Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-24282

5.5

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

Microsoft
Details

CVE-2026-24018

7.8

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.

Fortinet
Details

CVE-2026-24017

8.1

An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through …

Fortinet
Details

CVE-2026-23907

5.3

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that …

Apache
Details

CVE-2026-23674

7.5

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

Microsoft
Details

CVE-2026-23673

7.8

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-23672

7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Microsoft
Details

CVE-2026-23671

7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally.

Concurrent
Details

CVE-2026-23669

8.8

Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

Microsoft
Details

CVE-2026-23668

7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Microsoft
Details
750/3864