| CVE-2026-48571 | 7 | — | — | — | microsoft / windows 11 23h2 | Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | 86d ago |
| CVE-2026-6851 | 7 | — | — | — | bitdefender / internet security | An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used | 86d ago |
| CVE-2026-15515 | 7 | — | — | — | — | A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. | 88d ago |
| CVE-2026-56254 | 7 | — | — | — | — | In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the priva | 90d ago |
| CVE-2026-59948 | 7 | — | — | — | — | Composer is a dependency Manager for the PHP language. | 92d ago |
| CVE-2026-56297 | 7 | — | — | — | freerdp / freerdp | FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive d | 92d ago |
| CVE-2026-53329 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_v | 99d ago |
| CVE-2026-58050 | 7 | — | — | — | libssh2 / libssh2 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and | 103d ago |
| CVE-2026-49417 | 7 | — | — | — | freebsd / freebsd | Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remai | 103d ago |
| CVE-2026-54321 | 7 | — | — | — | — | Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. | 107d ago |
| CVE-2026-0083 | 7 | — | — | — | google / android | In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. | 113d ago |
| CVE-2026-0125 | 7 | — | — | — | google / android | In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. | 114d ago |
| CVE-2024-38487 | 7 | — | — | — | — | api-gateway container running with root privilege would allow an attacker to escape the container and access host | 114d ago |
| CVE-2026-54230 | 7 | — | — | — | redhat / automatic bug reporting tool | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. | 118d ago |
| CVE-2026-54229 | 7 | — | — | — | — | A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. | 118d ago |
| CVE-2026-44495 | 7 | — | — | — | axios / axios | Axios is a promise based HTTP client for the browser and Node.js. | 119d ago |
| CVE-2026-42462 | 7 | — | — | — | — | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. | 120d ago |
| CVE-2026-6090 | 7 | — | — | — | — | A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authent | 120d ago |
| CVE-2026-47648 | 7 | — | — | — | microsoft / windows 10 1607 | Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. | 121d ago |
| CVE-2026-47293 | 7 | — | — | — | microsoft / 365 apps | Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. | 121d ago |
| CVE-2026-45653 | 7 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 121d ago |
| CVE-2026-45640 | 7 | — | — | — | microsoft / windows 10 21h2 | Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. | 121d ago |
| CVE-2026-45603 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary F | 121d ago |
| CVE-2026-45601 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary F | 121d ago |
| CVE-2026-45598 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary F | 121d ago |
| CVE-2026-45597 | 7 | — | — | — | microsoft / windows 11 23h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manag | 121d ago |
| CVE-2026-45596 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 121d ago |
| CVE-2026-44818 | 7 | — | — | — | microsoft / 365 apps | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Ex | 121d ago |
| CVE-2026-42984 | 7 | — | — | — | microsoft / windows 10 1809 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 121d ago |
| CVE-2026-42912 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 121d ago |
| CVE-2026-42911 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 121d ago |
| CVE-2026-42836 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery | 121d ago |
| CVE-2026-41108 | 7 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. | 121d ago |
| CVE-2026-34335 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 121d ago |
| CVE-2026-46309 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU | 122d ago |
| CVE-2026-46299 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_s | 122d ago |
| CVE-2026-46164 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info_su | 133d ago |
| CVE-2026-46154 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under scx_cgroup_ops_ | 133d ago |
| CVE-2026-44604 | 7 | — | — | — | — | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. | 133d ago |
| CVE-2026-46029 | 7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mm/slab: return NULL early from kmalloc_nolock | 134d ago |
| CVE-2026-49000 | 7 | — | — | — | — | An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, in | 135d ago |
| CVE-2025-46284 | 7 | — | — | — | apple / macos | A race condition was addressed with additional validation. | 135d ago |
| CVE-2026-24200 | 7 | — | — | — | — | NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-afte | 135d ago |
| CVE-2025-71215 | 7 | — | — | — | trendmicro / apex one | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verifica | 140d ago |
| CVE-2026-29518 | 7 | — | — | — | samba / rsync | Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling | 141d ago |
| CVE-2026-45036 | 7 | — | — | — | tabby / tabby | Tabby (formerly Terminus) is a highly configurable terminal emulator. | 146d ago |
| CVE-2025-54518 | 7 | — | — | — | — | Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attac | 147d ago |
| CVE-2026-42825 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 149d ago |
| CVE-2026-40410 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally. | 149d ago |
| CVE-2026-35416 | 7 | — | — | — | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock all | 149d ago |
| CVE-2026-34347 | 7 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 149d ago |
| CVE-2026-34345 | 7 | — | — | — | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock all | 149d ago |
| CVE-2026-34342 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spool | 149d ago |
| CVE-2026-34341 | 7 | — | — | — | microsoft / windows 10 1607 | Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges lo | 149d ago |
| CVE-2026-34340 | 7 | — | — | — | microsoft / windows 10 1809 | Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 149d ago |
| CVE-2026-34331 | 7 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GR | 149d ago |
| CVE-2026-33839 | 7 | — | — | — | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GR | 149d ago |
| CVE-2026-7818 | 7 | — | — | — | pgadmin / pgadmin 4 | Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. | 150d ago |
| CVE-2026-4546 | 7 | — | — | — | flos-freeware / notepad2 | A weakness has been identified in Flos Freeware Notepad2 4.2.25. | 200d ago |
| CVE-2026-4545 | 7 | — | — | — | flos-freeware / notepad2 | A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. | 200d ago |