lead to memory corruption and potentially allow an attacker with local access to crash the system or execute code with elevated privileges. The issue occurs in error handling code that wasn't properly coordinated between two layers of the filesystem's initialization logic.

  • CVE-2026-46299HIGH 7.0

    CVE-2026-46299 is a lock-handling bug in the Linux kernel's HFS+ filesystem driver that can allow a local attacker with moderate privileges to crash the system or potentially escalate privileges. The vulnerability occurs during filesystem mount when the code acquires a lock but fails to release it properly if certain filename validation steps fail. This causes the system to detect a memory leak while a critical lock is still held, triggering a kernel warning and potential system instability.

  • CVE-2026-46309HIGH 7.0

    CVE-2026-46309 is a memory access control flaw in the Linux kernel's GPU driver (xe) that can leak sensitive data. When a privileged process uses a low-coherency GPU memory mode on CPU-cached buffers, the GPU can bypass CPU caches and read stale data directly from RAM—including sensitive information from previously freed memory of other processes. The fix validates GPU memory configuration requests to prevent this dangerous combination.

  • CVE-2026-47293HIGH 7.0

    A use-after-free vulnerability exists in Microsoft Office's Click-To-Run installation and update mechanism. An attacker with valid credentials on a local machine can exploit a memory management flaw to gain elevated (administrator) privileges. This is not a remote vulnerability—it requires an authorized user account and local access—but the privilege escalation risk makes it a meaningful threat in environments where credential compromise or insider activity is a concern.

  • CVE-2026-47648HIGH 7.0

    CVE-2026-47648 is a privilege escalation vulnerability in Windows Storage that affects multiple versions of Windows 10, Windows 11, and Windows Server. An authorized local user can exploit an untrusted search path flaw to gain elevated privileges on a compromised system. The vulnerability requires local access and user interaction is not needed, but exploitation depends on specific system conditions. With a CVSS score of 7.0 (HIGH), this poses a meaningful risk to environments where local account compromise is plausible.

  • CVE-2026-54229HIGH 7.0

    A timing vulnerability exists in the abrt-dbus D-Bus service that allows a local attacker with limited privileges to take control of crash dump files while the system is processing them. The vulnerability stems from a race condition where the ChownProblemDir method changes file ownership even though privileged event handlers are actively writing to the same directory. An attacker exploiting this can redirect, modify, or delete crash dumps before they're fully processed, potentially compromising system integrity and enabling local privilege escalation.

  • CVE-2026-54230HIGH 7.0

    A vulnerability in libreport's ABRT (Automatic Bug Reporting Tool) event handler scripts allows a local attacker with limited privileges to overwrite arbitrary files on a system. The flaw occurs because event scripts use file output redirection without protective measures that would prevent following symbolic links. An attacker can replace a target file with a symlink pointing to a sensitive system file, then trigger an ABRT event. Since the event scripts run as root, they unwittingly follow the symlink and write data to the attacker's chosen location, potentially corrupting critical system files or planting malicious content.

  • CVE-2026-6090HIGH 7.0

    CVE-2026-6090 is a HIGH severity authentication bypass vulnerability in Lenovo Smart Connect for Windows that allows an authenticated local user to gain elevated system privileges and run arbitrary code. An attacker already logged into the system could exploit this to escalate their access and take full control of the machine. The vulnerability requires local access and some specific conditions to trigger, making it a meaningful risk for shared systems or environments where user accounts are provisioned broadly.