Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52171
Total
4143
Critical
15453
High
15185
Medium
CVE ID Severity Score Description Published
CVE-2026-50456 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-50455 MEDIUM 5.5 Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-50454 HIGH 7.8 Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50453 MEDIUM 6.1 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. Jul 14, 2026
CVE-2026-50452 HIGH 7.0 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. Jul 14, 2026
CVE-2026-50451 HIGH 7.1 Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50450 HIGH 7.8 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50449 HIGH 7.0 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50448 HIGH 7.8 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Jul 14, 2026
CVE-2026-50447 CRITICAL 9.8 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. Jul 14, 2026
CVE-2026-50445 MEDIUM 6.5 Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. Jul 14, 2026
CVE-2026-50444 HIGH 8.8 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. Jul 14, 2026
CVE-2026-50442 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-50441 HIGH 7.8 Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50440 HIGH 7.8 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50439 HIGH 8.1 Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. Jul 14, 2026
CVE-2026-50438 HIGH 8.8 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50437 MEDIUM 5.5 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-50436 HIGH 7.8 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50435 HIGH 7.8 Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50434 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-50433 HIGH 7.8 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. Jul 14, 2026
CVE-2026-50432 MEDIUM 5.3 Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. Jul 14, 2026
CVE-2026-50431 MEDIUM 5.5 Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability Jul 14, 2026
CVE-2026-50430 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. Jul 14, 2026