π¨ CVE-2026-50353
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50357
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
π@cveNotify
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-50358
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50359
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50360
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
π@cveNotify
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-50361
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
π@cveNotify
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50386
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
π@cveNotify
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-50387
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
π@cveNotify
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50388
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
π@cveNotify
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-50389
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
π@cveNotify
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-50401
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
π@cveNotify
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-50402
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
π@cveNotify
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50403
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
π@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50421
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
π@cveNotify
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50422
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
π@cveNotify
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50424
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
π@cveNotify
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-57095
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
π@cveNotify
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-57096
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
π@cveNotify
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2025-45868
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.
π@cveNotify
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.
π@cveNotify
GitHub
Vulnerability-Disclosure/CVE-2025-45868/README.md at main Β· netero1010/Vulnerability-Disclosure
Contribute to netero1010/Vulnerability-Disclosure development by creating an account on GitHub.
π¨ CVE-2026-9103
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
π@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
π@cveNotify
Ibm
Security Bulletin: Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
An unauthenticated endpoint in the login API allowed any network-reachable attacker to obtain a 365-day superuser bearer token without requiring any credentials. The /api/v1/login/auto_login endpoint issued tokens when the AUTO_LOGIN configuration defaultedβ¦