|
631
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45653
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
4.3 |
MEDIUM
Network
|
-
|
-
|
User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-45650
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
7.1 |
HIGH
Local
|
-
|
-
|
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-45649
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
8.8 |
HIGH
Network
|
-
|
-
|
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-45648
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-45647
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-45645
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
8.0 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45644
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
7.8 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-45643
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
3.9 |
LOW
Physics
|
-
|
-
|
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-45642
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
8.4 |
HIGH
Local
|
-
|
-
|
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
New
|
CWE-843
Type Confusion
|
CVE-2026-45641
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|