Security advisories from the vendors you use.
Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.
Connected directly to official vendor sources
The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.
4,726 advisories
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Windows Update Stack Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.
Visual Studio Code Security Feature Bypass Vulnerability
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Release Notes
Microsoft Office Word Remote Code Execution Vulnerability
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Release Notes Install KB5002923.
Windows DHCP Server Denial of Service Vulnerability
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.
DirectWrite Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Work Folder Service Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123066.
Visual Studio Code Security Feature Bypass Vulnerability
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Release Notes
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows NTFS Remote Code Execution Vulnerability
Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows DHCP Server Denial of Service Vulnerability
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
Install KB5122876. Install KB5122882. Install KB5122871. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Device Association Broker Service Elevation of Privilege Vulnerability
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099.
Windows Error Reporting Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Release Notes
mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
ipvs: fix the checksum validations
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
sctp: reject stale cookies with mismatched verification tags
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
drm/vmwgfx: use check_add_overflow for shader size+offset bound
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
Mariner
See the Microsoft Security Update Guide for the update that applies to your product.
Start with the vendor's bulletin.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.