Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.004
Published
2026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
8.1
EPSS Score
0.004
Published
2026-07-14
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.004
Published
2026-07-14
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.004
Published
2026-07-14
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.002
Published
2026-07-14
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
CVSS Score
6.5
EPSS Score
0.007
Published
2026-07-14
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.004
Published
2026-07-14
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
CVSS Score
4.3
EPSS Score
0.003
Published
2026-07-14
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
CVSS Score
4.3
EPSS Score
0.003
Published
2026-07-14
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
CVSS Score
7.2
EPSS Score
0.002
Published
2026-07-14


Contact Us

Shodan ® - All rights reserved