Vulnerabilities

Summary — last 7 days

New vulnerabilities2,731▼ 88 vs. last week
Critical / high1,419▲ 189 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)83▼ 429 vs. last week
–

9 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.3)0.42%—Sysinternals Process MonitorAI6/9/20267/23/2026
A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. This enables attackers to steal administrative access tokens and session credentials.
DeferredMedium (4.2)0.27%—Sysinternals Process ExplorerAI5/7/20246/17/2026
Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling.
ModifiedMedium (5.5)0.77%—Microsoft SysinternalsMicrosoft Sysinternals Process Monitor6/14/20236/17/2026
Sysinternals Process Monitor for Windows Denial of Service Vulnerability
ModifiedHigh (10)7.4%—Microsoft Sysinternals Debugview11/8/20076/16/2026
Dbgv.sys in Microsoft Sysinternals DebugView before 4.72 provides an unspecified mechanism for copying data into kernel memory, which allows local users to gain privileges via unspecified vectors.
ModifiedMedium (4.4)0.28%—Sysinternals Process Monitor9/19/20076/16/2026
Process Monitor 1.22 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2)…
ModifiedLow (1.9)0.28%—Sysinternals Regmon9/19/20076/16/2026
RegMon 7.04 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks to the (1) NtCreateKey and (2) NtOpenKey Windows Native API functions.
ModifiedHigh (10)3.5%—Sysinternals Process Explorer8/23/20056/16/2026
Buffer overflow in Sysinternals Process Explorer 9.23, and other versions before 9.25, allows local users to execute arbitrary code via a long CompanyName field in the VersionInfo information in a running process.
ModifiedMedium (4.6)1.5%—Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+712/31/20046/16/2026
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not…
ModifiedLow (2.1)0.85%—Sysinternals Regmon12/31/20046/16/2026
NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.