CVE-2026-50294
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose inf
CVSS
6.2
Medium
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Published: Jul 14, 2026 · Last modified: Jul 16, 2026 · CWE-497
0.4%EPSS · 30 days0.4%
2026-07-152026-07-21
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-37507—16.7%
——5HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.13hCVE-2026-105884.4 MED5.0%
——2A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.5dCVE-2026-619775.3 MED9.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.9dCVE-2026-619765.3 MED9.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.9dCVE-2026-619755.3 MED9.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.9dCVE-2026-573936.5 MED18.9%
——6Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.12h