| CVE-2026-62780 | 7 | — | — | — | microsoft / windows 11 23h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62774 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62773 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62766 | 7 | — | — | — | microsoft / windows 11 24h2 | Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62753 | 7 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62749 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62748 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 58d ago |
| CVE-2026-62734 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 58d ago |
| CVE-2026-62729 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 58d ago |
| CVE-2026-62728 | 7 | — | — | — | microsoft / windows 10 1607 | Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized at | 58d ago |
| CVE-2026-62726 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62725 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62724 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62723 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-62705 | 7 | — | — | — | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter | 58d ago |
| CVE-2026-62693 | 7 | — | — | — | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Servic | 58d ago |
| CVE-2026-62690 | 7 | — | — | — | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifi | 58d ago |
| CVE-2026-61939 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Winlogon allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-61938 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-61929 | 7 | — | — | — | microsoft / windows 11 23h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-61927 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-61366 | 7 | — | — | — | microsoft / windows 10 1607 | Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-61361 | 7 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. | 58d ago |
| CVE-2026-61348 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 58d ago |
| CVE-2026-61346 | 7 | — | — | — | microsoft / windows 10 1809 | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-59126 | 7 | — | — | — | microsoft / windows 10 21h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Loggi | 58d ago |
| CVE-2026-59125 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges loca | 58d ago |
| CVE-2026-59122 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 58d ago |
| CVE-2026-50472 | 7 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. | 58d ago |
| CVE-2026-20716 | 7 | — | — | — | intel / xeon 634 firmware | Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of p | 58d ago |
| CVE-2026-58230 | 7 | — | — | — | — | SAP Approuter does not sufficiently validate certain token content under specific configurations. | 59d ago |
| CVE-2026-70640 | 7 | — | — | — | — | llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JN | 63d ago |
| CVE-2026-64587 | 7 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts b | 64d ago |
| CVE-2026-18718 | 7 | — | — | — | — | Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker | 66d ago |
| CVE-2026-18605 | 7 | — | — | — | — | A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. | 66d ago |
| CVE-2026-69097 | 7 | — | — | — | — | GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject a | 66d ago |
| CVE-2026-10848 | 7 | — | — | — | zephyrproject / zephyr | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ | 67d ago |
| CVE-2026-67326 | 7 | — | — | — | — | GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing | 68d ago |
| CVE-2026-17993 | 7 | — | — | — | google / chrome | Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege e | 71d ago |
| CVE-2026-40272 | 7 | — | — | — | — | Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corru | 71d ago |
| CVE-2026-16184 | 7 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a | 72d ago |
| CVE-2026-43755 | 7 | — | — | — | apple / macos | A race condition was addressed with improved state management. | 73d ago |
| CVE-2026-43693 | 7 | — | — | — | apple / macos | A race condition was addressed with improved state handling. | 73d ago |
| CVE-2026-28926 | 7 | — | — | — | apple / macos | A race condition was addressed with improved state handling. | 73d ago |
| CVE-2026-64510 | 7 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix acpi_nfit_init() error c | 75d ago |
| CVE-2026-64460 | 7 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Skip VF Resizable BAR restore on read | 75d ago |
| CVE-2026-64420 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mfd: cros_ec: Delay dev_set_drvdata() until pr | 75d ago |
| CVE-2026-64413 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sas | 75d ago |
| CVE-2026-64315 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: caam - use print_hex_dump_devel to gua | 75d ago |
| CVE-2026-64283 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Treat memslot binding offset | 75d ago |
| CVE-2026-64222 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack | 76d ago |
| CVE-2026-64219 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and l | 76d ago |
| CVE-2026-16584 | 7 | — | — | — | — | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an act | 77d ago |
| CVE-2026-61120 | 7 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). | 79d ago |
| CVE-2026-61061 | 7 | — | — | — | oracle / jdeveloper | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). | 79d ago |
| CVE-2026-60833 | 7 | — | — | — | oracle / solaris | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). | 79d ago |
| CVE-2026-60705 | 7 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 79d ago |
| CVE-2026-60494 | 7 | — | — | — | oracle / jd edwards enterpriseone general ledger | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundatio | 79d ago |
| CVE-2026-46999 | 7 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Disc | 79d ago |
| CVE-2026-58598 | 7 | — | — | — | microsoft / windows 10 21h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engi | 84d ago |