<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Microsoft Windows</title>
  <link>https://cvedaily.com/pages/tags/windows.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/windows.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Microsoft Windows</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:26 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-50033 – Local privilege escalation due to DLL hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-50033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-50033</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-50033</strong></p>
  <p>Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44682 – Local privilege escalation due to DLL hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44682</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44682</strong></p>
  <p>Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44609 – Local privilege escalation due to EXE hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44609</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44609</strong></p>
  <p>Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42061 – Local privilege escalation due to excessive permissions assigned to child proces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42061</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42061</strong></p>
  <p>Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8036 – Improper input validation in NI-PAL may allow a local authenticated user to acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8036</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8036</strong></p>
  <p>Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8035 – Improper input validation in the NI-PAL kernel driver may allow a local authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8035</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8035</strong></p>
  <p>Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59612 – Memory corruption in windows drivers while sending incorrect trusted application...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59612</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59612</strong></p>
  <p>Memory corruption in windows drivers while sending incorrect trusted application request</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52011 – launch-editor allows users to open files with line numbers in editor from Node.j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52011</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52011</strong></p>
  <p>launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8501 – Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8501</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8501</strong></p>
  <p>Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-782</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4991 – Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4991</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4991</strong></p>
  <p>Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32325 – Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32325</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32325</strong></p>
  <p>Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-268</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27788 – Incorrect permission assignment for critical resource issue exists in ServerView...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27788</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27788</strong></p>
  <p>Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4387 – StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4387</guid>
    <pubDate>Fri, 29 May 2026 20:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4387</strong></p>
  <p>StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS permissions.    Exploitation requires local read access to the affected user's…</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10056 – CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10056</guid>
    <pubDate>Fri, 29 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10056</strong></p>
  <p>CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affect…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9994 – Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9994</guid>
    <pubDate>Thu, 28 May 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9994</strong></p>
  <p>Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-9991 – Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9991</guid>
    <pubDate>Thu, 28 May 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-9991</strong></p>
  <p>Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9984 – Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9984</guid>
    <pubDate>Thu, 28 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9984</strong></p>
  <p>Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9966 – Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9966</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9966</strong></p>
  <p>Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-9959 – Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9959</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-9959</strong></p>
  <p>Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9949 – Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9949</guid>
    <pubDate>Thu, 28 May 2026 23:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9949</strong></p>
  <p>Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9945 – Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9945</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9945</strong></p>
  <p>Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9937 – Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9937</guid>
    <pubDate>Thu, 28 May 2026 23:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9937</strong></p>
  <p>Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9932 – Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9932</guid>
    <pubDate>Thu, 28 May 2026 23:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9932</strong></p>
  <p>Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9928 – Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9928</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9928</strong></p>
  <p>Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9924 – Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.21...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9924</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9924</strong></p>
  <p>Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9907 – Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9907</guid>
    <pubDate>Thu, 28 May 2026 23:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9907</strong></p>
  <p>Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9905 – Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9905</guid>
    <pubDate>Thu, 28 May 2026 23:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9905</strong></p>
  <p>Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9890 – Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9890</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9890</strong></p>
  <p>Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10000 – Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10000</guid>
    <pubDate>Thu, 28 May 2026 23:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10000</strong></p>
  <p>Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10044 – Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10044</guid>
    <pubDate>Thu, 28 May 2026 22:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10044</strong></p>
  <p>Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences. Attackers can bypass the incomplete path traversal guard, which only blocks forward slashes and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46213 – In the Linux kernel, the following vulnerability has been resolved:

HID: applet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46213</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46213</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  HID: appletb-kbd: fix UAF in inactivity-timer cleanup path  Commit 38224c472a03 ("HID: appletb-kbd: fix slab use-after-free bug in appletb_kbd_probe") added timer_delete_sync(&kbd->inactivity_timer) to both the probe close_hw error path and appletb_kbd_remove(), but the way it was wired in left the inactivity timer reachable dur…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46139 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46139</guid>
    <pubDate>Thu, 28 May 2026 10:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46139</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: use kzalloc to zero-initialize security descriptor buffer  Commit 62e7dd0a39c2d ("smb: common: change the data type of num_aces to le16") split struct smb_acl's __le32 num_aces field into __le16 num_aces and __le16 reserved. The reserved field corresponds to Sbz2 in the MS-DTYP ACL wire format, which must be zero [1…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32996 – This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32996</guid>
    <pubDate>Thu, 28 May 2026 05:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32996</strong></p>
  <p>This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42184 – Tauri is a framework for building binaries for all major desktop platforms. From...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42184</guid>
    <pubDate>Wed, 27 May 2026 15:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42184</strong></p>
  <p>Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to http://<scheme>.localhost/ because those platforms' WebView implementations cannot serve custom URI scheme…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3676 – IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3676</guid>
    <pubDate>Wed, 27 May 2026 14:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3676</strong></p>
  <p>IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2237 – A use of get request method with sensitive query strings vulnerability in volume...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2237</guid>
    <pubDate>Wed, 27 May 2026 09:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2237</strong></p>
  <p>A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-598</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24193 – NVIDIA Display Driver for Windows and Linux contains a vulnerability where an at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24193</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24193</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24191 – NVIDIA Display Driver for Windows contains a vulnerability where an attacker cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24191</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24191</strong></p>
  <p>NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24190 – NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24190</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24190</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24182 – NVIDIA Display Driver for Windows and Linux contains a vulnerability where an at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24182</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24182</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33221 – NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33221</guid>
    <pubDate>Tue, 26 May 2026 18:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33221</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46430 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46430</guid>
    <pubDate>Tue, 26 May 2026 17:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46430</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows, and utils.JoinHostPort("", ":5553") resolves to ":5553". This vulnerability is fixed in 1.17.7.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45721 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45721</guid>
    <pubDate>Tue, 26 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45721</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named handler.lua to execute as the request handler. The loop terminates only after 100 ancestor steps or when filepath.Dir returns…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13755 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Win...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13755</guid>
    <pubDate>Tue, 26 May 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13755</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9489 – NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9489</guid>
    <pubDate>Mon, 25 May 2026 02:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9489</strong></p>
  <p>NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging t…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48831 – Wine ships a .desktop file that registers itself as a MIME handler for EXE files...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48831</guid>
    <pubDate>Sun, 24 May 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48831</strong></p>
  <p>Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions of the invoker. This allows escaping Flatpak and Snap sandboxes, because MIME handlers are not intended for use by code interpreters and loaders. NOTE: some par…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8673 – Unprotected transport of credentials vulnerability in syslink software AG Avantr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8673</guid>
    <pubDate>Fri, 22 May 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8673</strong></p>
  <p>Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks.  This issue affects Avantra: before 25.3.0.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-523</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8672 – Use of default password vulnerability in syslink software AG Avantra on Linux, W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8672</guid>
    <pubDate>Fri, 22 May 2026 14:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8672</strong></p>
  <p>Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords.  This issue affects Avantra: before 25.3.0.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8671 – Insertion of sensitive information into log file vulnerability in syslink softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8671</guid>
    <pubDate>Fri, 22 May 2026 14:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8671</strong></p>
  <p>Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure.  This issue affects Avantra: before 25.3.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8670 – Insufficient session expiration vulnerability in syslink software AG Avantra on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8670</guid>
    <pubDate>Fri, 22 May 2026 14:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8670</strong></p>
  <p>Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay).  This issue affects Avantra: before 25.3.1.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9118 – Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9118</guid>
    <pubDate>Wed, 20 May 2026 20:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9118</strong></p>
  <p>Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9112 – Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9112</guid>
    <pubDate>Wed, 20 May 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9112</strong></p>
  <p>Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9110 – Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.77...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9110</guid>
    <pubDate>Wed, 20 May 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9110</strong></p>
  <p>Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42834 – Improper access control in Windows Admin Center allows an authorized attacker to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42834</guid>
    <pubDate>Wed, 20 May 2026 13:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42834</strong></p>
  <p>Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45585 – Microsoft is aware of a security feature bypass vulnerability in Windows publicl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45585</guid>
    <pubDate>Wed, 20 May 2026 00:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45585</strong></p>
  <p>Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as &quot;YellowKey&quot;. The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34883 – An issue was discovered in the Portrait Dell Color Management application before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34883</guid>
    <pubDate>Tue, 19 May 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34883</strong></p>
  <p>An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate privileges to Administrator. During installation, the software writes the file CCFLFamily_07Feb11.edr to C:\ProgramData\Portrait Displays\CW\data\i1D3\ while running with elevated privileges. Because the…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47092 – Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47092</guid>
    <pubDate>Mon, 18 May 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47092</strong></p>
  <p>Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version check, causing execFile() to execute the attacker-supplied executable with cmd.exe arguments, resulti…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41119 – Dell Live Optics Windows and Personal Edition collectors contain an improper cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41119</guid>
    <pubDate>Mon, 18 May 2026 11:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41119</strong></p>
  <p>Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37247 – Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteServi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37247</guid>
    <pubDate>Sat, 16 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37247</strong></p>
  <p>Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46383 – Microsoft APM is an open-source, community-driven dependency manager for AI agen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46383</guid>
    <pubDate>Fri, 15 May 2026 17:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46383</strong></p>
  <p>Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm install is given a local .tar.gz that is not recognized as a plugin-format bundle, APM probes whether it is a l…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8398 – A supply chain attack compromised the official installation packages of DAEMON T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8398</guid>
    <pubDate>Fri, 15 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8398</strong></p>
  <p>A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.e…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-506</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7373 – Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7373</guid>
    <pubDate>Fri, 15 May 2026 03:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7373</strong></p>
  <p>Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which would in turn load an OpenSSL configuration file from a static location. This static location would be writable by a pre-existing "vagrant" user, if they already…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45369 – python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45369</guid>
    <pubDate>Thu, 14 May 2026 21:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45369</strong></p>
  <p>python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_protocol.py inserts user-controlled tool_args values directly into shell command strings without any sanitization or escaping. These commands are then executed via /bin/bash -c (Unix) or powershell.exe -Command (Windows), allowing an attacker to inject arbitrary shell commands.…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8574 – Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8574</guid>
    <pubDate>Thu, 14 May 2026 20:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8574</strong></p>
  <p>Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8573 – Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8573</guid>
    <pubDate>Thu, 14 May 2026 20:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8573</strong></p>
  <p>Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8567 – Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8567</guid>
    <pubDate>Thu, 14 May 2026 20:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8567</strong></p>
  <p>Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8563 – Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8563</guid>
    <pubDate>Thu, 14 May 2026 20:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8563</strong></p>
  <p>Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8559 – Integer overflow in Internationalization in Google Chrome on Windows prior to 14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8559</guid>
    <pubDate>Thu, 14 May 2026 20:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8559</strong></p>
  <p>Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8556 – Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8556</guid>
    <pubDate>Thu, 14 May 2026 20:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8556</strong></p>
  <p>Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8555 – Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8555</guid>
    <pubDate>Thu, 14 May 2026 20:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8555</strong></p>
  <p>Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8554 – Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8554</guid>
    <pubDate>Thu, 14 May 2026 20:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8554</strong></p>
  <p>Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8547 – Insufficient policy enforcement in Passwords in Google Chrome on Windows prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8547</guid>
    <pubDate>Thu, 14 May 2026 20:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8547</strong></p>
  <p>Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8546 – Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.777...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8546</guid>
    <pubDate>Thu, 14 May 2026 20:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8546</strong></p>
  <p>Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8542 – Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8542</guid>
    <pubDate>Thu, 14 May 2026 20:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8542</strong></p>
  <p>Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8531 – Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.16...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8531</guid>
    <pubDate>Thu, 14 May 2026 20:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8531</strong></p>
  <p>Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8530 – Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8530</guid>
    <pubDate>Thu, 14 May 2026 20:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8530</strong></p>
  <p>Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8519 – Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8519</guid>
    <pubDate>Thu, 14 May 2026 20:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8519</strong></p>
  <p>Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8510 – Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8510</guid>
    <pubDate>Thu, 14 May 2026 20:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8510</strong></p>
  <p>Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26191 – Fleet is open source device management software. Prior to version 4.81.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26191</guid>
    <pubDate>Thu, 14 May 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26191</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered. When a software package (.pkg, .deb, .rpm, .exe, or .msi) is uploaded to Fleet, metadata is extracted from…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24899 – Fleet is open source device management software. Prior to version 4.82.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24899</guid>
    <pubDate>Thu, 14 May 2026 20:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24899</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. Because Fleet validates JWT signatures using Microsoft's multi-tenant JWKS endpoint but does not enforce the `aud` (audience) or `iss` (issuer) claims, any Microsoft-signed Azure AD access token conta…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44586 – SiYuan is an open-source personal knowledge management system. From 2.1.12 to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44586</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44586</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are created with nodeIntegration: true and contextIsolation: false, a successful payload can call Node.…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23998 – Fleet is open source device management software. Prior to version 4.81.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23998</guid>
    <pubDate>Thu, 14 May 2026 19:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23998</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this could allow an attacker to impersonate an enrolled Windows device and retrieve sensitive configuration data. Fleet’s Windows MDM management endpoint rel…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42598 – Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42598</guid>
    <pubDate>Thu, 14 May 2026 18:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42598</strong></p>
  <p>Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible to request paths such as http://localhost:8080/c:/Windows/System32/drivers/etc/hosts and have the contents returned. This vulnerability is fixed in 2.13.0.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30906 – Untrusted search path in the installer for Zoom Rooms for Windows before version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30906</guid>
    <pubDate>Wed, 13 May 2026 19:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30906</strong></p>
  <p>Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30905 – External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30905</guid>
    <pubDate>Wed, 13 May 2026 19:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30905</strong></p>
  <p>External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0251 – Multiple local privilege escalation vulnerabilities in the Palo Alto Networks Gl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0251</guid>
    <pubDate>Wed, 13 May 2026 19:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0251</strong></p>
  <p>Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.  The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affect…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0249 – Multiple improper certificate validation vulnerabilities in the Palo Alto Networ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0249</guid>
    <pubDate>Wed, 13 May 2026 19:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0249</strong></p>
  <p>Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system user or an attacker on the same subnet to redirect traffic to an unauthorized server and facilitate the installation of malicious software…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0248 – An improper certificate validation vulnerability in the Prisma Access Agent® for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0248</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0248</strong></p>
  <p>An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information.    The Prisma Access Agent on macOS, Windows, Linux and iOS are…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0246 – A vulnerability with a privilege management mechanism in the Palo Alto Networks ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0246</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0246</strong></p>
  <p>A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts.    The Prisma Access Ag…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44470 – The Claude Desktop app gives you Claude Code with a graphical interface built fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44470</guid>
    <pubDate>Wed, 13 May 2026 16:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44470</strong></p>
  <p>The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Windows ran as SYSTEM and did not validate whether the VM bundle directory was a real directory or an NTFS directory junction before creating files within it. A local non-elevated user could replace the use…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-43483 – In the Linux kernel, the following vulnerability has been resolved:

KVM: SVM: S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43483</guid>
    <pubDate>Wed, 13 May 2026 16:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-43483</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated  Explicitly set/clear CR8 write interception when AVIC is (de)activated to fix a bug where KVM leaves the interception enabled after AVIC is activated.  E.g. if KVM emulates INIT=>WFS while AVIC is deactivated, CR8 will remain intercepted in perpetuity.  On it…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47091 – Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk &lt;2.4.0p2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47091</guid>
    <pubDate>Wed, 13 May 2026 10:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47091</strong></p>
  <p>Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whose name matches 'MySQL' or 'MariaDB' (or with write access to a binary referenced by such a service) to execute arbitrary code in the context of the Checkmk agent service, which typically runs as SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44612 – Bytello Share (Windows Edition) installer executable provided by Bytello insecur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44612</guid>
    <pubDate>Wed, 13 May 2026 06:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44612</strong></p>
  <p>Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44307 – Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44307</guid>
    <pubDate>Tue, 12 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44307</strong></p>
  <p>Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42896 – Integer overflow or wraparound in Windows DWM Core Library allows an authorized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42896</guid>
    <pubDate>Tue, 12 May 2026 18:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42896</strong></p>
  <p>Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42825 – Use after free in Windows Telephony Service allows an authorized attacker to ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42825</guid>
    <pubDate>Tue, 12 May 2026 18:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42825</strong></p>
  <p>Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42141 – Xibo is an open source digital signage platform with a web content management sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42141</guid>
    <pubDate>Tue, 12 May 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42141</strong></p>
  <p>Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41097 – Reliance on a component that is not updateable in Windows Secure Boot allows an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41097</guid>
    <pubDate>Tue, 12 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41097</strong></p>
  <p>Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-1329</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41096 – Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41096</guid>
    <pubDate>Tue, 12 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41096</strong></p>
  <p>Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41089 – Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41089</guid>
    <pubDate>Tue, 12 May 2026 18:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41089</strong></p>
  <p>Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41089">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
