CVE Database

Comprehensive vulnerability intelligence with advanced analytics

5.5

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.05%
View Details
6.2

Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.04%
View Details
7.8

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_10_22h2
EPSS: 0.06%
View Details
7.8

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.05%
View Details
7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.04%
View Details
6.5

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.07%
View Details
7.8

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2022
EPSS: 0.15%
View Details
7.8

Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.05%
View Details
7.8

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.04%
View Details
7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
7.7

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.04%
View Details
7.2

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft sql_server_2025
EPSS: 0.07%
View Details
7.5

Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.08%
View Details
7.5

A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a Denial-of-Service attack on a target…

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
7.5

A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.03%
View Details
7.8

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal resource caused scenario where potential for use after free was present.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.01%
View Details
6.2

Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
8.8

An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated network-adjacent attackers to perform arbitrary configuration changes without providing credentials, as long as a valid admin session is active. This can result in full compromise of the device (i.e., via unauthenticated access to /boaform/formSaveConfig…

Published: Jan 13, 2026
Modified: Jan 16, 2026
EPSS: 0.04%
View Details
3.8

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: fortinet fortisandbox
EPSS: 0.02%
View Details
6.5

Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.02%
View Details
9.8

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: fortinet fortisiem
EPSS: 0.09%
View Details

Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.04%
View Details
7.2

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code…

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: fortinet forticlientems
EPSS: 0.04%
View Details