CVE-2026-49788
- EPSS 0.78%
- Veröffentlicht 14.07.2026 17:05:52
- Zuletzt bearbeitet 22.07.2026 16:17:30
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVE-2026-49789
- EPSS 0.28%
- Veröffentlicht 14.07.2026 17:05:52
- Zuletzt bearbeitet 22.07.2026 16:17:31
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-49787
- EPSS 0.82%
- Veröffentlicht 14.07.2026 17:05:51
- Zuletzt bearbeitet 22.07.2026 16:17:30
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
- EPSS 0.15%
- Veröffentlicht 14.07.2026 17:05:50
- Zuletzt bearbeitet 22.07.2026 16:17:29
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
CVE-2026-49783
- EPSS 0.26%
- Veröffentlicht 14.07.2026 17:05:50
- Zuletzt bearbeitet 22.07.2026 16:17:30
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-49184
- EPSS 0.27%
- Veröffentlicht 14.07.2026 17:05:49
- Zuletzt bearbeitet 22.07.2026 16:17:29
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49180
- EPSS 0.33%
- Veröffentlicht 14.07.2026 17:05:48
- Zuletzt bearbeitet 22.07.2026 16:17:29
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-49178
- EPSS 0.62%
- Veröffentlicht 14.07.2026 17:05:47
- Zuletzt bearbeitet 22.07.2026 16:17:29
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
CVE-2026-44800
- EPSS 0.15%
- Veröffentlicht 14.07.2026 17:05:45
- Zuletzt bearbeitet 22.07.2026 16:17:22
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-40378
- EPSS 0.82%
- Veröffentlicht 14.07.2026 17:05:44
- Zuletzt bearbeitet 22.07.2026 16:17:18
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.