Common Vulnerabilities and Exposures (CVE)

CVE-2026-59131

Aug 20, 2026 22:01:12 UTC

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

CVE-2026-59126

Aug 20, 2026 22:01:11 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

CVE-2026-59125

Aug 20, 2026 22:01:11 UTC

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-59122

Aug 20, 2026 22:01:10 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-59119

Aug 20, 2026 22:01:10 UTC

Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

CVE-2026-58651

Aug 20, 2026 22:01:09 UTC

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-58641

Aug 20, 2026 22:01:09 UTC

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

CVE-2026-54981

Aug 20, 2026 22:01:08 UTC

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-42976

Aug 20, 2026 22:01:07 UTC

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

CVE-2026-55015

Aug 20, 2026 22:01:06 UTC

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

CVE-2026-69550

Aug 20, 2026 22:01:05 UTC

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-18824

Aug 20, 2026 22:01:05 UTC

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

CVE-2026-24301

Aug 20, 2026 22:01:05 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-69414

Aug 20, 2026 22:01:04 UTC

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this ...

CVE-2026-50523

Aug 20, 2026 22:01:04 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.