|
1071
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-41095
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1072
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-41096
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1073
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
New
|
CWE-1329
Reliance on Component That is Not Updateable
|
CVE-2026-41097
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1074
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-41100
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1075
|
7.1 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-41101
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1076
|
7.1 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-41102
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1077
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-303
Incorrect Implementation of Authentication Algorithm
|
CVE-2026-41103
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1078
|
7.4 |
HIGH
Network
|
-
|
-
|
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-41107
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1079
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature ove…
New
|
CWE-74
Injection
|
CVE-2026-41109
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1080
|
6.3 |
MEDIUM
Local
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
New
|
CWE-59 CWE-79 CWE-200
Link Following Cross-site Scripting Information Exposure
|
CVE-2026-41610
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|