Vulnerabilities
Tracked app vulnerabilities
7,772 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-62696
HIGH 7.8
Local
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62695
HIGH 7.8
Local
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62693
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to ele… |
|
CVE-2026-62692
HIGH 7.8
Local
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62690
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-62688
HIGH 7.8
Local
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61939
HIGH 7.0
Local
Use after free in Winlogon allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61938
HIGH 7.0
Local
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61937
HIGH 7.8
Local
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61934
HIGH 7.8
Local
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61932
HIGH 7.8
Local
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61930
HIGH 7.8
Local
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61929
HIGH 7.0
Local
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61927
HIGH 7.0
Local
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61926
HIGH 7.8
Local
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61925
HIGH 7.8
Local
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61920
MEDIUM 6.6
Network
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a… |
|
CVE-2026-61367
HIGH 7.8
Local
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61365
HIGH 7.8
Local
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61364
HIGH 7.8
Local
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61363
HIGH 7.5
Network
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-61361
HIGH 7.0
Local
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. |
|
CVE-2026-61359
HIGH 7.8
Local
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61356
HIGH 7.8
Local
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61355
HIGH 7.8
Local
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61353
HIGH 7.8
Local
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61349
HIGH 7.8
Local
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61348
HIGH 7.0
Local
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59134
HIGH 7.5
Network
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-59127
HIGH 7.8
Local
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59126
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to e… |
|
CVE-2026-59122
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-56174
HIGH 7.8
Local
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50472
HIGH 7.0
Local
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49179
HIGH 8.8
Network
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code… |
|
CVE-2026-42976
HIGH 7.8
Local
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72971
HIGH 5.5
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability |
|
CVE-2026-70348
HIGH 5.5
Windows Management Services Denial of Service Vulnerability |
|
CVE-2026-70347
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-70346
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-70345
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-70344
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-70330
HIGH 6.7
Windows DNS Elevation of Privilege Vulnerability |
|
CVE-2026-70304
HIGH 6.7
Windows DNS Elevation of Privilege Vulnerability |
|
CVE-2026-68819
HIGH 5.9
Windows Network File System Denial of Service Vulnerability |
|
CVE-2026-6727
HIGH 5.9
MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability |
|
CVE-2026-6726
HIGH 7.9
MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse |
|
CVE-2026-66804
HIGH 7.8
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2026-66799
CRITICAL 7.8
Windows Key Guard Elevation of Privilege Vulnerability |
|
CVE-2026-65796
HIGH 5.9
Windows iSCSI Target Service Denial of Service Vulnerability |