Common Vulnerabilities and Exposures (CVE)

CVE-2026-47284

Aug 13, 2026 20:53:26 UTC

Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVE-2026-47281

Aug 13, 2026 20:53:25 UTC

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-45658

Aug 13, 2026 20:53:24 UTC

Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

CVE-2026-45647

Aug 13, 2026 20:53:24 UTC

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVE-2026-45654

Aug 13, 2026 20:53:23 UTC

Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-45653

Aug 13, 2026 20:53:22 UTC

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-45644

Aug 13, 2026 20:53:22 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.

CVE-2026-45608

Aug 13, 2026 20:53:21 UTC

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

CVE-2026-45637

Aug 13, 2026 20:53:21 UTC

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-45603

Aug 13, 2026 20:53:20 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-45638

Aug 13, 2026 20:53:20 UTC

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-45635

Aug 13, 2026 20:53:19 UTC

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

CVE-2026-45602

Aug 13, 2026 20:53:18 UTC

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

CVE-2026-45600

Aug 13, 2026 20:53:18 UTC

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-45596

Aug 13, 2026 20:53:17 UTC

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.