Latest warnings
| CVE-2024-21386 |
.NET Denial of Service Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21404 |
.NET Denial of Service Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2023-46838 |
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
|
MSRC | 2026‑02‑20 | High |
| CVE-2021-38593 |
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
|
MSRC | 2026‑02‑20 | High |
| CVE-2023-6200 |
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-24476 |
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-24479 |
A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-1550 |
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-25740 |
A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-22019 |
A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion bypassing standard safeguards like timeouts and body size limits.
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-24478 |
An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-26328 |
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-26327 |
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-25710 |
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-26308 |
Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-23807 |
Apache Xerces C++: Use-after-free on external DTD scan
|
MSRC | 2026‑02‑20 | High |
| CVE-2023-52481 |
arm64: errata: Add Cortex-A520 speculative unprivileged load workaround
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-21329 |
Azure Connected Machine Agent Elevation of Privilege Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-20667 |
Azure DevOps Server Remote Code Execution Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-20679 |
Azure Stack Hub Spoofing Vulnerability
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2022-48624 |
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-25739 |
create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes and crash because of a missing check for ubi->leb_size.
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-25112 |
Denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv2
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2023-52485 |
drm/amd/display: Wake DMCUB before sending a command
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-26607 |
drm/bridge: sii902x: Fix probing race issue
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-21394 |
Dynamics 365 Field Service Spoofing Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21396 |
Dynamics 365 Sales Spoofing Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21328 |
Dynamics 365 Sales Spoofing Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-25260 |
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2023-46045 |
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-1552 |
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21348 |
Internet Connection Sharing (ICS) Denial of Service Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21412 |
Internet Shortcut Files Security Feature Bypass Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-1312 |
Kernel: race condition leads to use after free during vma lock in lock_vma_under_rcu
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-26594 |
ksmbd: validate mech token in session setup
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-24575 |
libgit2 is vulnerable to a denial of service attack in `git_revparse_single`
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-24577 |
libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`
|
MSRC | 2026‑02‑20 | Critical |
| CVE-2024-26588 |
LoongArch: BPF: Prevent out-of-bounds memory access
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21349 |
Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21381 |
Microsoft Azure Active Directory B2C Spoofing Vulnerability
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-21397 |
Microsoft Azure File Sync Elevation of Privilege Vulnerability
|
MSRC | 2026‑02‑20 | Medium |
| CVE-2024-21403 |
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
|
MSRC | 2026‑02‑20 | Critical |
| CVE-2024-21376 |
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
|
MSRC | 2026‑02‑20 | Critical |
| CVE-2024-21364 |
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
|
MSRC | 2026‑02‑20 | Critical |
| CVE-2024-21315 |
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21389 |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21393 |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21395 |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21327 |
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
|
MSRC | 2026‑02‑20 | High |
| CVE-2024-21380 |
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
|
MSRC | 2026‑02‑20 | High |
Page 1