| CVE-2026-42912 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 88d ago |
| CVE-2026-42911 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 88d ago |
| CVE-2026-42836 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery | 88d ago |
| CVE-2026-41108 | 7 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-34335 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 88d ago |
| CVE-2026-46309 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU | 89d ago |
| CVE-2026-46299 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_s | 89d ago |
| CVE-2026-46164 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info_su | 100d ago |
| CVE-2026-46154 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under scx_cgroup_ops_ | 100d ago |
| CVE-2026-44604 | 7 | high | — | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. | 100d ago |
| CVE-2026-46029 | 7 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mm/slab: return NULL early from kmalloc_nolock | 101d ago |
| CVE-2026-49000 | 7 | high | — | An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, in | 101d ago |
| CVE-2025-46284 | 7 | high | apple / macos | A race condition was addressed with additional validation. | 102d ago |
| CVE-2026-24200 | 7 | high | — | NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-afte | 102d ago |
| CVE-2025-71215 | 7 | high | trendmicro / apex one | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verifica | 107d ago |
| CVE-2026-29518 | 7 | high | samba / rsync | Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling | 108d ago |
| CVE-2026-45036 | 7 | high | tabby / tabby | Tabby (formerly Terminus) is a highly configurable terminal emulator. | 113d ago |
| CVE-2025-54518 | 7 | high | — | Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attac | 113d ago |
| CVE-2026-42825 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40410 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-35416 | 7 | high | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock all | 116d ago |
| CVE-2026-34347 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-34345 | 7 | high | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock all | 116d ago |
| CVE-2026-34342 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spool | 116d ago |
| CVE-2026-34341 | 7 | high | microsoft / windows 10 1607 | Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges lo | 116d ago |
| CVE-2026-34340 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-34331 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GR | 116d ago |
| CVE-2026-33839 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GR | 116d ago |
| CVE-2026-7818 | 7 | high | pgadmin / pgadmin 4 | Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. | 117d ago |
| CVE-2026-4546 | 7 | high | flos-freeware / notepad2 | A weakness has been identified in Flos Freeware Notepad2 4.2.25. | 167d ago |
| CVE-2026-4545 | 7 | high | flos-freeware / notepad2 | A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. | 167d ago |
| CVE-2026-32611 | 7 | high | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 171d ago |
| CVE-2026-32608 | 7 | high | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 171d ago |