Complete feed
Security advisories & CVEs
3544 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-61928] Windows Hello Tampering Vulnerability
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 3 more. Affected products named by the advisory: Windows Server 2022; Windows Server 2025 (Server Core installation).
Medium [CVE-2026-61368] Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.
Medium [CVE-2026-61347] Windows Event Logging Service Information Disclosure Vulnerability
Windows Event Logging Service Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-61345] Microsoft Remote Registry Service Denial of Service Vulnerability
Microsoft Remote Registry Service Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-59136] Microsoft COM for Windows Information Disclosure Vulnerability
Microsoft COM for Windows Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-59135] Microsoft Windows Search Component Information Disclosure Vulnerability
Microsoft Windows Search Component Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-59128] Windows Encrypting File System (EFS) Information Disclosure Vulnerability
Windows Encrypting File System (EFS) Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-63512] Microsoft SharePoint Server Tampering Vulnerability
Microsoft SharePoint Server Tampering Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-62837] Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-62829] Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability Affected products named by the advisory: Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-32791] Escalation of Privilege via Untrusted Search Path
Escalation of Privilege via Untrusted Search Path. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-426. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: pcm.
Medium [CVE-2025-31936] Privilege escalation via improper memory range handling in SMM
Privilege escalation via improper memory range handling in SMM. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: microcode_ctl.
Medium [CVE-2026-21399] Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow
Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120.
Medium [CVE-2026-20908] Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition
Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367.
Medium [CVE-2026-20786] Denial of service via out-of-bounds read
Denial of service via out-of-bounds read. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.
Medium [CVE-2026-20783] Denial of Service via improper conditions check
Denial of Service via improper conditions check. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-606.
Medium [CVE-2026-20731] Denial of Service via Improper Buffer Restrictions
Denial of Service via Improper Buffer Restrictions. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-131.
Medium [CVE-2026-73075] Out-of-bounds Access in Popup Opacity Handling
Out-of-bounds Access in Popup Opacity Handling. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-125.
Medium [CVE-2026-73074] Heap buffer overflow via integer wraparound in text property handling
Heap buffer overflow via integer wraparound in text property handling. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190.
Medium [CVE-2026-19078] Open redirect vulnerability enables phishing via unvalidated parameter.
Open redirect vulnerability enables phishing via unvalidated parameter. Red Hat rates this low (CVSS 4.3). Weakness: CWE-601. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.