CVE-2026-24292
- EPSS 0.05%
- Veröffentlicht 10.03.2026 17:04:43
- Zuletzt bearbeitet 13.03.2026 19:02:15
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-24290
- EPSS 0.05%
- Veröffentlicht 10.03.2026 17:04:42
- Zuletzt bearbeitet 13.03.2026 19:14:28
Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-24287
- EPSS 0.07%
- Veröffentlicht 10.03.2026 17:04:41
- Zuletzt bearbeitet 13.03.2026 19:23:33
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-30785
- EPSS 0.01%
- Veröffentlicht 05.03.2026 16:16:19
- Zuletzt bearbeitet 05.03.2026 19:38:33
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Pas...
CVE-2026-2636
- EPSS 0.04%
- Veröffentlicht 25.02.2026 18:57:02
- Zuletzt bearbeitet 27.02.2026 14:06:59
This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an u...
CVE-2025-59033
- EPSS 0.04%
- Veröffentlicht 08.09.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 16:15:48
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the s...
CVE-2022-50238
- EPSS 0.04%
- Veröffentlicht 08.09.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 16:15:43
The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expect...
CVE-2025-9491
- EPSS 0.35%
- Veröffentlicht 26.08.2025 16:25:15
- Zuletzt bearbeitet 05.11.2025 21:15:36
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vul...
CVE-2025-34091
- EPSS 0%
- Veröffentlicht 02.07.2025 19:25:27
- Zuletzt bearbeitet 24.07.2025 07:15:53
Rejected reason: Neither filed by Chrome nor a valid security vulnerability.
CVE-2025-21197
- EPSS 1.78%
- Veröffentlicht 08.04.2025 17:23:36
- Zuletzt bearbeitet 10.07.2025 15:52:05
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.