|
211
|
7.0 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally.
New
|
CWE-362
Race Condition
|
CVE-2026-45597
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
New
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-45596
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-45595
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
New
|
CWE-200
Information Exposure
|
CVE-2026-45594
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.
New
|
CWE-190 CWE-416
Integer Overflow or Wraparound Use After Free
|
CVE-2026-45593
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.
New
|
CWE-190 CWE-416
Integer Overflow or Wraparound Use After Free
|
CVE-2026-45592
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217
|
7.5 |
HIGH
Network
|
-
|
-
|
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-45591
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218
|
7.9 |
HIGH
Local
|
-
|
-
|
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-45588
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-45586
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
New
|
CWE-94
Code Injection
|
CVE-2026-45583
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|