|
1041
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_26h1
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
|
CWE-20 CWE-122 CWE-416
Improper Input Validation Heap-based Buffer Overflow Use After Free
|
CVE-2026-44811
|
2026-06-13 02:00 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1042
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_26h1
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-44813
|
2026-06-13 01:59 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1043
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_11_26h1
|
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
|
CWE-122 CWE-125
Heap-based Buffer Overflow Out-of-bounds Read
|
CVE-2026-44814
|
2026-06-13 01:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1044
|
7.8 |
HIGH
Local
|
microsoft
|
windows_narrator_braille
|
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
|
CWE-426
Untrusted Search Path
|
CVE-2026-48565
|
2026-06-13 01:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1045
|
5.5 |
MEDIUM
Local
|
microsoft
|
visual_studio_code
|
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
|
CWE-20 CWE-23 NVD-CWE-noinfo
Improper Input Validation Relative Path Traversal
|
CVE-2026-48569
|
2026-06-13 01:57 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1046
|
6.5 |
MEDIUM
Network
|
gpac
|
gpac
|
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of…
|
CWE-1077
Floating Point Comparison with Incorrect Operator
|
CVE-2025-55658
|
2026-06-13 01:46 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1047
|
4.4 |
MEDIUM
Network
|
-
|
-
|
IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, lis…
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-47190
|
2026-06-13 01:24 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1048
|
- |
|
-
|
-
|
The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.
|
-
|
CVE-2026-40677
|
2026-06-13 01:22 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1049
|
- |
|
-
|
-
|
A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8828
|
2026-06-13 01:22 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1050
|
- |
|
-
|
-
|
Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.
|
CWE-284
Improper Access Control
|
CVE-2026-44976
|
2026-06-13 01:20 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|