2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-49959 — Hermes: WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49959

Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by placing malicious executable Git configuration in a workspace repository's .git/config file. Attackers can exploit Git subprocess invocations in api/workspace_git.py through vectors such as core.fsmonitor during git status, protocol.ext.allow with ext:: remotes during git fetch, credential.helper, core.askPass, core.gitProxy, CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDHermesTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-49841 — FreeSWITCH: Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49841

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-www-form-urlencoded body but accepts Content-Length up to just under 10 MiB. The body-read loop is bounded by Content-Length rather than the buffer size, producing an attacker-contr CVSSv3.1 9.8 (CRITICAL)

CWECWE 122CWECWE 131VNDFreeswitchTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-49840 — FreeSWITCH: Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49840

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(len + 1) with no sign or magnitude check. A malicious or man-in-the-middle ESL peer can send a frame with a negative Content-Length to corrupt the heap of, or crash, any process li CVSSv3.1 9.1 (CRITICAL)

CWECWE 20CWECWE 787CWECWE 122CWECWE 195VNDFreeswitchTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-49160 — Microsoft Windows_10_1607: Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49160

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. CVSSv3.1 7.5 (HIGH) · EPSS 99th percentile

CWECWE 400VNDMicrosoftVNDUncontrolledTYPVulnerability
7.5
CVSS v3.1
100
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-47653 — Heap: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47653

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-47652 — Out: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47652

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. CVSSv3.1 8.2 (HIGH)

CWECWE 122TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-47643 — External: control of file name or path in Azure Stack Edge allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47643

External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 73TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-47635 — Access: of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47635

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 122VNDAccessTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-47631 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47631

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 79TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-47298 — Microsoft: Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47298

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 285VNDMicrosoftTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-47291 — Integer: overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47291

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122CWECWE 190TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-47289 — Heap: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47289

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-47281 — Visual: Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47281

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 862CWECWE 306CWECWE 798VNDVisualTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-45657 — Use: after free in Windows Kernel allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45657

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416CWECWE 122TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45648 — Stack: Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45648

Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45644 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45644

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 79TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45641 — Out: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45641

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 843TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45635 — Use: after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45635

Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 843TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45607 — Out: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45607

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 125TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-45602 — No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45602

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45599 — Use: after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45599

Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45504 — Server: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45504

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 918TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45503 — Server: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45503

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 285TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
MED

CVE-2026-45502 — Microsoft Exchange_server: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45502

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. CVSSv3.1 5.0 (MEDIUM) · EPSS 97th percentile

CWECWE 918VNDMicrosoftTYPVulnerability
5.0
CVSS v3.1
81
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45484 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45484

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score