|
131
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer underflow (wrap or wraparound) in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-40397
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-40382
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-40381
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
6.2 |
MEDIUM
Physics
|
-
|
-
|
Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.
New
|
CWE-122 CWE-125 CWE-197
Heap-based Buffer Overflow Out-of-bounds Read Numeric Truncation Error
|
CVE-2026-40380
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-200
Information Exposure
|
CVE-2026-40379
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-40377
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
New
|
CWE-200
Information Exposure
|
CVE-2026-40374
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
8.8 |
HIGH
Network
|
-
|
-
|
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-40370
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
7.8 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-40369
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
8.0 |
HIGH
Network
|
-
|
-
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40368
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|