Security advisories from the vendors you use.
Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.
Connected directly to official vendor sources
The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.
4,726 advisories
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Message Queuing Remote Code Execution Vulnerability
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122871.
Windows Remote Desktop Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.
Windows Imaging Component Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Release Notes Install KB5002916.
Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Install KB5122771. Install KB5122770. Install KB5122768. Install KB5122769.
Microsoft SQL Server Remote Code Execution Vulnerability
Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.
Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122768. Install KB5122769.
Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Install KB5122769. Install KB5122768. Install KB5122775. Install KB5122773. Install KB5122774. Install KB5122771. Install KB5122770. Install KB5122772.
Microsoft SQL Server Remote Code Execution Vulnerability
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
Install KB5122773. Install KB5122771. Install KB5122770. Install KB5122772. Install KB5122769. Install KB5122768.
Skype for Business Remote Code Execution Vulnerability
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
Install KB5123300. Install KB5123287. Install KB5123301.
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
Release Notes
Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
Release Notes
HEVC Video Extensions Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
Update Information
CMS AuthEnvelopedData Processing May Accept Forged Messages
Mariner
Release Notes CBL-Mariner Releases
Entra ID Elevation of Privilege Vulnerability
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Copilot Studio Elevation of Privilege Vulnerability
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
Azure AI Language Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
Microsoft Fabric Elevation of Privilege Vulnerability
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Azure Cosmos DB Spoofing Vulnerability
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
Start with the vendor's bulletin.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.