Common Vulnerabilities and Exposures (CVE)

CVE-2026-45636

Aug 13, 2026 20:53:17 UTC

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-45598

Aug 13, 2026 20:53:16 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-45601

Aug 13, 2026 20:53:16 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-45599

Aug 13, 2026 20:53:15 UTC

Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

CVE-2026-45597

Aug 13, 2026 20:53:14 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-45595

Aug 13, 2026 20:53:14 UTC

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-45604

Aug 13, 2026 20:53:13 UTC

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-45594

Aug 13, 2026 20:53:13 UTC

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-45593

Aug 13, 2026 20:53:12 UTC

Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.

CVE-2026-45592

Aug 13, 2026 20:53:11 UTC

Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-45591

Aug 13, 2026 20:53:11 UTC

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVE-2026-45586

Aug 13, 2026 20:53:10 UTC

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.

CVE-2026-45482

Aug 13, 2026 20:53:10 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-45476

Aug 13, 2026 20:53:09 UTC

Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-45465

Aug 13, 2026 20:53:08 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.