|
71
|
6.5 |
MEDIUM
Network
|
-
|
-
|
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-42891
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
72
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a netw…
New
|
CWE-74
Injection
|
CVE-2026-42838
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
73
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
New
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-42833
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
74
|
7.7 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-42832
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
75
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-42831
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
76
|
6.5 |
MEDIUM
Local
|
-
|
-
|
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
New
|
CWE-426
Untrusted Search Path
|
CVE-2026-42830
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
77
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-42825
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
78
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
New
|
CWE-284
Improper Access Control
|
CVE-2026-42823
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
79
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn't the default) can craft a policy that makes…
New
|
CWE-862
Missing Authorization
|
CVE-2026-42541
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
80
|
- |
|
-
|
-
|
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1…
New
|
CWE-200
Information Exposure
|
CVE-2026-42498
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|