Vulnerabilities
Summary — last 7 days
New vulnerabilities2,731▼ 88 vs. last week
Critical / high1,419▲ 189 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)83▼ 429 vs. last week
9 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.3) | 0.42% | — | Sysinternals Process MonitorAI | 6/9/2026 | 7/23/2026 | A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. This enables attackers to steal administrative access tokens and session credentials. | |
| Deferred | Medium (4.2) | 0.27% | — | Sysinternals Process ExplorerAI | 5/7/2024 | 6/17/2026 | Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling. | |
| Modified | Medium (5.5) | 0.77% | — | Microsoft SysinternalsMicrosoft Sysinternals Process Monitor | 6/14/2023 | 6/17/2026 | Sysinternals Process Monitor for Windows Denial of Service Vulnerability | |
| Modified | High (10) | 7.4% | — | Microsoft Sysinternals Debugview | 11/8/2007 | 6/16/2026 | Dbgv.sys in Microsoft Sysinternals DebugView before 4.72 provides an unspecified mechanism for copying data into kernel memory, which allows local users to gain privileges via unspecified vectors. | |
| Modified | Medium (4.4) | 0.28% | — | Sysinternals Process Monitor | 9/19/2007 | 6/16/2026 | Process Monitor 1.22 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2)… | |
| Modified | Low (1.9) | 0.28% | — | Sysinternals Regmon | 9/19/2007 | 6/16/2026 | RegMon 7.04 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks to the (1) NtCreateKey and (2) NtOpenKey Windows Native API functions. | |
| Modified | High (10) | 3.5% | — | Sysinternals Process Explorer | 8/23/2005 | 6/16/2026 | Buffer overflow in Sysinternals Process Explorer 9.23, and other versions before 9.25, allows local users to execute arbitrary code via a long CompanyName field in the VersionInfo information in a running process. | |
| Modified | Medium (4.6) | 1.5% | — | Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+7 | 12/31/2004 | 6/16/2026 | Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not… | |
| Modified | Low (2.1) | 0.85% | — | Sysinternals Regmon | 12/31/2004 | 6/16/2026 | NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue. |