Vulnerabilities
Tracked app vulnerabilities
2,273 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-50298
MEDIUM 6.8
Physical
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50295
MEDIUM 5.5
Local
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-50294
MEDIUM 6.2
Local
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-49807
MEDIUM 6.2
Local
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-49804
MEDIUM 6.6
Physical
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-49801
MEDIUM 5.5
Local
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-49799
MEDIUM 6.5
Network
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-49794
MEDIUM 4.6
Physical
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-49180
MEDIUM 5.5
Local
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca… |
|
CVE-2026-49174
MEDIUM 6.1
Local
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-49168
MEDIUM 6.8
Physical
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-49167
MEDIUM 4.7
Local
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44806
MEDIUM 5.3
Network
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-41087
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-40422
MEDIUM 5.5
Local
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-34349
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. |
|
CVE-2026-34348
MEDIUM 6.5
Network
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-34346
MEDIUM 5.5
Local
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. |
|
CVE-2026-34328
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-33842
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-13356
MEDIUM 6.3
Network 1 apps
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin… |
|
CVE-2026-57963
MEDIUM 6.5
Network 1 apps
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. Thi… |
|
CVE-2026-57962
MEDIUM 5.3
Network 1 apps
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplie… |
|
CVE-2026-4360
MEDIUM 5.3
Network 1 apps
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrust… |
|
CVE-2026-43746
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. P… |
|
CVE-2026-43745
MEDIUM 6.5
Network
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5… |
|
CVE-2026-43743
MEDIUM 4.7
Local
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. … |
|
CVE-2026-43742
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… |
|
CVE-2026-43740
MEDIUM 6.5
Network
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visio… |
|
CVE-2026-43734
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… |
|
CVE-2026-43732
MEDIUM 6.5
Network
A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6… |
|
CVE-2026-43727
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, v… |
|
CVE-2026-43726
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… |
|
CVE-2026-43722
MEDIUM 5.5
Local
The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS… |
|
CVE-2026-43721
MEDIUM 6.5
Network
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, … |
|
CVE-2026-43720
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… |
|
CVE-2026-43718
MEDIUM 6.5
Network
A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.… |
|
CVE-2026-43717
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… |
|
CVE-2026-43716
MEDIUM 6.5
Network
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing malic… |
|
CVE-2026-43713
MEDIUM 6.5
Network
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26… |
|
CVE-2026-43712
MEDIUM 6.5
Network
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visio… |
|
CVE-2026-43709
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… |
|
CVE-2026-43708
MEDIUM 4.3
Network
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visi… |
|
CVE-2026-43707
MEDIUM 6.5
Network
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, … |
|
CVE-2026-43706
MEDIUM 6.5
Network
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8… |
|
CVE-2026-43704
MEDIUM 5.3
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… |
|
CVE-2026-43703
MEDIUM 6.5
Network
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Ta… |
|
CVE-2026-43700
MEDIUM 6.5
Network
A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe … |
|
CVE-2026-43699
MEDIUM 6.5
Network
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t… |
|
CVE-2026-43676
MEDIUM 6.5
Network
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5… |