Vulnerabilities
Tracked app vulnerabilities
6,145 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-61929
HIGH 7.0
Local
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61927
HIGH 7.0
Local
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61926
HIGH 7.8
Local
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61925
HIGH 7.8
Local
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61367
HIGH 7.8
Local
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61365
HIGH 7.8
Local
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61364
HIGH 7.8
Local
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61363
HIGH 7.5
Network
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-61361
HIGH 7.0
Local
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. |
|
CVE-2026-61359
HIGH 7.8
Local
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61356
HIGH 7.8
Local
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61355
HIGH 7.8
Local
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61353
HIGH 7.8
Local
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61349
HIGH 7.8
Local
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61348
HIGH 7.0
Local
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59134
HIGH 7.5
Network
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-59127
HIGH 7.8
Local
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59126
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to e… |
|
CVE-2026-59122
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-56174
HIGH 7.8
Local
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50472
HIGH 7.0
Local
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49179
HIGH 8.8
Network
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code… |
|
CVE-2026-42976
HIGH 7.8
Local
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72971
HIGH 5.5
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability |
|
CVE-2026-70348
HIGH 5.5
Windows Management Services Denial of Service Vulnerability |
|
CVE-2026-70347
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-70346
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-70345
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-70344
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-70330
HIGH 6.7
Windows DNS Elevation of Privilege Vulnerability |
|
CVE-2026-70304
HIGH 6.7
Windows DNS Elevation of Privilege Vulnerability |
|
CVE-2026-68819
HIGH 5.9
Windows Network File System Denial of Service Vulnerability |
|
CVE-2026-6727
HIGH 5.9
MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability |
|
CVE-2026-6726
HIGH 7.9
MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse |
|
CVE-2026-66804
HIGH 7.8
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2026-65796
HIGH 5.9
Windows iSCSI Target Service Denial of Service Vulnerability |
|
CVE-2026-65794
HIGH 6.5
Windows SMB Client Information Disclosure Vulnerability |
|
CVE-2026-65790
HIGH 7.8
Windows Message Queuing Elevation of Privilege Vulnerability |
|
CVE-2026-65785
HIGH 6.5
Windows DHCP Client Denial of Service Vulnerability |
|
CVE-2026-65784
HIGH 5.5
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2026-65783
HIGH 7.0
Windows Autopilot Elevation of Privilege Vulnerability |
|
CVE-2026-65782
HIGH 7.0
Windows Autopilot Elevation of Privilege Vulnerability |
|
CVE-2026-65781
HIGH 7.0
Windows Autopilot Elevation of Privilege Vulnerability |
|
CVE-2026-65780
HIGH 7.0
Windows Autopilot Elevation of Privilege Vulnerability |
|
CVE-2026-65779
HIGH 7.0
Windows Autopilot Elevation of Privilege Vulnerability |
|
CVE-2026-65778
HIGH 7.0
Windows Autopilot Elevation of Privilege Vulnerability |
|
CVE-2026-65777
HIGH 5.3
Active Directory Security Feature Bypass Vulnerability |
|
CVE-2026-65681
HIGH 7.5
Windows iSCSI Target Service Denial of Service Vulnerability |
|
CVE-2026-65679
HIGH 8.1
Windows iSCSI Target Service Remote Code Execution Vulnerability |
|
CVE-2026-65672
HIGH 7.8
Remote Access API Elevation of Privilege Vulnerability |