|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":July 21, 2026, 10 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | 7.8 |
重要
Local |
マイクロソフト |
Microsoft Windows 11 24h2 Microsoft Windows Server 2012 Microsoft Windows 11 25h2 Microsoft Windows Server 2019 Microsoft … |
マイクロソフトのMicrosoft Windows 10 1607等の複数製品における解放済みメモリの使用に関する脆弱性 New |
CWE-416
解放済みメモリの使用 |
CVE-2026-50312 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 2 | 7.8 |
重要
Local |
マイクロソフト |
Microsoft Windows 11 24h2 Microsoft Windows Server 2012 Microsoft Windows 11 25h2 Microsoft Windows Server 2019 Microsoft … |
マイクロソフトのMicrosoft Windows 10 1607等の複数製品におけるヒープベースのバッファオーバーフローの脆弱性 New |
CWE-122
ヒープオーバーフロー |
CVE-2026-50313 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 3 | 7.8 |
重要
Local |
マイクロソフト |
Microsoft Office 2021 Long Term Servicing Channel Edition Microsoft Office 2019 Microsoft 365 Apps Microsoft Office 2024 … |
マイクロソフトのMicrosoft 365 Apps等の複数製品における解放済みメモリの使用に関する脆弱性 New |
CWE-416
解放済みメモリの使用 |
CVE-2026-50314 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 4 | 7.8 |
重要
Local |
マイクロソフト |
Microsoft Windows Server 2025 Microsoft Windows 11 24h2 Microsoft Windows 11 26h1 Microsoft Windows 11 25h2 |
マイクロソフトのMicrosoft Windows 11 24h2等の複数製品におけるNULL ポインタデリファレンスに関する脆弱性 New |
CWE-476
NULL ポインタデリファレンス |
CVE-2026-50315 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 5 | 5.5 |
警告
Local |
マイクロソフト |
Microsoft Windows 11 24h2 Microsoft Windows 11 25h2 Microsoft Windows 10 22h2 Microsoft Windows Server 2022 Microsoft Wind… |
マイクロソフトのMicrosoft Windows 10 21h2等の複数製品におけるログファイルからの情報漏えいに関する脆弱性 New |
CWE-532
ログファイルからの情報漏えい |
CVE-2026-50316 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 6 | 7 |
重要
Local |
マイクロソフト |
Microsoft Windows Server 2025 Microsoft Windows 11 24h2 Microsoft Windows 11 26h1 Microsoft Windows 11 25h2 |
マイクロソフトのMicrosoft Windows 11 24h2等の複数製品における複数の脆弱性 New |
CWE-362 CWE-416 |
CVE-2026-50317 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 7 | 7.8 |
重要
Local |
マイクロソフト |
Microsoft Windows 11 24h2 Microsoft Windows 11 25h2 Microsoft Windows Server 2019 Microsoft Windows 10 22h2 Microsoft Wind… |
マイクロソフトのMicrosoft Windows 10 1607等の複数製品におけるスタックベースのバッファオーバーフローの脆弱性 New |
CWE-121
スタックオーバーフロー |
CVE-2026-50318 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 8 | 7 |
重要
Local |
マイクロソフト |
Microsoft Windows 11 24h2 Microsoft Windows Server 2012 Microsoft Windows 11 25h2 Microsoft Windows Server 2019 Microsoft … |
マイクロソフトのMicrosoft Windows 10 1607等の複数製品における複数の脆弱性 New |
CWE-362 CWE-416 |
CVE-2026-50321 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 9 | 7 |
重要
Local |
マイクロソフト |
Microsoft Windows Server 2025 Microsoft Windows 11 24h2 Microsoft Windows 11 26h1 Microsoft Windows 11 25h2 |
マイクロソフトのMicrosoft Windows 11 24h2等の複数製品における複数の脆弱性 New |
CWE-362 CWE-416 |
CVE-2026-50322 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
| 10 | 7 |
重要
Local |
マイクロソフト |
Microsoft Windows Server 2025 Microsoft Windows 11 24h2 Microsoft Windows 11 26h1 Microsoft Windows 11 25h2 |
マイクロソフトのMicrosoft Windows 11 24h2等の複数製品における解放済みメモリの使用に関する脆弱性 New |
CWE-416
解放済みメモリの使用 |
CVE-2026-50323 | 2026-07-21 10:44 | 2026-07-14 | Show | GitHub Exploit DB Packet Storm |
Update Date:July 21, 2026, 4:31 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | 7.8 |
HIGH
Local |
microsoft | windows_subsystem_for_linux | Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. Update |
CWE-126
Buffer Over-read |
CVE-2026-57968 | 2026-07-21 03:39 | 2026-07-15 | Show | GitHub Exploit DB Packet Storm |
| 2 | 4.7 |
MEDIUM
Local |
microsoft | windows_subsystem_for_linux | Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. Update |
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition |
CVE-2026-57973 | 2026-07-21 03:39 | 2026-07-15 | Show | GitHub Exploit DB Packet Storm |
| 3 | 6.5 |
MEDIUM
Network |
microsoft |
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 windows_server_2019<… |
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. Update |
CWE-908
Use of Uninitialized Resource |
CVE-2026-57982 | 2026-07-21 03:39 | 2026-07-15 | Show | GitHub Exploit DB Packet Storm |
| 4 | 7.0 |
HIGH
Local |
microsoft |
windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025 |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. Update |
CWE-362
Race Condition |
CVE-2026-58527 | 2026-07-21 03:38 | 2026-07-15 | Show | GitHub Exploit DB Packet Storm |
| 5 | 4.6 |
MEDIUM
Physics |
microsoft |
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025 |
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. Update |
CWE-125
Out-of-bounds Read |
CVE-2026-58528 | 2026-07-21 03:33 | 2026-07-15 | Show | GitHub Exploit DB Packet Storm |
| 6 | 7.8 |
HIGH
Local |
microsoft |
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 windows_server_2022<… |
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. Update |
CWE-122
Heap-based Buffer Overflow |
CVE-2026-58530 | 2026-07-21 03:28 | 2026-07-15 | Show | GitHub Exploit DB Packet Storm |
| 7 | 7.5 |
HIGH
Network |
microsoft |
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 windows_server_2019<… |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. Update |
CWE-362 CWE-416 Race Condition Use After Free |
CVE-2026-58531 | 2026-07-21 03:26 | 2026-07-15 | Show | GitHub Exploit DB Packet Storm |
| 8 | 9.8 |
CRITICAL
Network |
langflow | langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived… New |
CWE-306
Missing Authentication for Critical Function |
CVE-2026-9103 | 2026-07-21 03:22 | 2026-07-18 | Show | GitHub Exploit DB Packet Storm |
| 9 | 9.9 |
CRITICAL
Network |
langflow | langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard inte… New |
CWE-94
Code Injection |
CVE-2026-9135 | 2026-07-21 03:22 | 2026-07-18 | Show | GitHub Exploit DB Packet Storm |
| 10 | - | - | - | The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An att… New |
CWE-59
Link Following |
CVE-2026-8170 | 2026-07-21 03:16 | 2026-07-21 | Show | GitHub Exploit DB Packet Storm |