Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
89,947 matching · page 191/1799Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-44802(opens NVD record) | High | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-44801(opens NVD record) | High | 7.5 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-44799(opens NVD record) | High | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42993(opens NVD record) | High | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42992(opens NVD record) | High | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42991(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42989(opens NVD record) | High | 7.8 | Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42987(opens NVD record) | High | 8.1 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42986(opens NVD record) | High | 7.8 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42985(opens NVD record) | High | 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42984(opens NVD record) | High | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42983(opens NVD record) | High | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42981(opens NVD record) | High | 8.1 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42980(opens NVD record) | High | 7.8 | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42979(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42978(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42977(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42974(opens NVD record) | High | 8.1 | Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42973(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | Jun 9, 2026 |
| CVE-2026-42972(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. | Jun 9, 2026 |
| CVE-2026-42971(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | Jun 9, 2026 |
| CVE-2026-42970(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | Jun 9, 2026 |
| CVE-2026-42969(opens NVD record) | Medium | 5.5 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | Jun 9, 2026 |
| CVE-2026-42968(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. | Jun 9, 2026 |
| CVE-2026-42916(opens NVD record) | High | 7.8 | Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42915(opens NVD record) | Medium | 5.5 | Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. | Jun 9, 2026 |
| CVE-2026-42914(opens NVD record) | Medium | 5.3 | Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. | Jun 9, 2026 |
| CVE-2026-42913(opens NVD record) | High | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42912(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42911(opens NVD record) | High | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42910(opens NVD record) | High | 7.8 | Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42909(opens NVD record) | High | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 |
| CVE-2026-42908(opens NVD record) | High | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | Jun 9, 2026 |
| CVE-2026-42907(opens NVD record) | Medium | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. | Jun 9, 2026 |
| CVE-2026-42906(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. | Jun 9, 2026 |
| CVE-2026-42905(opens NVD record) | High | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42904(opens NVD record) | Critical | 9.6 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | Jun 9, 2026 |
| CVE-2026-42903(opens NVD record) | Medium | 6.5 | Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. | Jun 9, 2026 |
| CVE-2026-42902(opens NVD record) | High | 7.8 | Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42837(opens NVD record) | High | 7.8 | Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42836(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42835(opens NVD record) | High | 8.1 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | Jun 9, 2026 |
| CVE-2026-42829(opens NVD record) | High | 7.8 | Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. | Jun 9, 2026 |
| CVE-2026-42828(opens NVD record) | High | 7.8 | Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 |
| CVE-2026-42771(opens NVD record) | Medium | 6.2 | Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen. Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so the most likely result is a crash and a Denial of Service. An internal helper function called from X509_VERIFY_PARAM_[set|add]_email() used a wrong length when validating the local part of an email address. This could cause the 64 octet limit on the local part of an email address to be not enforced, or cause an out of bound read and potentially a crash. The bug is reachable via S-MIME validation with a crafted From: address supplied in an email message that can potentially cause a crash. No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. | Jun 9, 2026 |
| CVE-2026-42770(opens NVD record) | Low | 3.7 | Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts. When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared. A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack). The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity. The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue. | Jun 9, 2026 |
| CVE-2026-42769(opens NVD record) | Medium | 5.3 | Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level. Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate. One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one. The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate. A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code). An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor. Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity. The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. | Jun 9, 2026 |
| CVE-2026-42768(opens NVD record) | Low | 3.7 | Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output. Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key. The attack is possible in 2 variants. 1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success. An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available. That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it. 2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted. An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle. We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity. To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled. The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key. The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption. The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary. | Jun 9, 2026 |
| CVE-2026-42767(opens NVD record) | Medium | 5.9 | Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client. Applications that process untrusted CMP/CRMF messages may be affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. | Jun 9, 2026 |
| CVE-2026-42766(opens NVD record) | Medium | 5.9 | Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service. The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present. An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service. Applications that process password-encrypted CMS messages may be affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. | Jun 9, 2026 |