Security advisories from the vendors you use.
Search new and updated bulletins from Microsoft, Citrix, Cisco, Palo Alto Networks, Fortinet, Ivanti, Delinea, Ubuntu, and AWS. We keep each vendor's advisory ID, affected products, CVEs, severity, dates, and available fix guidance together.
Connected directly to official vendor sources
The original vendor bulletin remains the authority. SecurityAlert gives you one place to find it and compare the details vendors publish in different formats.
4,737 advisories
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Skype for Business and Lync Denial of Service Vulnerability
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
Install KB5123301. Install KB5123287. Install KB5123300.
Skype for Business and Lync Denial of Service Vulnerability
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
Install KB5123301. Install KB5123287. Install KB5123300.
Skype for Business Information Disclosure Vulnerability
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
Install KB5123300. Install KB5123287. Install KB5123301.
Skype for Business Spoofing Vulnerability
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
Install KB5123301. Install KB5123300. Install KB5123287.
Skype for Business Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
Install KB5123300. Install KB5123287. Install KB5123301.
Skype for Business and Lync Denial of Service Vulnerability
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
Install KB5123301. Install KB5123300. Install KB5123287.
Microsoft Teams for Android Information Disclosure Vulnerability
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Release Notes
Microsoft Office Spoofing Vulnerability
Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.
Click to Run Release Notes Install KB5002916.
Skype for Business Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Install KB5123301. Install KB5123287. Install KB5123300.
Azure Arc SQL Server Extension Elevation of Privilege Vulnerability
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Release Notes
Windows Active Directory Domain Services Remote Code Execution Vulnerability
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Microsoft Word Remote Code Execution Vulnerability
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Click to Run Release Notes Install KB5002923.
Microsoft PowerShell Security Feature Bypass Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Active Directory Domain Services Denial of Service Vulnerability
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Netlogon Spoofing Vulnerability
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Install KB5122871. Install KB5124008. Install KB5124012.
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
Windows Push Notifications Elevation of Privilege Vulnerability
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012.
Windows Installer Elevation of Privilege Vulnerability
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Install KB5122876. Install KB5122882. Install KB5122878. Install KB5122871. Install KB5124008. Install KB5122880. Install KB5124012. Install KB5123099. Install KB5123065. Install KB5123066.
.NET Information Disclosure Vulnerability
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
Release Notes Install KB5126104. Install KB5126105. Install KB5126106.
Xbox Gaming Services Elevation of Privilege Vulnerability
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
Store
HEVC Video Extensions Elevation of Privilege Vulnerability
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
Update Information
ASP.NET Core Denial of Service Vulnerability
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Release Notes
Start with the vendor's bulletin.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.