Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-50305 — Microsoft Brokering File System Elevation of Privilege Vulnerability

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-50304 — Windows Active Directory Federation Services Denial of Service Vulnerability

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-50302 — Windows Cryptographic Services Security Feature Bypass Vulnerability

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-50301 — Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
6.4 MEDIUM
CVE-2026-4018 — TOCTOU race condition in the QNX Neutrino kernel impacts versions of the QNX Software Dev…

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, dat…

Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.4 HIGH
CVE-2026-4017 — Buffer overflow in the QNX Neutrino kernel impacts versions of the QNX Software Developme…

Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.

Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
5.5 MEDIUM
CVE-2026-49177 — Windows TCP/IP Information Disclosure Vulnerability

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

Jul 14, 2026 Aug 12, 2026
Jul 14, 2026
Aug 12, 2026
5.5 MEDIUM
CVE-2026-48580 — Microsoft Excel Information Disclosure Vulnerability

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.8 HIGH
CVE-2026-48368 — Audition | Out-of-bounds Write (CWE-787)

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in …

macos windows audition | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.8 HIGH
CVE-2026-48365 — Audition | Out-of-bounds Write (CWE-787)

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in …

macos windows audition | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.8 HIGH
CVE-2026-48309 — Audition | Out-of-bounds Write (CWE-787)

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in …

macos windows audition | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
5.5 MEDIUM
CVE-2026-47969 — Audition | Out-of-bounds Read (CWE-125)

Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploit…

macos windows audition | Information Disclosure
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.8 HIGH
CVE-2026-47968 — Audition | Out-of-bounds Write (CWE-787)

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in …

macos windows audition | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.8 HIGH
CVE-2026-47967 — Audition | Out-of-bounds Write (CWE-787)

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in …

macos windows audition | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.8 HIGH
CVE-2026-47642 — Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
8.8 HIGH
CVE-2026-47295 — Microsoft SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-47290 — Microsoft Office Remote Code Execution Vulnerability

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
8.2 HIGH
CVE-2026-45756 — Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() W…

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match()…

symfony | Remote | Denial of Service
Jul 14, 2026 Jul 21, 2026
Jul 14, 2026
Jul 21, 2026
8.6 HIGH
CVE-2026-45077 — Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\…

symfony | Remote | Injection
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
8.1 HIGH
CVE-2026-45074 — Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Tick…

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSch…

symfony | Remote | Authentication
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
Showing 20 of 11087 Results