CVE-2026-15418
- EPSS 0.15%
- Veröffentlicht 10.09.2026 17:15:04
- Zuletzt bearbeitet 10.09.2026 19:54:25
In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earl...
CVE-2026-50387
- EPSS 1.92%
- Veröffentlicht 14.07.2026 17:07:08
- Zuletzt bearbeitet 22.07.2026 16:17:49
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-45639
- EPSS 0.87%
- Veröffentlicht 09.06.2026 17:17:30
- Zuletzt bearbeitet 23.07.2026 08:10:00
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-44801
- EPSS 0.46%
- Veröffentlicht 09.06.2026 17:17:15
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-44799
- EPSS 0.46%
- Veröffentlicht 09.06.2026 17:17:15
- Zuletzt bearbeitet 23.07.2026 08:10:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42985
- EPSS 1.26%
- Veröffentlicht 09.06.2026 17:17:14
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42909
- EPSS 0.4%
- Veröffentlicht 09.06.2026 17:17:10
- Zuletzt bearbeitet 23.07.2026 08:10:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-34883
- EPSS 0.14%
- Veröffentlicht 19.05.2026 00:00:00
- Zuletzt bearbeitet 24.07.2026 12:10:00
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate privileges to Administrator. During installation, the s...
CVE-2026-32157
- EPSS 0.78%
- Veröffentlicht 14.04.2026 16:57:26
- Zuletzt bearbeitet 25.09.2026 18:17:19
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-24292
- EPSS 0.34%
- Veröffentlicht 10.03.2026 17:04:43
- Zuletzt bearbeitet 13.03.2026 19:02:15
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.