Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.004
Published
2026-06-09
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-06-09
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
CVSS Score
9.8
EPSS Score
0.155
Published
2026-06-09
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-06-09
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH's bundled XML parser expands nested <!ENTITY> declarations without a depth or count bound, so a small DTD can describe a body that expands exponentially ("billion laughs"). The PIDF body of a SIP PUBLISH is fed to this parser before any digest check, letting an unauthenticated network attacker force unbounded CPU and memory consumption with a single request. This issue has been patched in version 1.11.0.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-06-09
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.6
EPSS Score
0.006
Published
2026-06-09
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
CVSS Score
7.1
EPSS Score
0.004
Published
2026-06-09
User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
4.3
EPSS Score
0.006
Published
2026-06-09
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.003
Published
2026-06-09
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVSS Score
7.9
EPSS Score
0.003
Published
2026-06-09


Contact Us

Shodan ® - All rights reserved