CVE-2026-78450 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-78447 Windows Biometric Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-78448 Windows Biometric Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-78451 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-78453 Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
CVE-2026-78455 Xbox Information Disclosure Vulnerability
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-78452 Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-78454 Windows CD-ROM Driver Information Disclosure Vulnerability
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
CVE-2026-78456 SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-78457 Windows Security Health Service Elevation of Privilege Vulnerability
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.
CVE-2026-78462 Visual Studio Code Security Feature Bypass Vulnerability
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-69595 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
CVE-2026-78464 Windows MIDI Service Module Elevation of Privileges Vulnerability
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-66819 Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67369 Microsoft SQL Server Information Disclosure Vulnerability
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-78507 Microsoft Office Word Remote Code Execution Vulnerability
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78506 Microsoft Office Word Information Disclosure Vulnerability
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-78512 Microsoft Office Word Remote Code Execution Vulnerability
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78514 Microsoft Office Word Remote Code Execution Vulnerability
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78503 Microsoft Office Word Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.


