Fri, Jan 23 · 02:15 AM CSTCVE-2026-24304
9.9/10 · Must read/watchNVDvuln
Summary
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
CVECVE-2026-24304
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jan 23 · 02:15 AM CST
ModifiedThu, Jul 30 · 09:17 PM CDT
Wed, Jan 18 · 06:15 PM CSTCVE-2022-47966
9.8/10 · Must read/watchNVDvuln
Summary
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and
CVECVE-2022-47966
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 18 · 06:15 PM CST
ModifiedFri, Jul 31 · 04:16 AM CDT
Tue, Jun 13 · 09:15 AM CDTCVE-2023-27997
9.8/10 · Must read/watchNVDvuln
Summary
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may
CVECVE-2023-27997
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 13 · 09:15 AM CDT
ModifiedFri, Jul 31 · 04:16 AM CDT
Fri, Nov 10 · 06:15 AM CSTCVE-2023-47246
9.8/10 · Must read/watchNVDvuln
Summary
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
CVECVE-2023-47246
SeverityCRITICAL
TypeUPDATED
PublishedFri, Nov 10 · 06:15 AM CST
ModifiedFri, Jul 31 · 04:16 AM CDT
Mon, Oct 28 · 12:15 AM CDTCVE-2024-50623
9.8/10 · Must read/watchNVDvuln
Summary
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVECVE-2024-50623
SeverityCRITICAL
TypeUPDATED
PublishedMon, Oct 28 · 12:15 AM CDT
ModifiedFri, Jul 31 · 04:16 AM CDT
Tue, Oct 10 · 02:15 PM CDTCVE-2023-4966
9.4/10 · Must read/watchNVDvuln
Summary
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVECVE-2023-4966
SeverityCRITICAL
TypeUPDATED
PublishedTue, Oct 10 · 02:15 PM CDT
ModifiedFri, Jul 31 · 04:16 AM CDT
Tue, Jun 03 · 01:15 PM CDTCVE-2025-4517
9.4/10 · Must read/watchNVDvuln
Summary
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See
CVECVE-2025-4517
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 03 · 01:15 PM CDT
ModifiedThu, Jul 30 · 11:16 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20868
8.8/10 · Worth your timeNVDvuln
Summary
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVECVE-2026-20868
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:17 PM CDT
Thu, Feb 05 · 04:15 AM CSTCVE-2025-61732
8.6/10 · Worth your timeNVDvuln
Summary
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVECVE-2025-61732
SeverityHIGH
TypeUPDATED
PublishedThu, Feb 05 · 04:15 AM CST
ModifiedThu, Jul 30 · 12:17 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20856
8.1/10 · Worth your timeNVDvuln
Summary
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
CVECVE-2026-20856
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:17 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20931
8.0/10 · Worth your timeNVDvuln
Summary
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
CVECVE-2026-20931
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:17 PM CDT
Wed, May 12 · 11:15 PM CDTCVE-2021-23134
7.8/10 · Worth your timeNVDvuln
Summary
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
CVECVE-2021-23134
SeverityHIGH
TypeUPDATED
PublishedWed, May 12 · 11:15 PM CDT
ModifiedThu, Jul 30 · 07:36 PM CDT
Sun, Mar 07 · 05:15 AM CSTCVE-2021-27365
7.8/10 · Worth your timeNVDvuln
Summary
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink messag
CVECVE-2021-27365
SeverityHIGH
TypeUPDATED
PublishedSun, Mar 07 · 05:15 AM CST
ModifiedThu, Jul 30 · 07:20 PM CDT
Wed, Mar 22 · 02:15 PM CDTCVE-2023-1281
7.8/10 · Worth your timeNVDvuln
Summary
Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()' is called with the destroyed tcf_ext. A local attacker user can use this vulnerab
CVECVE-2023-1281
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 22 · 02:15 PM CDT
ModifiedThu, Jul 30 · 05:16 PM CDT
Fri, Jul 21 · 09:15 PM CDTCVE-2023-3609
7.8/10 · Worth your timeNVDvuln
Summary
A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can contro
CVECVE-2023-3609
SeverityHIGH
TypeUPDATED
PublishedFri, Jul 21 · 09:15 PM CDT
ModifiedThu, Jul 30 · 05:16 PM CDT
Wed, Sep 06 · 02:15 PM CDTCVE-2023-4244
7.8/10 · Worth your timeNVDvuln
Summary
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-
CVECVE-2023-4244
SeverityHIGH
TypeUPDATED
PublishedWed, Sep 06 · 02:15 PM CDT
ModifiedThu, Jul 30 · 07:14 PM CDT
Tue, Feb 13 · 06:15 PM CSTCVE-2024-21338
7.8/10 · Worth your timeNVDvuln
Summary
Windows Kernel Elevation of Privilege Vulnerability
CVECVE-2024-21338
SeverityHIGH
TypeUPDATED
PublishedTue, Feb 13 · 06:15 PM CST
ModifiedFri, Jul 31 · 04:16 AM CDT
Tue, Jul 22 · 08:15 AM CDTCVE-2025-38352
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right af
CVECVE-2025-38352
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 22 · 08:15 AM CDT
ModifiedThu, Jul 30 · 01:13 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20809
7.8/10 · Worth your timeNVDvuln
Summary
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
CVECVE-2026-20809
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:16 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20811
7.8/10 · Worth your timeNVDvuln
Summary
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVECVE-2026-20811
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:16 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20816
7.8/10 · Worth your timeNVDvuln
Summary
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
CVECVE-2026-20816
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:16 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20817
7.8/10 · Worth your timeNVDvuln
Summary
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVECVE-2026-20817
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:16 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20820
7.8/10 · Worth your timeNVDvuln
Summary
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVECVE-2026-20820
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:16 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20822
7.8/10 · Worth your timeNVDvuln
Summary
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVECVE-2026-20822
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:16 PM CDT
Tue, Jan 13 · 06:16 PM CSTCVE-2026-20826
7.8/10 · Worth your timeNVDvuln
Summary
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.
CVECVE-2026-20826
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 06:16 PM CST
ModifiedThu, Jul 30 · 09:16 PM CDT