CVE-2026-44705 tmp: Path Traversal via unsanitized prefix/postfix enables directory escape
Information published.
Categories: Microsoft
CVE-2026-52858 Vim: Arbitrary Code Execution via Python Omni-Completion
Information published.
Categories: Microsoft
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name
Information published.
Categories: Microsoft
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex
Information published.
Categories: Microsoft
CVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen Snapshot
Information published.
Categories: Microsoft
CVE-2026-52860 Vim: Arbitrary Code Execution via Python Omni-Completion
Information published.
Categories: Microsoft
CVE-2026-46683 Snappy: SSRF and local file read via the xsl-style-sheet option
Information published.
Categories: Microsoft
CVE-2026-46643 Snappy: Binary path is never shell-escaped due to an inverted is_executable check
Information published.
Categories: Microsoft
CVE-2026-42012 Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
Information published.
Categories: Microsoft
CVE-2026-5260 Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
Information published.
Categories: Microsoft
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
Information published.
Categories: Microsoft
CVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name
Information published.
Categories: Microsoft
CVE-2026-34355 Apache HTTP Server: mod_proxy_html buffer overflow
Information published.
Categories: Microsoft
CVE-2026-44185 Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`
Information published.
Categories: Microsoft
CVE-2026-34356 Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow
Information published.
Categories: Microsoft
CVE-2026-44186 Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
Information published.
Categories: Microsoft
CVE-2026-42535 Apache HTTP Server: mod_dav_fs protected directory access
Information published.
Categories: Microsoft
CVE-2026-44631 Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
Information published.
Categories: Microsoft
CVE-2026-29167 Apache HTTP Server: mod_ldap per-dir use-after-free
Information published.
Categories: Microsoft
CVE-2026-43951 Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash
Information published.
Categories: Microsoft


