Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-34391

Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, and certificate payloads across the entire Windows fleet. Version 4.81.1 patches the issue.

PUBLISHED
Vendor
fleetdm
Product
fleet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34390

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vulnerability where insufficient access control checks in ProjectUsersAddCommand (manage_proj_user_add.php) allow users having manage_project_threshold access level (manager by default) to grant project-level administrator access to any user (including themselves) in any Project they have manager rights in. The normal project-user add form restricts the selectable access levels to

PUBLISHED
Vendor
mantisbt
Product
mantisbt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3439

A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

PUBLISHED
Vendor
SonicWall
Product
SonicOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34389

Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. An attacker who obtained a valid invite token could create an account under an arbitrary email address while inheriting the role granted by the invite, including global admin. Version 4.81.0 patches the issue.

PUBLISHED
Vendor
fleetdm
Product
fleet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34388

Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type value. The server terminates immediately, disrupting all connected hosts, MDM enrollments, and API consumers. Version 4.81.0 patches the issue.

PUBLISHED
Vendor
fleetdm
Product
fleet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34387

Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a crafted software package. Version 4.81.1 patches the issue.

PUBLISHED
Vendor
fleetdm
Product
fleet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34386

Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurations, exfiltrate sensitive data from the Fleet database, and inject arbitrary content into team configs via direct API calls. Version 4.81.0 patches the issue.

PUBLISHED
Vendor
fleetdm
Product
fleet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34385

Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline could allow an attacker with a valid MDM enrollment certificate to exfiltrate or modify the contents of the Fleet database, including user credentials, API tokens, and device enrollment secrets. Version 4.81.0 patches the issue.

PUBLISHED
Vendor
fleetdm
Product
fleet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34384

Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. Unlike the delete_user mode in the same file (which correctly validates the token), these three approval actions read their parameters from $_GET and perform irreversible state changes without any protection. An attacker who has submitted a pending re

PUBLISHED
Vendor
Admidio
Product
admidio
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34383

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been pa

PUBLISHED
Vendor
Admidio
Product
admidio
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34382

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authenticated user to a malicious page can silently destroy that user's list configurations — including organization-wide shared lists when the victim holds administrator rights. This issue has been patched in version 5.0.8.

PUBLISHED
Vendor
Admidio
Product
admidio
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34381

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in the Apache configuration, which causes Apache to silently ignore all .htaccess files. As a result, any file uploaded to the documents module regardless of the role-based permissions configured in the UI, is directly accessible over HTTP without authentication by

PUBLISHED
Vendor
Admidio
Product
admidio
Provider severity
HIGH
Conflicts
0

CVE-2026-34380

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr24.c at line 377. The expression (uint64_t)(w * 3) computes w * 3 as a signed 32-bit integer before casting to uint64_t. When w is large, this multiplication constitutes undefined behavior under the C standard. On tested

PUBLISHED
Vendor
AcademySoftwareFoundation
Product
openexr
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3438

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

PUBLISHED
Vendor
Sonatype
Product
Nexus Repository
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34379

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, AcademySoftwareFoundation, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, openexr, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
2

CVE-2026-34378

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.4.0 to before 3.4.9, a missing bounds check on the dataWindow attribute in EXR file headers allows an attacker to trigger a signed integer overflow in generic_unpack(). By setting dataWindow.min.x to a large negative value, OpenEXRCore computes an enormous image width, which is later used in a signed integer multiplication that overflows, causing

PUBLISHED
Vendor
AcademySoftwareFoundation
Product
openexr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34377

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This would not allow invalid transactions to be accep

PUBLISHED
Vendor
ZcashFoundation, ZcashFoundation
Product
zebra, zebra-consensus
Provider severity
HIGH
Conflicts
1

CVE-2026-34376

PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.0, an access-control vulnerability allows unauthenticated users to retrieve password-protected shared PDFs by directly calling the file-serving endpoint without completing the password verification flow. This results in unauthorized access to confidential documents that users expected to be protected by a shared-link password. This issue has been patched in version

PUBLISHED
Vendor
mrmn2
Product
PdfDing
Provider severity
HIGH
Conflicts
0

CVE-2026-34375

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUEST['plugin']` parameter into a JavaScript block without any encoding or sanitization. The `plugin` parameter is not included in any of the framework's input filter lists defined in `security.php`, so it passes through completely raw. An attacker can inject arbitrary JavaScript by crafting a malicious URL and sending it to a victim user. Th

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
HIGH
Conflicts
0

CVE-2026-34374

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without parameterization. This method is called as a fallback from `LiveTransmition::keyExists()` when the initial parameterized lookup returns no results. Although the calling function correctly uses parameterized queries for its own lookup, the fallback path to `Live_schedule::keyExists()`

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
CRITICAL
Conflicts
0

CVE-2026-34373

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionally allows cross-origin requests from any website. This bypasses origin restrictions that operators configure to control which websites can interact with the Parse Server API. The REST API correctly enforces the configured allowOrigin restriction. This issue has

PUBLISHED
Vendor
parse-community
Product
parse-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34372

Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even have permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5.

PUBLISHED
Vendor
sulu
Product
sulu
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34371

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when persisting code-generated artifacts. On deployments using the default local file strategy, a malicious artifact filename containing traversal sequences (for example, ../../../../../app/client/dist/poc.txt) is concatenated into the server-side destination path and written with fs.writeFileSync() without sanitization. This gives any user who can trigger e

PUBLISHED
Vendor
danny-avila
Product
LibreChat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34370

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated student to read the private course notes of any other user on the platform by manipulating the notebook_id parameter in the editnote action. The application fetches the note content using only the supplied integer ID without verifying that the requesting user owns the note, and the full title

PUBLISHED
Vendor
chamilo
Product
chamilo-lms
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3437

An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.

PUBLISHED
Vendor
Portwell
Product
Portwell Engineering Toolkits
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-34369

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos without verifying the video password. While the normal web playback flow enforces password checks via the `CustomizeUser::getModeYouTube()` hook, this enforcement is completely absent from the API code path. An unauthenticated attacker can retrieve

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34368

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sender's wallet balance, checks sufficiency in PHP, then writes the new balance — all without database transactions or row-level locking. An attacker with multiple authenticated sessions can send concurrent transfer requests that all read the same stale balance, eac

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34367

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Invoice PDF generation module. User-supplied HTML in the invoice Notes field is passed unsanitised to the Dompdf rendering library, which will fetch any remote resources referenced in the markup. This can be triggered via the PDF preview and email delivery endpoints. This issue

PUBLISHED
Vendor
InvoiceShelf
Product
InvoiceShelf
Provider severity
HIGH
Conflicts
0

CVE-2026-34366

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Payment receipt PDF generation module. User-supplied HTML in the payment Notes field is passed unsanitised to the Dompdf rendering library, which will fetch any remote resources referenced in the markup. The vulnerability is exploitable directly via the PDF receipt endpoint, reg

PUBLISHED
Vendor
InvoiceShelf
Product
InvoiceShelf
Provider severity
HIGH
Conflicts
0

CVE-2026-34365

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Estimate PDF generation module. User-supplied HTML in the estimate Notes field is passed unsanitised to the Dompdf rendering library, which will fetch any remote resources referenced in the markup. The vulnerability is exploitable directly via the PDF preview and customer view e

PUBLISHED
Vendor
InvoiceShelf
Product
InvoiceShelf
Provider severity
HIGH
Conflicts
0

CVE-2026-34364

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category listing API, fails to enforce user group-based access controls on categories. In the default request path (no `?user=` parameter), user group filtering is entirely skipped, exposing all non-private categories including those restricted to specific user groups. When the `?user=` parameter is supplied, a type confusion bug causes the filter to use the ad

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34363

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process each subscriber concurrently using shared mutable objects. The sensitive data filter modifies these shared objects in-place, so when one subscriber's filter removes a protected field, subsequent subscribers may receive the already-filtered object. This can cau

PUBLISHED
Vendor
parse-community
Product
parse-server
Provider severity
HIGH
Conflicts
0

CVE-2026-34362

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This allows captured or legitimately obtained tokens to provide permanent WebSocket access, even after user accounts are deleted, banned, or demoted from admin. Admin tokens grant access to real-time connecti

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34361

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a startsWith() URL prefix matching flaw in the credential provider (ManagedWebAccessUtils.getServer()), an attacker can steal authentication tokens (Bearer, Basic, API keys) configured for legitimate FHIR servers by

PUBLISHED
Vendor
hapifhir
Product
org.hl7.fhir.core
Provider severity
CRITICAL
Conflicts
0

CVE-2026-34360

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and makes server-side HTTP requests to it without any hostname, scheme, or domain validation. An unauthenticated attacker with network access to the validator can probe internal network services, cloud metadata endpoints, and map network topology through error-based i

PUBLISHED
Vendor
hapifhir
Product
org.hl7.fhir.core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34359

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch. Because configured server URLs (e.g., http://tx.fhir.org) lack a trailing slash or host boundary check, an attacker-controlled domain like http://tx.fhir.org.attacker.com matches the prefix and receives Bearer tokens, B

PUBLISHED
Vendor
hapifhir
Product
org.hl7.fhir.core
Provider severity
HIGH
Conflicts
0

CVE-2026-34358

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin controllers enforce permission checks on form display methods but omit equivalent checks on the corresponding write methods, allowing any authenticated user to bypass RBAC via direct POST/PATCH requests. Controllers missing checks on write methods store() and update() include ApplicationApiController (admin.api.write), CouponController (adm

PUBLISHED
Vendor
Ctrlpanel-gg
Product
panel
Provider severity
HIGH
Conflicts
1

CVE-2026-34356

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Provider severity
HIGH
Conflicts
0

CVE-2026-34355

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apache Software Foundation
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Apache HTTP Server
Provider severity
HIGH
Conflicts
2

CVE-2026-34354

Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs() function of the GPA service, by creating a log file and manipulating it into a symlink that points to the targeted path; this can allow an unprivileged local user to make arbitrary root-ow

PUBLISHED
Vendor
Akamai, Akamai
Product
Zero Trust Client, Guardicore Platform Agent
Provider severity
HIGH
Conflicts
1

CVE-2026-34353

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

PUBLISHED
Vendor
OCaml
Product
OCaml
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34352

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

PUBLISHED
Vendor
TigerVNC
Product
TigerVNC
Provider severity
HIGH
Conflicts
0

CVE-2026-34351

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows Server 2016, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2019, Windows Server 2022, Windows Server 2012, Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows 11 version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-34350

Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34349

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 10 Version 1809, Windows 11 Version 25H2, Windows 10 Version 21H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34348

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2022, Windows 11 Version 24H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34347

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2012 R2, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 23H2, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2012, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-34346

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2012, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 11 version 23H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 23H2, Windows Server 2022, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34345

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 23H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2019, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-34344

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012, Windows Server 2019, Windows 11 version 23H2, Windows Server 2012 R2, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2022, Windows 11 Version 23H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1