Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-50560

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an e

PUBLISHED
Vendor
netty
Product
netty
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5056

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of UncompressedFrameConfigBox structures. The issue results from the lack of proper validation of the length of user-supplied data

PUBLISHED
Vendor
GStreamer
Product
GStreamer
Provider severity
HIGH
Conflicts
0

CVE-2026-50559

A flaw was found in Quarkus. A remote attacker could bypass HTTP path-based authorization policies by using specially crafted encoded semicolons, slashes, or backslashes in HTTP requests. This could allow unauthorized access to protected static resources, leading to information disclosure.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, quarkusio, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Apache Camel 4 for Quarkus 3, Cryostat 4 on RHEL 9, streams for Apache Kafka 3, OpenShift Serverless, Red Hat Build of Keycloak, Cryostat 4 on RHEL 9, Red Hat Build of Keycloak, Streams for Apache Kafka 2.9.4, Cryostat 4 on RHEL 9, Red Hat build of Quarkus 3.20.6.SP2, OpenShift Serverless, Red Hat build of Quarkus 3.33.2.SP1, OpenShift Serverless, Red Hat OpenShift Dev Spaces 3.29, Red Hat build of Apache Camel - HawtIO 4, OpenShift Serverless, OpenShift Serverless, Red Hat build of Apicurio Registry 3, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Build of Keycloak, Red Hat Fuse 7, Red Hat build of Quarkus 3.27.4.SP1, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1, Red Hat build of Debezium 3, Red Hat Build of Keycloak, OpenShift Serverless, quarkus, Red Hat Build of Keycloak, OpenShift Serverless, OpenShift Serverless, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
2

CVE-2026-50558

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths, allowing a malicious or compromised session to write files outside the intended download directory and potentially overwrite ~/.penelope/peneloperc. This issue is fixed in version 0.20.0.

PUBLISHED
Vendor
brightio
Product
penelope
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50557

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22 and 19.2.22, an issue in the @angular/compiler and @angular/core packages allows bypassing element and attribute sanitization/validation through specific namespace workarounds. Specifically, namespaced script elements (e.g., <svg:script> or <:svg:script>) were not properly identified as script elements by the Angular template p

PUBLISHED
Vendor
angular
Product
angular
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50556

A flaw was found in @angular/platform-server. This Cross-Site Scripting (XSS) vulnerability exists in its DOM emulation dependency, domino, when handling the content of `<noscript>` elements during server-side rendering. A remote attacker could exploit this by injecting unescaped closing `</noscript>` tags within dynamic text content. This allows for the execution of arbitrary code in the user's browser context, potentially leading to information disclosure or other malicious activities.

PUBLISHED
Vendor
Red Hat, Red Hat, angular
Product
Red Hat Enterprise Linux 8, Red Hat Fuse 7, angular
Provider severity
HIGH
Conflicts
3

CVE-2026-50555

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of raw-text elements (such as <script>, <style>, and <iframe>). domino supports escaping raw-text elements during serialization to prevent closing-tag breakout. However, a

PUBLISHED
Vendor
angular
Product
angular
Provider severity
HIGH
Conflicts
0

CVE-2026-50552

Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the radio station creation endpoint (POST /api/radio/stations). The url field validation rules are declared without the bail keyword, so the HasAudioContentType rule — which issues HTTP requests to the supplied URL — still executes even after the SafeUrl rule has rejected the URL as pointing to a private/reserved address. Any authenticated, non-admin u

PUBLISHED
Vendor
koel
Product
koel
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50551

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0.

PUBLISHED
Vendor
siyuan-note
Product
siyuan
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5055

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the NoMachine Device Server. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate p

PUBLISHED
Vendor
NoMachine
Product
NoMachine
Provider severity
HIGH
Conflicts
0

CVE-2026-50549

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to the original path and writes without approval. A malicious agent can create an in-workspace symlink that points outside the workspace and force canonicalization to fail — either because the target does not exist or because

PUBLISHED
Vendor
cursor
Product
cursor
Provider severity
CRITICAL
Conflicts
0

CVE-2026-50548

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory parameter, which could cause the sandbox to include writable paths outside the intended workspace. A malicious agent could set working_directory to a sensitive location and write arbitrary files outside the workspace under t

PUBLISHED
Vendor
cursor
Product
cursor
Provider severity
CRITICAL
Conflicts
0

CVE-2026-50545

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated dangerous fields into the generated pods. This issue has been patched in version 1.24.0.

PUBLISHED
Vendor
fission
Product
fission
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5054

NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of command line parameters. The issue results from the lack of proper validation of a user-supplied path prior to using it in file op

PUBLISHED
Vendor
NoMachine
Product
NoMachine
Provider severity
HIGH
Conflicts
0

CVE-2026-50530

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether tableId and field IDs in the request body belong to the shared resource, allowing an attacker with a valid share link token to replace dataset identifiers and retrieve unauthorized data through POST /de2api/chartData/getData. This issue is fixed in version 2.10.24.

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
HIGH
Conflicts
0

CVE-2026-5053

NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers to delete arbitrary files on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of environment variables. The issue results from the lack of proper validation of a user-supplied path prior to using it in file oper

PUBLISHED
Vendor
NoMachine
Product
NoMachine
Provider severity
HIGH
Conflicts
0

CVE-2026-50529

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket, allowing unauthenticated attackers who know a protected share UUID to obtain a valid link token for subsequent share-related API calls even with missing or invalid credentials. This issue is fixed in version 2.10.24.

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
HIGH
Conflicts
0

CVE-2026-50528

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Visual Studio 2026 version 18.7, .NET 10.0, Microsoft Visual Studio 2022 version 17.12, Microsoft Visual Studio 2022 version 17.14, .NET 8.0, .NET 9.0
Provider severity
HIGH
Conflicts
2

CVE-2026-50527

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Visual Studio 2022 version 17.14, Microsoft .NET Framework 3.5 AND 4.8.1, .NET 10.0, .NET 9.0, Microsoft Visual Studio 2022 version 17.12, Microsoft .NET Framework 3.5 AND 4.8, Microsoft Visual Studio 2026 version 18.7, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, .NET 8.0, Microsoft .NET Framework 4.8
Provider severity
HIGH
Conflicts
1

CVE-2026-50526

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
.NET 10.0, Microsoft Visual Studio 2022 version 17.12, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.7, .NET 9.0, .NET 8.0
Provider severity
HIGH
Conflicts
2

CVE-2026-50525

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 4.8.1, Microsoft Visual Studio 2022 version 17.14, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft Visual Studio 2026 version 18.7, Microsoft .NET Framework 3.5 AND 4.8, Microsoft .NET Framework 4.8, .NET 10.0, Microsoft Visual Studio 2022 version 17.12, .NET 8.0, Microsoft .NET Framework 3.5, .NET 9.0
Provider severity
HIGH
Conflicts
1

CVE-2026-50524

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
.NET 10.0, Microsoft Visual Studio 2022 version 17.12, .NET 9.0, .NET 8.0, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.7
Provider severity
HIGH
Conflicts
1

CVE-2026-50522

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019
Provider severity
CRITICAL
Conflicts
1

CVE-2026-50521

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
HIGH
Conflicts
0

CVE-2026-50520

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Visual Studio Code
Provider severity
HIGH
Conflicts
0

CVE-2026-5052

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

PUBLISHED
Vendor
HashiCorp, HashiCorp
Product
Vault, Vault Enterprise
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50519

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
GitHub Copilot Chat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-50518

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 1607, Windows Server 2016, Windows Server 2012, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 (Server Core installation)
Provider severity
CRITICAL
Conflicts
1

CVE-2026-50517

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot
Provider severity
CRITICAL
Conflicts
0

CVE-2026-50512

Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft PC Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-50511

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft PC Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-50510

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
GitHub Copilot Plugin for JetBrains IDEs
Provider severity
HIGH
Conflicts
0

CVE-2026-5051

HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.

PUBLISHED
Vendor
HashiCorp, HashiCorp
Product
Vault, Vault Enterprise
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50509

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2016 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-50508

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server 2012 R2, Windows Server 2016, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50507

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows 11 version 23H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2012 R2, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 22H2, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50506

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
AspNetCore.OData, AspNet.OData
Provider severity
HIGH
Conflicts
1

CVE-2026-50505

Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows 10 Version 1809, Windows Server 2016, Windows 11 Version 24H2, Windows 10 Version 1607, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2012 R2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50504

Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows Server 2012
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50503

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-50502

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-50501

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-50500

Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2012 R2, Windows Server 2019, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2025, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-5050

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 7.0.0 due to successful_request() handlers calculating a local signature but not validating Ds_Signature from the request before accepting payment status across the Redsys, Bizum, and Google Pay gateway flows. This makes it possible for unauthenticated attackers to forge payment callback data and mark pending orders as paid whe

PUBLISHED
Vendor
jconti
Product
Payment Gateway for Redsys & WooCommerce Lite
Provider severity
HIGH
Conflicts
0

CVE-2026-50499

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows Server 2022, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-50498

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2012
Provider severity
HIGH
Conflicts
2

CVE-2026-50497

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 10 Version 1607, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2012 R2, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
2

CVE-2026-50496

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows Server 2022, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-50495

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2019, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 1809, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-50494

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2025, Windows 10 Version 1809, Windows Server 2012, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1