Vulnerabilities
Tracked app vulnerabilities
16,412 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,412
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-20871
HIGH 7.8
Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20870
HIGH 7.8
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20869
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacke… |
|
CVE-2026-20868
HIGH 8.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-20867
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20866
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20865
HIGH 7.8
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20864
HIGH 7.8
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20863
HIGH 7.0
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20862
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-20861
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20860
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |
|
CVE-2026-20859
HIGH 7.8
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20858
HIGH 7.8
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20857
HIGH 7.8
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20856
HIGH 8.1
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-20854
HIGH 7.5
Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. |
|
CVE-2026-20853
HIGH 7.4
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate… |
|
CVE-2026-20852
HIGH 7.7
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. |
|
CVE-2026-20851
MEDIUM 6.2
Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20849
HIGH 7.5
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-20848
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… |
|
CVE-2026-20847
MEDIUM 6.5
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. |
|
CVE-2026-20844
HIGH 7.4
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-20843
HIGH 7.8
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20842
HIGH 7.0
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20840
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-20839
MEDIUM 5.5
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-20838
MEDIUM 5.5
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-20837
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
|
CVE-2026-20836
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile… |
|
CVE-2026-20835
MEDIUM 5.5
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. |
|
CVE-2026-20834
MEDIUM 4.6
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. |
|
CVE-2026-20832
HIGH 7.8
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability |
|
CVE-2026-20831
HIGH 7.8
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20829
MEDIUM 5.5
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. |
|
CVE-2026-20828
MEDIUM 4.6
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-20827
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose inform… |
|
CVE-2026-20826
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an autho… |
|
CVE-2026-20825
MEDIUM 4.4
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-20824
MEDIUM 5.5
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2026-20823
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20822
HIGH 7.8
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20821
MEDIUM 6.2
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20820
HIGH 7.8
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20819
MEDIUM 5.5
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. |
|
CVE-2026-20817
HIGH 7.8
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20816
HIGH 7.8
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20815
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz… |
|
CVE-2026-20814
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile… |