Skip to content
cyberexploits

CVEs

Sourced from CVEProject/cvelistV5 and the CISA KEV catalog.

351,354 CVEs
CVSS
CVE
Description
KEV added
PoCs
9.9
CVE-2026-42823
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
2026-05-12
8.8
CVE-2026-41613
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
2026-05-12
9.1
CVE-2026-41103
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
2026-05-12
7.8
CVE-2026-40381
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
2026-05-12
6.7
CVE-2026-41097
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
2026-05-12
8.8
CVE-2026-41086
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
2026-05-12
8.8
CVE-2026-40420
Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
2026-05-12
8.8
CVE-2026-35436
Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
2026-05-12
7.8
CVE-2026-40418
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
2026-05-12
7.4
CVE-2026-40413
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.
2026-05-12
8.8
CVE-2026-40403
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
2026-05-12
9.3
CVE-2026-40402
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
2026-05-12
7.1
CVE-2026-40401
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally.
2026-05-12
7.8
CVE-2026-40398
Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
2026-05-12
4.4
CVE-2026-32209
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
2026-05-12
7.8
CVE-2026-40397
Integer underflow (wrap or wraparound) in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
2026-05-12
7.8
CVE-2026-40382
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
2026-05-12
7.8
CVE-2026-40369
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
2026-05-12
8.8
CVE-2026-40370
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
2026-05-12
8.4
CVE-2026-40367
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-05-12
8.8
CVE-2026-40365
Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
2026-05-12
7.8
CVE-2026-40362
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
2026-05-12
8.4
CVE-2026-40361
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-05-12
7.8
CVE-2026-40359
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
2026-05-12
8.4
CVE-2026-40358
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-05-12
8.8
CVE-2026-40357
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
2026-05-12
7.0
CVE-2026-34341
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
2026-05-12
7.0
CVE-2026-34340
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
2026-05-12
5.5
CVE-2026-34339
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
2026-05-12
7.8
CVE-2026-34338
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
2026-05-12
7.8
CVE-2026-34337
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
2026-05-12
7.8
CVE-2026-34336
Buffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
2026-05-12
7.8
CVE-2026-34334
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
2026-05-12
8.0
CVE-2026-34332
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
2026-05-12
7.8
CVE-2026-33838
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
2026-05-12
7.8
CVE-2026-33837
Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
2026-05-12
7.8
CVE-2026-33835
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
2026-05-12
8.2
CVE-2026-33833
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
2026-05-12
8.8
CVE-2026-33112
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
2026-05-12
8.8
CVE-2026-33110
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
2026-05-12
7.5
CVE-2026-42899
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
2026-05-12
9.9
CVE-2026-42898
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
2026-05-12
7.8
CVE-2026-42896
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
2026-05-12
4.3
CVE-2026-35429
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
2026-05-12
6.5
CVE-2026-42891
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
2026-05-12
7.0
CVE-2026-42825
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
2026-05-12
7.4
CVE-2026-41107
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
2026-05-12
4.3
CVE-2026-32175
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.
2026-05-12
7.8
CVE-2026-42831
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-05-12
5.5
CVE-2026-32185
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
2026-05-12
Page 168 / 7028