Where
AND
-Infinity
0

Vendor Risk Score

See how microsoft compares to other vendors in security performance

View Risk Score →

Software

Nlnet Labs UnboundPrivacy/configuration issue when adding local data in views through 'unbound-control'

Risk 23
Severity
3.1
First published (updated )

Nlnet Labs UnboundDNS Cookie bypass when combined with proxy-protocol use

Risk 21
Severity
3.7
First published (updated )

Nlnet Labs UnboundA wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path

Risk 21
Severity
3.7
First published (updated )

Nlnet Labs UnboundOff-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN

Risk 21
Severity
3.7
First published (updated )

Nlnet Labs UnboundExtra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records

Risk 21
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nlnet Labs UnboundDegradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries

Risk 21
Severity
3.7
First published (updated )

Microsoft Windows 11Win32k Information Disclosure Vulnerability

Risk 18
Severity
3.3
First published (updated )

Microsoft Windows 10Windows Kernel Information Disclosure Vulnerability

Risk 18
Severity
3.3
First published (updated )

Libarchive libarchiveLibarchive: heap overflow oob read while parsing a tar archive contains a pax extended header

Risk 25
Severity
3.9
First published (updated )

Nokogiri NokogiriNokogiri: Possible Use-After-Free in XInclude Processing

Risk 50
Severity
2.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nokogiri NokogiriNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

Risk 27
Severity
1.7
First published (updated )

Nokogiri NokogiriNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

Risk 27
Severity
1.7
First published (updated )

Nokogiri NokogiriNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

Risk 43
Severity
1.7
First published (updated )

Nokogiri NokogiriNokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

Risk 43
Severity
1.7
First published (updated )

Nokogiri XML::SchemaNokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Risk 15
Severity
2.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

NokogiriNokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

Risk 54
Severity
1.7
First published (updated )

gnupg gpgsmCMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS forma…

Risk 16
Severity
2.9
First published (updated )

rubygems/concurrent-rubyconcurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption

Risk 86
Severity
2.1
First published (updated )

rubygems/concurrent-rubyconcurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

Risk 32
Severity
2
First published (updated )

npm/undiciundici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

Risk 20
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxfoundation Runcrunc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

Risk 17
Severity
3.3
First published (updated )

Erlang Erlang\/otpSFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured

Risk 38
Severity
2.3
First published (updated )

Microsoft 365 AppsMicrosoft Excel Security Feature Bypass Vulnerability

Risk 17
Severity
3.3
First published (updated )

Microsoft 365 AppsMicrosoft Word Information Disclosure Vulnerability

Risk 17
Severity
3.3
First published (updated )

Microsoft Office 2016Microsoft Office Information Disclosure Vulnerability

Risk 17
Severity
3.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft Windows 10Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability

Risk 22
Severity
3.9
First published (updated )

tmux tmuxtmux image.c image_free use after free

Risk 34
Severity
1.1
First published (updated )

Google ChromeUninitialized Use in Skia

Risk 17
Severity
3.1
First published (updated )

OpenSC OpenSCOpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow

Risk 37
Severity
1.3
First published (updated )

Google ChromeChromium: CVE-2026-12032 Inappropriate implementation  Passwords

Risk 17
Severity
3.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203