2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45482 — Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45482

Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. CVSSv3.1 8.4 (HIGH)

CWECWE 22TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45476 — Use: after free in Linux MANA Driver allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45476

Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.2 (HIGH)

CWECWE 416TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45474 — Heap: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45474

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 416VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45472 — Heap: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45472

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 416VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45463 — Heap: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45463

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 121CWECWE 191VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45461 — Heap: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45461

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 416VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45458 — Access: of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45458

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 416VNDAccessTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-45456 — Access: of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45456

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 843VNDAccessTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-45447 — Issue: summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45447

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BI CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-44822 — Out: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44822

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 125TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-44815 — Stack: Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44815

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDStackTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-44810 — Windows: Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44810

Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. CVSSv3.1 8.4 (HIGH)

CWECWE 287TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-42987 — Use: after free in Windows Deployment Services allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42987

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-42985 — Heap: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42985

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-42981 — Integer: underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42981

Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 191TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-42974 — Integer: underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42974

Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 190TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-42904 — Heap: Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42904

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-42835 — Improper neutralization of special elements in output used by a downstream component ('injection') in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42835

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 74TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-41098 — Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41098

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.4 (HIGH)

CWECWE 79TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-40371 — Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40371

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 280TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-38615 — DedeCMS: V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38615

DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDDedecmsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-34182 — Issue: Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34182

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message. In one use case, an attacker may send a CMS message containing AuthEnvelop CVSSv3.1 9.1 (CRITICAL)

CWECWE 354TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-32193 — Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32193

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
CRIT

CVE-2026-26142 — Deserialization: of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26142

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-0419 — Netgear Jr6150_firmware: Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0419

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified t CVSSv3.1 8.0 (HIGH) · EPSS 21th percentile

CWECWE 20VNDNetgearTYPVulnerability
8.0
CVSS v3.1
90
Edit Score