|
91
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 windows_server_2022<…
|
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Update
|
CWE-197
Numeric Truncation Error
|
CVE-2026-50357
|
2026-07-21 02:21 |
2026-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2025
|
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Update
|
CWE-416
Use After Free
|
CVE-2026-50353
|
2026-07-21 02:20 |
2026-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 windows_server_2019<…
|
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Update
|
CWE-416
Use After Free
|
CVE-2026-54995
|
2026-07-21 02:18 |
2026-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net/sched: dualpi2: fix GSO backlog accounting
When DualPI2 splits a GSO skb into N segments, it propagates N
additional packets …
New
|
-
|
CVE-2026-64207
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
l2cap_conn_del() takes conn->lock and then calls cancel_work_sy…
New
|
-
|
CVE-2026-64206
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
i2c: i801: fix hardware state machine corruption in error path
A severe livelock and subsequent Hung Task panic were observed in …
New
|
-
|
CVE-2026-64205
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
When CONFIG_BPF_LSM=y is set, BPF inode storage maps
…
New
|
-
|
CVE-2026-64192
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
i2c: stub: Reject I2C block transfers with invalid length
The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0]
as…
New
|
-
|
CVE-2026-64191
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net: team: fix NULL pointer dereference in team_xmit during mode change
__team_change_mode() clears team->ops with memset() befor…
New
|
-
|
CVE-2026-64190
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: fix race between dump and ip_set_list resize
The release path of ip_set_dump_do() and ip_set_dump_done() read
i…
New
|
-
|
CVE-2026-64189
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|