Total
398710 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-64898 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-13 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-64903 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2016 and 3 more | 2026-08-13 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-62871 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-13 | N/A | 7.8 HIGH |
| Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-12908 | 2026-08-13 | N/A | N/A | ||
| Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. | |||||
| CVE-2026-62799 | 1 Microsoft | 1 Windows 11 26h1 | 2026-08-13 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-62811 | 1 Microsoft | 6 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 3 more | 2026-08-13 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-65778 | 1 Microsoft | 2 Windows 11 24h2, Windows 11 25h2 | 2026-08-13 | N/A | 7.0 HIGH |
| Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-65779 | 1 Microsoft | 3 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 | 2026-08-13 | N/A | 7.0 HIGH |
| Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-65780 | 1 Microsoft | 3 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 | 2026-08-13 | N/A | 7.0 HIGH |
| Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-65781 | 1 Microsoft | 2 Windows 11 24h2, Windows 11 25h2 | 2026-08-13 | N/A | 7.0 HIGH |
| Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-62788 | 1 Microsoft | 5 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 2 more | 2026-08-13 | N/A | 7.0 HIGH |
| Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-62780 | 1 Microsoft | 5 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 2 more | 2026-08-13 | N/A | 7.0 HIGH |
| Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-64239 | 1 Linux | 1 Linux Kernel | 2026-08-13 | N/A | 7.8 HIGH |
| In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() DAMON sysfs maintains the DAMOS tried region directory objects via a linked list. When the user requests refresh of the directories, DAMON sysfs removes all the region directories first, and then generate updated regions directory on the empty space. The removal function (damon_sysfs_scheme_regions_rm_dirs()) only puts the kobj objects. Deletion of the container region object from the linked list is done inside the kobj release callback function. If somehow the callback invocation is delayed, the list will contain regions list that gonna be freed. If the updated region directories creation is started in this situation, the list can be corrupted and use-after-free can happen. Because the kobj objects are managed by only DAMON sysfs, the issue cannot happen in normal situation. But, such delays can be made on kernels that built with CONFIG_DEBUG_KOBJECT_RELEASE. On the kernel, the issue can indeed be reproduced like below. # damo start --damos_action stat # cd /sys/kernel/mm/damon/admin/kdamonds/0/ # for i in {1..10}; do echo update_schemes_tried_regions > state; done # dmesg | grep underflow [ 89.296152] refcount_t: underflow; use-after-free. Fix the issue by removing the region object from the list when decrementing the reference count. Also update damos_sysfs_populate_region_dir() to add the region object to the list only after the kobject_init_and_add() is success, so that fail of kobject_init_and_add() is not leaving the deallocated object on the list. The issue was discovered [1] by Sashiko. | |||||
| CVE-2026-65782 | 1 Microsoft | 2 Windows 11 24h2, Windows 11 25h2 | 2026-08-13 | N/A | 7.0 HIGH |
| Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-65783 | 1 Microsoft | 2 Windows 11 24h2, Windows 11 25h2 | 2026-08-13 | N/A | 7.0 HIGH |
| Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-64240 | 1 Linux | 1 Linux Kernel | 2026-08-13 | N/A | 5.5 MEDIUM |
| In the Linux kernel, the following vulnerability has been resolved: media: rc: igorplugusb: fix control request setup packet Commit eac69475b01f ("media: rc: igorplugusb: heed coherency rules") changed the control request storage from an embedded struct to an allocated pointer so it can obey DMA coherency rules. However, the driver still passes &ir->request to usb_fill_control_urb(). That points the URB setup packet at the pointer field itself rather than at the allocated struct usb_ctrlrequest. USB core then interprets pointer bytes as the setup packet. This can produce an invalid bRequestType and trigger the control direction warning reported by syzbot: usb 2-1: BOGUS control dir, pipe 80003580 doesn't match bRequestType 0 Pass ir->request itself as the setup packet. | |||||
| CVE-2026-62749 | 1 Microsoft | 4 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 1 more | 2026-08-13 | N/A | 7.0 HIGH |
| Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-64242 | 1 Linux | 1 Linux Kernel | 2026-08-13 | N/A | 7.8 HIGH |
| In the Linux kernel, the following vulnerability has been resolved: usb: gadget: net2280: Fix double free in probe error path usb_initialize_gadget() installs gadget_release() as the release callback for the embedded gadget device. The struct net2280 instance is therefore released through gadget_release() when the gadget device's last reference is dropped. The probe error path calls net2280_remove(), which tears down the partially initialized device and drops the gadget reference with usb_put_gadget(). Calling kfree(dev) afterwards can free the same object again. Drop the explicit kfree() and let the gadget device release callback handle the final free. This issue was found by a static analysis tool I am developing. | |||||
| CVE-2026-64241 | 1 Linux | 1 Linux Kernel | 2026-08-13 | N/A | 5.5 MEDIUM |
| In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: teardown bugs and resource leaks Address several teardown issues and resource leaks in the driver's remove path and error handling: 1. Debounce clock reference leak: The debounce clock (bank->db_clk) is obtained using of_clk_get() which increments the clock's reference count, but clk_put() is never called. Register a devm action to cleanly release it on unbind. Note that of_clk_get(..., 1) remains necessary over devm_clk_get() because the DT binding does not define clock-names, precluding name-based lookup. 2. Unregistered chained IRQ handler: The chained IRQ handler is not disconnected in remove(). If a stray interrupt fires after the driver is removed, the kernel attempts to execute a stale handler, leading to a panic. Fix this by clearing the handler in remove(). 3. IRQ domain leak: The linear IRQ domain and its generic chips are allocated manually during probe but never removed. Remove the IRQ domain during driver teardown to free the associated generic chips and mappings. [Bartosz: don't emit an error message on devres allocation failure] | |||||
| CVE-2026-62824 | 1 Microsoft | 3 Windows 10 1607, Windows Server 2012, Windows Server 2016 | 2026-08-13 | N/A | 8.8 HIGH |
| Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |||||
