| CVE-2026-50396 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50393 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50392 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50390 | 7 | high | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to e | 53d ago |
| CVE-2026-50372 | 7 | high | microsoft / windows 10 1607 | Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally | 53d ago |
| CVE-2026-50371 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allow | 53d ago |
| CVE-2026-50359 | 7 | high | microsoft / windows 10 1607 | Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50358 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50348 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50345 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50322 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50307 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-58526 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-54996 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print D | 53d ago |
| CVE-2026-54989 | 7 | high | microsoft / windows 10 1607 | Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate | 53d ago |
| CVE-2026-54129 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-54111 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print D | 53d ago |
| CVE-2026-50384 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Servic | 53d ago |
| CVE-2026-50356 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows A | 53d ago |
| CVE-2026-50325 | 7 | high | microsoft / windows 10 1607 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50323 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50297 | 7 | high | microsoft / windows 10 1607 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50296 | 7 | high | microsoft / windows 10 1607 | Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49806 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print D | 53d ago |
| CVE-2026-49805 | 7 | high | microsoft / windows 10 1607 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49803 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deploy | 53d ago |
| CVE-2026-49802 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print D | 53d ago |
| CVE-2026-49784 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows A | 53d ago |
| CVE-2026-49183 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard S | 53d ago |
| CVE-2026-49162 | 7 | high | microsoft / windows 11 24h2 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-48572 | 7 | high | microsoft / windows 11 23h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Install | 53d ago |
| CVE-2026-48571 | 7 | high | microsoft / windows 11 23h2 | Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-6851 | 7 | high | bitdefender / internet security | An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used | 53d ago |
| CVE-2026-15515 | 7 | high | — | A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. | 55d ago |
| CVE-2026-56254 | 7 | high | — | In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the priva | 57d ago |
| CVE-2026-59948 | 7 | high | — | Composer is a dependency Manager for the PHP language. | 59d ago |
| CVE-2026-56297 | 7 | high | freerdp / freerdp | FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive d | 59d ago |
| CVE-2026-53329 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_v | 66d ago |
| CVE-2026-58050 | 7 | high | libssh2 / libssh2 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and | 70d ago |
| CVE-2026-49417 | 7 | high | freebsd / freebsd | Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remai | 70d ago |
| CVE-2026-54321 | 7 | high | — | Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. | 74d ago |
| CVE-2026-0083 | 7 | high | google / android | In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. | 80d ago |
| CVE-2026-0125 | 7 | high | google / android | In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. | 81d ago |
| CVE-2024-38487 | 7 | high | — | api-gateway container running with root privilege would allow an attacker to escape the container and access host | 81d ago |
| CVE-2026-54230 | 7 | high | redhat / automatic bug reporting tool | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. | 85d ago |
| CVE-2026-54229 | 7 | high | — | A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. | 85d ago |
| CVE-2026-44495 | 7 | high | axios / axios | Axios is a promise based HTTP client for the browser and Node.js. | 86d ago |
| CVE-2026-42462 | 7 | high | — | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. | 87d ago |
| CVE-2026-6090 | 7 | high | — | A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authent | 87d ago |
| CVE-2026-47648 | 7 | high | microsoft / windows 10 1607 | Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-47293 | 7 | high | microsoft / 365 apps | Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-45653 | 7 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-45640 | 7 | high | microsoft / windows 10 21h2 | Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-45603 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary F | 88d ago |
| CVE-2026-45601 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary F | 88d ago |
| CVE-2026-45598 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary F | 88d ago |
| CVE-2026-45597 | 7 | high | microsoft / windows 11 23h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manag | 88d ago |
| CVE-2026-45596 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 88d ago |
| CVE-2026-44818 | 7 | high | microsoft / 365 apps | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Ex | 88d ago |
| CVE-2026-42984 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 88d ago |