Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
CVSSv3.1 8.0 (HIGH)
CWECWE 1220TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH
CVE-2026-50489 — Heap: Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
CVSSv3.1 8.1 (HIGH)
CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 18:17Z
CRIT
CVE-2026-50447 — Heap: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH
CVE-2026-50439 — Use: after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
CVSSv3.1 8.8 (HIGH)
CWECWE 59TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH
CVE-2026-50429 — Out: Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH
CVE-2026-50385 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVSSv3.1 8.8 (HIGH)
CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH
CVE-2026-50382 — Untrusted: pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 303TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH
CVE-2026-50340 — Use: after free in Windows Runtime allows an authorized attacker to elevate privileges over
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH
CVE-2026-45077 — Sensiolabs Symfony: Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, integrity checks, or an allowed_classes allowlist, allowing any reachable host to submit attacker-chosen serialized PHP payloads t
CVSSv3.1 8.6 (HIGH)
CVE-2026-45074 — Sensiolabs Symfony: From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost()
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an attacker controlling another application registered with the same CAS server can replay a victim ticket against the Symfony application and authenticate as the vi
CVSSv3.1 8.1 (HIGH)