CVE-2026-49170
- EPSS 2.8%
- Veröffentlicht 14.07.2026 17:04:29
- Zuletzt bearbeitet 22.07.2026 16:17:27
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
CVE-2026-49168
- EPSS 0.31%
- Veröffentlicht 14.07.2026 17:04:28
- Zuletzt bearbeitet 22.07.2026 16:17:27
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-49167
- EPSS 0.25%
- Veröffentlicht 14.07.2026 17:04:27
- Zuletzt bearbeitet 22.07.2026 16:17:27
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49164
- EPSS 0.65%
- Veröffentlicht 14.07.2026 17:04:26
- Zuletzt bearbeitet 22.07.2026 16:17:26
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
CVE-2026-49165
- EPSS 0.24%
- Veröffentlicht 14.07.2026 17:04:26
- Zuletzt bearbeitet 29.07.2026 20:17:03
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
CVE-2026-42990
- EPSS 0.67%
- Veröffentlicht 14.07.2026 17:04:24
- Zuletzt bearbeitet 22.07.2026 16:17:22
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
CVE-2026-42975
- EPSS 0.34%
- Veröffentlicht 14.07.2026 17:04:21
- Zuletzt bearbeitet 23.07.2026 05:16:30
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-42900
- EPSS 0.39%
- Veröffentlicht 14.07.2026 17:04:20
- Zuletzt bearbeitet 23.07.2026 05:16:30
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-34346
- EPSS 0.2%
- Veröffentlicht 14.07.2026 17:04:19
- Zuletzt bearbeitet 22.07.2026 16:17:17
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
CVE-2026-34349
- EPSS 0.35%
- Veröffentlicht 14.07.2026 17:04:19
- Zuletzt bearbeitet 22.07.2026 16:17:18
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.