Security Vulnerabilities
- CVEs Published In 2026
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.