2026-07-14
2026-07-14 18:17Z
CRIT

CVE-2026-50518 — Heap: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50518

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50502 — Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50502

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 1220TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50489 — Heap: Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50489

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50487 — Use: after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50487

Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50477 — Heap: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50477

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50474 — Use: after free in Remote Desktop Client allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50474

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50460 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50460

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 18:17Z
CRIT

CVE-2026-50447 — Heap: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50447

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50444 — Missing authentication for critical function in Windows Server Update Service allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50444

Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50439 — Use: after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50439

Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50438 — Improper link resolution before file access ('link following') in Microsoft PC Manager allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50438

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 59TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50429 — Out: Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50429

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 200CWECWE 125TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50413 — Use: after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50413

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50398 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows Media allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50398

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50385 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50385

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50382 — Untrusted: pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50382

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. CVSSv3.1 8.8 (HIGH)

CWECWE 822VNDUntrustedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
CRIT

CVE-2026-50380 — Heap: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50380

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50370 — Heap: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50370

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. CVSSv3.1 8.8 (HIGH)

CWECWE 20CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50369 — Use: after free in Windows Remote Desktop Services allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50369

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416CWECWE 362TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50365 — Windows: Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50365

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. CVSSv3.1 8.0 (HIGH)

CWECWE 287TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50360 — Incorrect: implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50360

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 303TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-50340 — Use: after free in Windows Runtime allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50340

Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.5 (HIGH)

CWECWE 416TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-47295 — Improper neutralization of special elements used in an sql command ('sql injection') in SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47295

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-45077 — Sensiolabs Symfony: Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45077

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, integrity checks, or an allowed_classes allowlist, allowing any reachable host to submit attacker-chosen serialized PHP payloads t CVSSv3.1 8.6 (HIGH)

CWECWE 502CWECWE 668VNDSensiolabsVNDSymfonyTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 18:17Z
HIGH

CVE-2026-45074 — Sensiolabs Symfony: From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45074

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an attacker controlling another application registered with the same CAS server can replay a victim ticket against the Symfony application and authenticate as the vi CVSSv3.1 8.1 (HIGH)

CWECWE 290VNDSensiolabsVNDSymfonyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score