Updated CVEs

IDDescriptionSeverityUpdated
CVE-2026-2395Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4.
critical
2026-07-30
CVE-2026-23904Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.
high
2026-07-30
CVE-2026-22068Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
medium
2026-07-30
CVE-2026-21655Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.
high
2026-07-30
CVE-2026-21653Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
high
2026-07-30
CVE-2026-21639A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.
medium
2026-07-30
CVE-2026-21265Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Windows Boot Manager 10/19/2026 For more information see this CVE and Windows Secure Boot certificate expiration and CA updates.
medium
2026-07-30
CVE-2026-21221Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-21047Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.
high
2026-07-30
CVE-2026-20962Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
medium
2026-07-30
CVE-2026-20941Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20940Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20939Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
medium
2026-07-30
CVE-2026-20938Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20937Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
medium
2026-07-30
CVE-2026-20936Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
medium
2026-07-30
CVE-2026-20935Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.
medium
2026-07-30
CVE-2026-20934Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
high
2026-07-30
CVE-2026-20932Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
medium
2026-07-30
CVE-2026-20931External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
high
2026-07-30
CVE-2026-20929Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
high
2026-07-30
CVE-2026-20927Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
medium
2026-07-30
CVE-2026-20926Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
high
2026-07-30
CVE-2026-20925External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-30
CVE-2026-20924Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20923Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20922Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
high
2026-07-30
CVE-2026-20921Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
high
2026-07-30
CVE-2026-20920Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20919Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
high
2026-07-30
CVE-2026-20918Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20877Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20876Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
medium
2026-07-30
CVE-2026-20875Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
high
2026-07-30
CVE-2026-20874Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20873Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20872External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
medium
2026-07-30
CVE-2026-20871Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20870Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20869Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20868Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
high
2026-07-30
CVE-2026-20867Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20866Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20865Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20864Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20863Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20862Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
medium
2026-07-30
CVE-2026-20861Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20860Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
high
2026-07-30
CVE-2026-20859Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
high
2026-07-30