|
311
|
7.5 |
HIGH
Network
|
-
|
-
|
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-42908
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
New
|
CWE-200
Information Exposure
|
CVE-2026-42907
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
New
|
CWE-200
Information Exposure
|
CVE-2026-42906
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-42905
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315
|
9.6 |
CRITICAL
Adjacent
|
-
|
-
|
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-42904
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
316
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-42903
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
New
|
CWE-285
Improper Authorization
|
CVE-2026-42902
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
318
|
7.8 |
HIGH
Local
|
-
|
-
|
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-42837
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319
|
7.0 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
New
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-42836
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
New
|
CWE-74
Injection
|
CVE-2026-42835
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|