CVE-2026-33825 Microsoft Defender Elevation of Privilege Vulnerability Microsoft Security 30 April 2026 om 16:00 Added FAQ information. This is an informational change only.
CVE-2026-24051 OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking Microsoft Security 30 April 2026 om 10:55 Information published.
CVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference Microsoft Security 30 April 2026 om 10:52 Information published.
CVE-2025-21870 ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers Microsoft Security 30 April 2026 om 10:48 Information published.
CVE-2025-21892 RDMA/mlx5: Fix the recovery flow of the UMR QP Microsoft Security 30 April 2026 om 10:45 Information published.
CVE-2026-25541 Bytes is vulnerable to integer overflow in BytesMut::reserve Microsoft Security 30 April 2026 om 10:12 Information published.
CVE-2019-1543 ChaCha20-Poly1305 with long nonces Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2022-2068 The c_rehash script allows command injection Microsoft Security 30 April 2026 om 10:47 Information published.
CVE-2019-1551 rsaz_512_sqr overflow bug on x86_64 Microsoft Security 30 April 2026 om 10:53 Information published.
CVE-2018-0734 Timing attack against DSA Microsoft Security 30 April 2026 om 10:52 Information published.
CVE-2018-0735 Timing attack against ECDSA signature generation Microsoft Security 30 April 2026 om 10:52 Information published.
CVE-2024-41067 btrfs: scrub: handle RST lookup error correctly Microsoft Security 30 April 2026 om 10:46 Information published.
CVE-2024-57976 btrfs: do proper folio cleanup when cow_file_range() failed Microsoft Security 30 April 2026 om 10:45 Information published.
CVE-2024-57974 udp: Deal with race between UDP socket address change and rehash Microsoft Security 30 April 2026 om 10:43 Information published.
CVE-2024-41045 bpf: Defer work in bpf_timer_cancel_and_free Microsoft Security 30 April 2026 om 10:42 Information published.
CVE-2026-6019 BaseCookie.js_output() does not neutralize embedded characters Microsoft Security 30 April 2026 om 10:55 Information published.
CVE-2026-41898 rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer Microsoft Security 30 April 2026 om 10:55 Information published.
CVE-2026-6732 Libxml2: libxml2: denial of service via crafted xsd-validated document Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2019-1547 ECDSA remote timing attack Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2026-5778 Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path. Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2026-5188 Integer underflow in X.509 SAN parsing in wolfSSL Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2026-5295 Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2026-5503 out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2019-1563 Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey Microsoft Security 30 April 2026 om 10:54 Information published.
CVE-2026-5507 Session Cache Restore β Arbitrary Free via Deserialized Pointer Microsoft Security 30 April 2026 om 10:53 Information published.
CVE-2026-5504 PKCS7 CBC Padding Oracle β Plaintext Recovery Microsoft Security 30 April 2026 om 10:53 Information published.
CVE-2026-5393 OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS Microsoft Security 30 April 2026 om 10:53 Information published.