Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-3223

Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.

PUBLISHED
Vendor
Google
Product
Web Designer
Provider severity
HIGH
Conflicts
0

CVE-2026-32229

In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled

PUBLISHED
Vendor
JetBrains
Product
Hub
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32228

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
HIGH
Conflicts
0

CVE-2026-32226

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft .NET Framework 4.8.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 3.5 AND 4.8, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.8, Microsoft .NET Framework 4.7.2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32225

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2019, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2016, Windows 10 Version 21H2, Windows 11 version 26H1, Windows 11 version 22H3, Windows Server 2012, Windows 10 Version 1809, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-32224

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
HIGH
Conflicts
0

CVE-2026-32223

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 25H2, Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32222

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-32221

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-32220

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3222

The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input wrapped in backticks as column names, bypassing the `esc_sql()` escaping function. Additionally, the `wpgmp_ajax_call` AJAX handler (registered for unauthenticated users via `wp_ajax_nopriv`) allows calling arbitrary class meth

PUBLISHED
Vendor
flippercode
Product
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
Provider severity
HIGH
Conflicts
0

CVE-2026-32219

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
2

CVE-2026-32218

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32217

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 version 22H3, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows 11 Version 23H2, Windows 11 version 26H1, Windows Server 2022, Windows Server 2019, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32216

Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32215

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 11 version 22H3, Windows 10 Version 1809, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows Server 2019, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32214

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows Server 2016, Windows 11 version 26H1, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 11 Version 25H2, Windows 11 version 22H3, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, Windows Server 2012 R2 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32213

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure AI Foundry
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32212

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1809, Windows 11 version 22H3, Windows 10 Version 1607, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows Server 2012, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32211

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Web Apps
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32210

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Dynamics 365 (online)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3221

Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32209

Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2016, Windows 11 version 26H1, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 11 Version 23H2, Windows Server 2022, Windows Server 2012, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 23H2, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32208

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
HIGH
Conflicts
0

CVE-2026-32207

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Machine Learning
Provider severity
HIGH
Conflicts
0

CVE-2026-32204

External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Monitor
Provider severity
HIGH
Conflicts
0

CVE-2026-32203

A flaw was found in .NET. A remote attacker could exploit a stack overflow vulnerability during encrypted key nested decryption, leading to a Denial of Service (DoS). This could make the affected system unavailable to legitimate users.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Microsoft, Microsoft, Microsoft, Red Hat, Red Hat, Red Hat, Microsoft, Red Hat, Microsoft, Red Hat, Red Hat, Red Hat, Microsoft, Red Hat
Product
Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Microsoft Visual Studio 2026 version 18.4, .NET 10.0, Microsoft Visual Studio 2022 version 17.14, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 10, Microsoft Visual Studio 2022 version 17.12, Red Hat Enterprise Linux 8, .NET 8.0, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, .NET 9.0, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
3

CVE-2026-32202

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows 10 Version 1607, Windows 11 Version 23H2, Windows Server 2025, Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2022
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32201

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32200

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft PowerPoint 2016, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2026-3220

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

PUBLISHED
Vendor
Unknown, Unknown, Unknown
Product
Speed Optimizer, Autoptimize, Clearfy Cache
Provider severity
HIGH
Conflicts
2

CVE-2026-32199

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Office Online Server, Microsoft Office LTSC for Mac 2024, Microsoft Excel 2016, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-32198

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office LTSC 2024, Office Online Server, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-32197

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Excel 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Office Online Server, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-32196

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32195

Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
HIGH
Conflicts
0

CVE-2026-32194

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Bing Images
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32193

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Kubernetes Service
Provider severity
HIGH
Conflicts
0

CVE-2026-32192

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Monitor
Provider severity
HIGH
Conflicts
0

CVE-2026-32191

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Bing Images
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32190

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-3219

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.

PUBLISHED
Vendor
Python Packaging Authority
Product
pip
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32189

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Excel 2016, Office Online Server, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-32188

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Office Online Server, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Microsoft Excel 2016, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2026-32186

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Bing
Provider severity
CRITICAL
Conflicts
1

CVE-2026-32185

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Teams for Android
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32184

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft HPC Pack 2019
Provider severity
HIGH
Conflicts
0

CVE-2026-32183

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows 11 Version 23H2, Windows 11 version 22H3, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-32181

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3218

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2.

PUBLISHED
Vendor
Drupal
Product
Responsive Favicons
Provider severity
MEDIUM
Conflicts
0