Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-55001 — Active Directory Domain Services Elevation of Privilege Vulnerability

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
6.4 MEDIUM
CVE-2026-55000 — Windows USB Print Driver Elevation of Privilege Vulnerability

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-54999 — Windows TCP/IP Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.

Jul 14, 2026 Jul 24, 2026
Jul 14, 2026
Jul 24, 2026
5.5 MEDIUM
CVE-2026-54997 — Windows SMB Information Disclosure Vulnerability

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
7.0 HIGH
CVE-2026-54996 — Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
9.8 CRITICAL
CVE-2026-54995 — Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
7.8 HIGH
CVE-2026-54993 — Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
8.4 HIGH
CVE-2026-54992 — Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
7.8 HIGH
CVE-2026-54991 — Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
9.8 CRITICAL
CVE-2026-54990 — Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-54989 — Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability

Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 23, 2026
Jul 14, 2026
Jul 23, 2026
6.1 MEDIUM
CVE-2026-54988 — Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
7.8 HIGH
CVE-2026-54987 — Windows Overlay Filter Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 23, 2026
Jul 14, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-54986 — Windows Win32k Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
7.5 HIGH
CVE-2026-54983 — Windows Active Directory Federation Services Denial of Service Vulnerability

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
8.8 HIGH
CVE-2026-54982 — Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
10.0 CRITICAL
CVE-2026-54433 — Roundcube Webmail Stored Cross-Site Scripting Vulnerability

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the vi…

webmail | Remote | Cross-Site Scripting
Jul 14, 2026 Jul 17, 2026
Jul 14, 2026
Jul 17, 2026
4.7 MEDIUM
CVE-2026-54432 — Roundcube Webmail Stored Cross-Site Scripting Vulnerability

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation…

webmail | Remote | Cross-Site Scripting
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
6.8 MEDIUM
CVE-2026-54132 — Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-54129 — Windows Hyper-V Elevation of Privilege Vulnerability

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
Showing 20 of 11267 Results