|
1041
|
8.4 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-40367
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1042
|
8.8 |
HIGH
Network
|
-
|
-
|
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-40370
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1043
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
New
|
CWE-200
Information Exposure
|
CVE-2026-40374
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1044
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-200
Information Exposure
|
CVE-2026-40379
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1045
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-40381
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1046
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-40382
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1047
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer underflow (wrap or wraparound) in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-40397
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1048
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-40398
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1049
|
7.8 |
HIGH
Local
|
-
|
-
|
Stack-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-40399
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1050
|
7.1 |
HIGH
Local
|
-
|
-
|
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-40401
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|