Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Windows

Windows Windows Server 2025

Advisory officiel

Windows Windows Server 2025 corrige 2618 CVE, dont 41 activement exploitées (CISA KEV). Les versions antérieures restent exposées à ces vulnérabilités.

Date de sortie
Fin de support
CVE corrigées
2618

132 critique · 2158 élevé

KEV CISA
41

CVE corrigées

CVE
CVE-2026-33824
CRITICAL 9.8 KEV

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVE-2025-59287 Exploit
CRITICAL 9.8 KEV

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2026-21510
HIGH 8.8 KEV

Windows Shell Security Feature Bypass Vulnerability

CVE-2026-21513
HIGH 8.8 KEV

MSHTML Framework Security Feature Bypass Vulnerability

CVE-2025-33053
HIGH 8.8 KEV

Internet Shortcut Files Remote Code Execution Vulnerability

CVE-2025-33073 Exploit
HIGH 8.8 KEV

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2024-49039
HIGH 8.8 KEV

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2026-81963
HIGH 7.8 KEV

Windows Update Stack Elevation of Privilege Vulnerability

CVE-2026-56155
HIGH 7.8 KEV

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVE-2026-21519
HIGH 7.8 KEV

Desktop Window Manager Elevation of Privilege Vulnerability

CVE-2026-21533
HIGH 7.8 KEV

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2025-62221
HIGH 7.8 KEV

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-60710
HIGH 7.8 KEV

Host Process for Windows Tasks Elevation of Privilege Vulnerability

CVE-2025-24990
HIGH 7.8 KEV

Windows Agere Modem Driver Elevation of Privilege Vulnerability

CVE-2025-59230
HIGH 7.8 KEV

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-30400
HIGH 7.8 KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-32701
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-32706
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-32709
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-29824
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-24985
HIGH 7.8 KEV

Windows Fast FAT File System Driver Remote Code Execution Vulnerability

CVE-2025-24993
HIGH 7.8 KEV

Windows NTFS Remote Code Execution Vulnerability

CVE-2025-21418
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-21333 Exploit
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2025-21334
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2025-21335
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2024-49138 Exploit
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-30397 Exploit
HIGH 7.5 KEV

Scripting Engine Memory Corruption Vulnerability

CVE-2025-21391
HIGH 7.1 KEV

Windows Storage Elevation of Privilege Vulnerability

CVE-2026-68820
HIGH 7.0 KEV

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2025-62215
HIGH 7.0 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-26633 Exploit
HIGH 7.0 KEV

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-24054 Exploit
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-43451
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2026-21525
MEDIUM 6.2 KEV

Windows Remote Access Connection Manager Denial of Service Vulnerability

CVE-2026-20805
MEDIUM 5.5 KEV

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CVE-2025-24991
HIGH 5.5 KEV

Windows NTFS Information Disclosure Vulnerability

CVE-2013-3900
MEDIUM 5.5 KEV

WinVerifyTrust Signature Validation Vulnerability

CVE-2025-47827
HIGH 4.6 KEV

MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11

CVE-2025-24984
HIGH 4.6 KEV

Windows NTFS Information Disclosure Vulnerability

CVE-2026-32202 Exploit
MEDIUM 4.3 KEV

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57092
CRITICAL 9.9

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

CVE-2025-49708
CRITICAL 9.9

Microsoft Graphics Component Elevation of Privilege Vulnerability

CVE-2026-78445
CRITICAL 9.8

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-77493
CRITICAL 9.8

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73025
CRITICAL 9.8

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-73009
CRITICAL 9.8

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-73010
CRITICAL 9.8

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

CVE-2026-72983
CRITICAL 9.8

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

CVE-2026-72979
CRITICAL 9.8

Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-72982
CRITICAL 9.8

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

CVE-2026-70296
CRITICAL 9.8

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-69910
CRITICAL 9.8

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

CVE-2026-69845
CRITICAL 9.8

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69824
CRITICAL 9.8

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.

CVE-2026-69829
CRITICAL 9.8

Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

CVE-2026-69768
CRITICAL 9.8

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.

CVE-2026-69730
CRITICAL 9.8

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-69715
CRITICAL 9.8

Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.

CVE-2026-69595
CRITICAL 9.8

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69590
CRITICAL 9.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-69586
CRITICAL 9.8

Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.

CVE-2026-69579
CRITICAL 9.8

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

CVE-2026-69525
CRITICAL 9.8

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVE-2026-69496
CRITICAL 9.8

Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.

CVE-2026-69491
CRITICAL 9.8

Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.

CVE-2026-69463
CRITICAL 9.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.

CVE-2026-69431
CRITICAL 9.8

Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.

CVE-2026-68839
CRITICAL 9.8

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69276
HIGH 9.8

Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability

CVE-2026-69408
HIGH 9.8

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

CVE-2026-69493
HIGH 9.8

Windows Event Logging Service Remote Code Execution Vulnerability

CVE-2026-69769
CRITICAL 9.8

Windows HTTP Print Provider Remote Code Execution Vulnerability

CVE-2026-69819
HIGH 9.8

RPC Runtime Library Remote Code Execution Vulnerability

CVE-2026-65791
CRITICAL 9.8

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

CVE-2026-62893
CRITICAL 9.8

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

CVE-2026-62878
CRITICAL 9.8

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-62815
CRITICAL 9.8

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

CVE-2026-56190
CRITICAL 9.8

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

CVE-2026-56188
CRITICAL 9.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to…

CVE-2026-56159
CRITICAL 9.8

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-50518
CRITICAL 9.8

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-50447
CRITICAL 9.8

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

CVE-2026-54990
CRITICAL 9.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-49172
CRITICAL 9.8

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

CVE-2026-42990
CRITICAL 9.8

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

CVE-2026-47291
CRITICAL 9.8

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

CVE-2026-45657
CRITICAL 9.8

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

CVE-2026-44815
CRITICAL 9.8

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

CVE-2026-41089
CRITICAL 9.8

Windows Netlogon Remote Code Execution Vulnerability

CVE-2026-41096
CRITICAL 9.8

Windows DNS Client Remote Code Execution Vulnerability

CVE-2025-60724
CRITICAL 9.8

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2025-53766
CRITICAL 9.8

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVE-2025-50165
CRITICAL 9.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-47981
CRITICAL 9.8

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability

CVE-2025-21298
CRITICAL 9.8

Windows OLE Remote Code Execution Vulnerability

CVE-2025-21307
CRITICAL 9.8

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

CVE-2025-21311
CRITICAL 9.8

Windows NTLM V1 Elevation of Privilege Vulnerability

CVE-2024-49112
CRITICAL 9.8

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2024-43639
CRITICAL 9.8

Windows KDC Proxy Remote Code Execution Vulnerability

CVE-2016-9535
CRITICAL 9.8

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when d…

CVE-2026-50380
CRITICAL 9.6

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVE-2026-42904
CRITICAL 9.6

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-49798
CRITICAL 9.3

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

CVE-2026-45602
CRITICAL 9.1

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

CVE-2025-50171
HIGH 9.1

Remote Desktop Spoofing Vulnerability

CVE-2026-83992
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-81955
HIGH 8.8

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2026-80096
HIGH 8.8

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

CVE-2026-80083
HIGH 8.8

Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.

CVE-2026-77495
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73023
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73012
HIGH 8.8

Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.

CVE-2026-73013
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73016
HIGH 8.8

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73006
HIGH 8.8

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2026-72986
HIGH 8.8

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

CVE-2026-72959
HIGH 8.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-72960
HIGH 8.8

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

CVE-2026-72950
HIGH 8.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-72940
HIGH 8.8

Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.

CVE-2026-71352
HIGH 8.8

Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

CVE-2026-71336
HIGH 8.8

Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

CVE-2026-70586
HIGH 8.8

Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.

CVE-2026-70203
HIGH 8.8

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

CVE-2026-69860
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-69729
HIGH 8.8

Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.

CVE-2026-69676
HIGH 8.8

Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.

CVE-2026-69669
HIGH 8.8

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.

CVE-2026-69628
HIGH 8.8

Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.

CVE-2026-69603
HIGH 8.8

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

CVE-2026-69598
HIGH 8.8

Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

CVE-2026-69601
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-69547
HIGH 8.8

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-69551
HIGH 8.8

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

CVE-2026-69518
HIGH 8.8

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

CVE-2026-69499
HIGH 8.8

Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-69461
HIGH 8.8

Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.

CVE-2026-69291
HIGH 8.8

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-62706
HIGH 8.8

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-62744
HIGH 8.8

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

CVE-2026-68828
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-69266
HIGH 8.8

Windows DHCP Server Remote Code Execution Vulnerability

CVE-2026-69334
HIGH 8.8

Windows Volume Manager Extension Driver Remote Code Execution Vulnerability

CVE-2026-69360
HIGH 8.8

Microsoft Office Word Remote Code Execution Vulnerability

CVE-2026-69386
HIGH 8.8

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

CVE-2026-69434
HIGH 8.8

Windows URL Moniker Remote Code Execution Vulnerability

CVE-2026-69485
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-69494
HIGH 8.8

Windows Event Logging Service Remote Code Execution Vulnerability

CVE-2026-69495
HIGH 8.8

Windows Event Logging Service Remote Code Execution Vulnerability

CVE-2026-69511
HIGH 8.8

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

CVE-2026-69712
CRITICAL 8.8

Windows Key Distribution Center Remote Code Execution Vulnerability

CVE-2026-69772
HIGH 8.8

Windows Network File System Remote Code Execution Vulnerability

CVE-2026-72933
HIGH 8.8

Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability

CVE-2026-73018
CRITICAL 8.8

Graphic Fonts Remote Code Execution Vulnerability

CVE-2026-77504
CRITICAL 8.8

Microsoft Office Word Remote Code Execution Vulnerability

CVE-2026-83996
HIGH 8.8

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2026-83998
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-62822
HIGH 8.8

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVE-2026-62823
HIGH 8.8

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-62816
HIGH 8.8

Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-62817
HIGH 8.8

Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-62818
HIGH 8.8

Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.

CVE-2026-62800
HIGH 8.8

Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.

CVE-2026-62795
HIGH 8.8

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

CVE-2026-62785
HIGH 8.8

Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

CVE-2026-62790
HIGH 8.8

Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.

CVE-2026-62784
HIGH 8.8

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.

CVE-2026-49179
HIGH 8.8

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code…

CVE-2026-58626
HIGH 8.8

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-58594
HIGH 8.8

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

CVE-2026-58534
HIGH 8.8

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

CVE-2026-57094
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57090
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-57087
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-56647
HIGH 8.8

Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

CVE-2026-56194
HIGH 8.8

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-54121
HIGH 8.8

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

CVE-2026-50692
HIGH 8.8

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-50687
HIGH 8.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50670
HIGH 8.8

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50666
HIGH 8.8

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-50489
HIGH 8.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-50474
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-50477
HIGH 8.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50444
HIGH 8.8

Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-50413
HIGH 8.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50398
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50385
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50382
HIGH 8.8

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

CVE-2026-50369
HIGH 8.8

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

CVE-2026-50370
HIGH 8.8

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-50360
HIGH 8.8

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-58608
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker t…

CVE-2026-54999
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o…

CVE-2026-54982
HIGH 8.8

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-54107
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg…

CVE-2026-49795
HIGH 8.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49178
HIGH 8.8

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

CVE-2026-48564
HIGH 8.8

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-47653
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47289
HIGH 8.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-45648
HIGH 8.8

Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

CVE-2026-42985
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-34329
HIGH 8.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2026-40403
CRITICAL 8.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2026-32225
HIGH 8.8

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-26167
HIGH 8.8

Windows Push Notifications Elevation of Privilege Vulnerability

CVE-2026-26178
HIGH 8.8

Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability

CVE-2026-32157
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-23669
HIGH 8.8

RPC Runtime Library Remote Code Execution Vulnerability

CVE-2026-24283
HIGH 8.8

Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability

CVE-2026-25177
HIGH 8.8

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2026-25188
HIGH 8.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-21255
HIGH 8.8

Windows Hyper-V Security Feature Bypass Vulnerability

CVE-2026-20868
HIGH 8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-62456
HIGH 8.8

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

CVE-2025-62549
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-64678
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-58715
HIGH 8.8

Windows Speech Runtime Elevation of Privilege Vulnerability

CVE-2025-58716
HIGH 8.8

Windows Speech Runtime Elevation of Privilege Vulnerability

CVE-2025-58718
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-59295
HIGH 8.8

Windows URL Parsing Remote Code Execution Vulnerability

CVE-2025-54106
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-54110
HIGH 8.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-54113
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-54918
CRITICAL 8.8

Windows NTLM Elevation of Privilege Vulnerability

CVE-2025-55234
HIGH 8.8

Windows SMB Elevation of Privilege Vulnerability

CVE-2025-49757
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-50163
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-53131
HIGH 8.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-53143
HIGH 8.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2025-53144
HIGH 8.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2025-53145
HIGH 8.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2025-53778
CRITICAL 8.8

Windows NTLM Elevation of Privilege Vulnerability

CVE-2025-47986
HIGH 8.8

Universal Print Management Service Elevation of Privilege Vulnerability

CVE-2025-47998
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-48817
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-48824
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49657
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49663
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49668
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49669
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49672
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49673
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49674
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49676
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49687
HIGH 8.8

Windows Input Method Editor (IME) Elevation of Privilege Vulnerability

CVE-2025-49688
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49723
HIGH 8.8

Windows StateRepository API Server file Tampering Vulnerability

CVE-2025-49724
HIGH 8.8

Windows Connected Devices Platform Service Remote Code Execution Vulnerability

CVE-2025-49729
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49740
HIGH 8.8

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2025-49753
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-33064
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-33066
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-29962
HIGH 8.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-29963
HIGH 8.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-29964
HIGH 8.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-29966
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-29967
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-21205
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21221
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21222
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-26647
HIGH 8.8

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-26669
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-27477
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-27481
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-27740
HIGH 8.8

Active Directory Certificate Services Elevation of Privilege Vulnerability

CVE-2025-24051
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-24056
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-26645
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-21190
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21200
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21201
HIGH 8.8

Windows Telephony Server Remote Code Execution Vulnerability

CVE-2025-21208
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-21368
HIGH 8.8

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVE-2025-21369
HIGH 8.8

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVE-2025-21371
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21406
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21407
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21410
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-21223
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21233
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21236
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21237
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21238
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21239
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21240
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21241
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21243
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21244
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21245
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21246
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21248
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21250
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21252
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21266
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21273
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21282
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21286
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21292
HIGH 8.8

Windows Search Service Elevation of Privilege Vulnerability

CVE-2025-21293
HIGH 8.8

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2025-21302
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21303
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21305
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21306
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21339
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21409
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21411
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21413
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21417
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-49080
HIGH 8.8

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

CVE-2024-49085
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-49086
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-49093
HIGH 8.8

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

CVE-2024-49102
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-49104
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-49117
CRITICAL 8.8

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2024-49125
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-43620
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43621
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43622
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43624
HIGH 8.8

Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability

CVE-2024-43627
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43628
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43635
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2026-27928
HIGH 8.7

Windows Hello Security Feature Bypass Vulnerability

CVE-2025-48822
CRITICAL 8.6

Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability

CVE-2025-27737
HIGH 8.6

Windows Security Zone Mapping Security Feature Bypass Vulnerability

CVE-2026-50340
HIGH 8.5

Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.

CVE-2026-69638
HIGH 8.4

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-69479
HIGH 8.4

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-77503
HIGH 8.4

Windows NTFS Elevation of Privilege Vulnerability

CVE-2026-54128
HIGH 8.4

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

CVE-2026-54992
HIGH 8.4

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

CVE-2026-54122
HIGH 8.4

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

CVE-2026-49184
HIGH 8.4

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-45641
HIGH 8.4

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVE-2026-45607
HIGH 8.4

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVE-2026-44810
HIGH 8.4

Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.

CVE-2026-32221
HIGH 8.4

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

CVE-2026-32091
HIGH 8.4

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2026-32162
HIGH 8.4

Windows COM Elevation of Privilege Vulnerability

CVE-2025-33067
HIGH 8.4

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2025-26678
HIGH 8.4

Windows Defender Application Control Security Feature Bypass Vulnerability

CVE-2025-24084
CRITICAL 8.4

Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability

CVE-2024-49105
CRITICAL 8.4

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-56179
HIGH 8.3

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-56181
HIGH 8.3

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-72962
HIGH 8.2

Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-72958
HIGH 8.2

Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

CVE-2026-72961
HIGH 8.2

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-69906
HIGH 8.2

Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-69874
HIGH 8.2

Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVE-2026-69846
HIGH 8.2

Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-50680
HIGH 8.2

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-50429
HIGH 8.2

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

CVE-2026-47652
HIGH 8.2

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

CVE-2026-83997
HIGH 8.1

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

CVE-2026-78450
HIGH 8.1

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-78444
HIGH 8.1

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

CVE-2026-78449
HIGH 8.1

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-72987
HIGH 8.1

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-72981
HIGH 8.1

Use after free in IP Helper allows an unauthorized attacker to execute code over a network.

CVE-2026-72936
HIGH 8.1

Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

CVE-2026-70563
HIGH 8.1

Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-70342
HIGH 8.1

Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69989
HIGH 8.1

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69858
HIGH 8.1

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-69827
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over …

CVE-2026-69813
HIGH 8.1

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-69680
HIGH 8.1

Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-69620
HIGH 8.1

Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69438
HIGH 8.1

Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.

CVE-2026-69325
HIGH 8.1

Microsoft JScript Remote Code Execution Vulnerability

CVE-2026-69510
HIGH 8.1

Windows DHCP Server Remote Code Execution Vulnerability

CVE-2026-69524
HIGH 8.1

Windows Active Directory Domain Services Remote Code Execution Vulnerability

CVE-2026-69530
CRITICAL 8.1

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

CVE-2026-69546
HIGH 8.1

Windows Active Directory Domain Services Remote Code Execution Vulnerability

CVE-2026-69732
HIGH 8.1

Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability

CVE-2026-69782
HIGH 8.1

Windows DNS Server Remote Code Execution Vulnerability

CVE-2026-69786
HIGH 8.1

Windows Text Shaping Remote Code Execution Vulnerability

CVE-2026-77505
CRITICAL 8.1

Windows DNS Server Remote Code Execution Vulnerability

CVE-2026-71331
HIGH 8.1

Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

CVE-2026-66802
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized a…

CVE-2026-65796
HIGH 8.1

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

CVE-2026-65789
HIGH 8.1

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-65679
HIGH 8.1

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

CVE-2026-62889
HIGH 8.1

Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-62820
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over…

CVE-2026-62819
HIGH 8.1

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-62792
HIGH 8.1

Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

CVE-2026-62781
HIGH 8.1

Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.

CVE-2026-62778
HIGH 8.1

Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56186
HIGH 8.1

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

CVE-2026-50686
HIGH 8.1

Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.

CVE-2026-50487
HIGH 8.1

Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50460
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50439
HIGH 8.1

Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.

CVE-2026-54995
HIGH 8.1

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-50694
HIGH 8.1

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-49164
HIGH 8.1

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

CVE-2026-42900
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri…

CVE-2026-45635
HIGH 8.1

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a netw…

CVE-2026-45599
HIGH 8.1

Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

CVE-2026-42981
HIGH 8.1

Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.

CVE-2026-42987
HIGH 8.1

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

CVE-2026-42974
HIGH 8.1

Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.

CVE-2026-40415
HIGH 8.1

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2026-33827
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o…

CVE-2026-20856
HIGH 8.1

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CVE-2025-50177
CRITICAL 8.1

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2025-33054
HIGH 8.1

Remote Desktop Spoofing Vulnerability

CVE-2025-49735
CRITICAL 8.1

Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability

CVE-2025-29828
CRITICAL 8.1

Windows Schannel Remote Code Execution Vulnerability

CVE-2025-32710
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-33070
CRITICAL 8.1

Windows Netlogon Elevation of Privilege Vulnerability

CVE-2025-33071
CRITICAL 8.1

Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability

CVE-2025-26663
CRITICAL 8.1

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2025-26670
CRITICAL 8.1

Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability

CVE-2025-26671
HIGH 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-27480
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-27482
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-24035
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-24045
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-24064
CRITICAL 8.1

Windows Domain Name Service Remote Code Execution Vulnerability

CVE-2025-21376
CRITICAL 8.1

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2025-21224
HIGH 8.1

Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

CVE-2025-21294
CRITICAL 8.1

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVE-2025-21295
CRITICAL 8.1

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability

CVE-2025-21297
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-21309
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49106
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49108
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49115
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49116
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49118
CRITICAL 8.1

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2024-49119
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49120
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49122
CRITICAL 8.1

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2024-49123
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49124
CRITICAL 8.1

Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability

CVE-2024-49126
CRITICAL 8.1

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

CVE-2024-49127
CRITICAL 8.1

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2024-49128
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-49132
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2024-43625
CRITICAL 8.1

Microsoft Windows VMSwitch Elevation of Privilege Vulnerability

CVE-2026-69875
HIGH 8.0

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69876
HIGH 8.0

Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

CVE-2026-69847
HIGH 8.0

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

CVE-2026-69826
HIGH 8.0

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69773
HIGH 8.0

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69727
HIGH 8.0

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69717
HIGH 8.0

Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

CVE-2026-69689
HIGH 8.0

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.

CVE-2026-69681
HIGH 8.0

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.

CVE-2026-69643
HIGH 8.0

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

CVE-2026-69623
HIGH 8.0

Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.

CVE-2026-69625
HIGH 8.0

Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.

CVE-2026-69619
HIGH 8.0

Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-69503
HIGH 8.0

Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.

CVE-2026-69505
HIGH 8.0

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69481
HIGH 8.0

Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.

CVE-2026-69423
HIGH 8.0

Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network.

CVE-2026-69371
HIGH 8.0

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network.

CVE-2026-69332
HIGH 8.0

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69322
HIGH 8.0

Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

CVE-2026-68838
HIGH 8.0

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-68834
HIGH 8.0

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-68827
HIGH 8.0

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

CVE-2026-68876
HIGH 8.0

Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

CVE-2026-68878
HIGH 8.0

Windows Fast FAT Driver Elevation of Privilege Vulnerability

CVE-2026-68880
HIGH 8.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-68894
HIGH 8.0

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2026-69271
HIGH 8.0

Microsoft Standard XPS Elevation of Privilege Vulnerability

CVE-2026-69301
HIGH 8.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69346
HIGH 8.0

Windows Print Spooler Components Elevation of Privilege Vulnerability

CVE-2026-69365
HIGH 8.0

Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability

CVE-2026-69412
HIGH 8.0

Windows DHCP Server Remote Code Execution Vulnerability

CVE-2026-69418
HIGH 8.0

Volume Manager Driver Elevation of Privilege Vulnerability

CVE-2026-69427
HIGH 8.0

Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability

CVE-2026-69458
HIGH 8.0

Windows BitLocker Elevation of Privilege Vulnerability

CVE-2026-69462
HIGH 8.0

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2026-69512
HIGH 8.0

Windows Spaceport.sys Elevation of Privilege Vulnerability

CVE-2026-69714
HIGH 8.0

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-69762
HIGH 8.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69807
HIGH 8.0

PowerShell Elevation of Privilege Vulnerability

CVE-2026-50683
HIGH 8.0

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2026-50502
HIGH 8.0

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

CVE-2026-50365
HIGH 8.0

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-49169
HIGH 8.0

Use after free in DNS Server allows an authorized attacker to execute code over a network.

CVE-2026-42975
HIGH 8.0

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-40400
HIGH 8.0

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-34332
HIGH 8.0

Windows Kernel-Mode Driver Remote Code Execution Vulnerability

CVE-2026-33826
HIGH 8.0

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

CVE-2026-27912
HIGH 8.0

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2026-25172
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2026-25173
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2026-26111
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2026-20931
HIGH 8.0

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2025-60715
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-62452
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-50160
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-50162
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-50164
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-53720
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-47972
HIGH 8.0

Windows Input Method Editor (IME) Elevation of Privilege Vulnerability

CVE-2025-49691
HIGH 8.0

Windows Miracast Wireless Display Remote Code Execution Vulnerability

CVE-2025-27487
HIGH 8.0

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-6726
HIGH 7.9

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a cred…

CVE-2026-48575
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48576
HIGH 7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48578
HIGH 7.9

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

CVE-2026-48568
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48570
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48573
HIGH 7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-47656
HIGH 7.9

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

CVE-2026-45654
HIGH 7.9

Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-45588
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-84000
HIGH 7.8

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

CVE-2026-83987
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83988
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83990
HIGH 7.8

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-83979
HIGH 7.8

Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83980
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83981
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83982
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83983
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83985
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83974
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83976
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83977
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83978
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83968
HIGH 7.8

Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83969
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83970
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83971
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83972
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83973
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83952
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-83954
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83955
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83967
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83498
HIGH 7.8

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-83942
HIGH 7.8

Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-80075
HIGH 7.8

Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.

CVE-2026-78448
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-77904
HIGH 7.8

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-77489
HIGH 7.8

Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73024
HIGH 7.8

Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-73026
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73020
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73021
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73011
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73014
HIGH 7.8

Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.

CVE-2026-73015
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73007
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72997
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73000
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73001
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73002
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72992
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72993
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72994
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72995
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72996
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72990
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72991
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72988
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72965
HIGH 7.8

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72967
HIGH 7.8

Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

CVE-2026-72957
HIGH 7.8

Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.

CVE-2026-72953
HIGH 7.8

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-72941
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72944
HIGH 7.8

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72946
HIGH 7.8

Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-72929
HIGH 7.8

Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-71343
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.

CVE-2026-71345
HIGH 7.8

Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.

CVE-2026-71334
HIGH 7.8

Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.

CVE-2026-71337
HIGH 7.8

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

CVE-2026-70574
HIGH 7.8

Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-70581
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70569
HIGH 7.8

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-70572
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70564
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-70289
HIGH 7.8

Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

CVE-2026-69921
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-69907
HIGH 7.8

Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.

CVE-2026-69900
HIGH 7.8

Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69841
HIGH 7.8

Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69844
HIGH 7.8

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69822
HIGH 7.8

Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVE-2026-69787
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69738
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69707
HIGH 7.8

Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69709
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-69691
HIGH 7.8

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-69685
HIGH 7.8

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVE-2026-69687
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69612
HIGH 7.8

Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69604
HIGH 7.8

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69608
HIGH 7.8

Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69589
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69592
HIGH 7.8

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69593
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69594
HIGH 7.8

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

CVE-2026-69583
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69584
HIGH 7.8

Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69585
HIGH 7.8

Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69580
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69582
HIGH 7.8

Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69571
HIGH 7.8

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69532
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-69513
HIGH 7.8

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69489
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69475
HIGH 7.8

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-69476
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69456
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVE-2026-69450
HIGH 7.8

Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69426
HIGH 7.8

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.

CVE-2026-69420
HIGH 7.8

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.

CVE-2026-69421
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69407
HIGH 7.8

Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69391
HIGH 7.8

Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69352
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69348
HIGH 7.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69323
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69312
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-69307
HIGH 7.8

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69298
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69293
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69295
HIGH 7.8

Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69284
HIGH 7.8

Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.

CVE-2026-69270
HIGH 7.8

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69265
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-68892
HIGH 7.8

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

CVE-2026-68875
HIGH 7.8

Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-68848
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-68844
HIGH 7.8

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.

CVE-2026-68845
HIGH 7.8

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVE-2026-68841
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-68832
HIGH 7.8

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-62697
HIGH 7.8

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-56172
HIGH 7.8

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

CVE-2026-56177
HIGH 7.8

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

CVE-2026-56198
HIGH 7.8

Microsoft Trace Data Helper Elevation of Privilege Vulnerability

CVE-2026-62810
HIGH 7.8

Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability

CVE-2026-68850
HIGH 7.8

Microsoft Account Elevation of Privilege Vulnerability

CVE-2026-68877
HIGH 7.8

Windows Storage Spaces Controller Remote Code Execution Vulnerability

CVE-2026-68885
HIGH 7.8

Microsoft Standard XPS Elevation of Privilege Vulnerability

CVE-2026-68888
HIGH 7.8

Microsoft Standard XPS Elevation of Privilege Vulnerability

CVE-2026-68890
HIGH 7.8

Microsoft Standard XPS Elevation of Privilege Vulnerability

CVE-2026-68896
HIGH 7.8

Microsoft Windows Search Component Elevation of Privilege Vulnerability

CVE-2026-69269
HIGH 7.8

Microsoft Standard XPS Elevation of Privilege Vulnerability

CVE-2026-69277
HIGH 7.8

Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability

CVE-2026-69283
HIGH 7.8

Windows CD-ROM Driver Elevation of Privilege Vulnerability

CVE-2026-69289
HIGH 7.8

Windows Setup Files Cleanup Elevation of Privilege Vulnerability

CVE-2026-69290
HIGH 7.8

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

CVE-2026-69324
HIGH 7.8

Windows Performance Monitor Elevation of Privilege Vulnerability

CVE-2026-69328
HIGH 7.8

Windows Storage Elevation of Privilege Vulnerability

CVE-2026-69359
HIGH 7.8

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2026-69368
HIGH 7.8

Windows Overlay Filter Elevation of Privilege Vulnerability

CVE-2026-69377
HIGH 7.8

Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability

CVE-2026-69389
HIGH 7.8

Windows Storage Management Provider Elevation of Privilege Vulnerability

CVE-2026-69392
HIGH 7.8

Windows Shell Elevation of Privilege Vulnerability

CVE-2026-69424
HIGH 7.8

Windows Distributed File System (DFS) Elevation of Privilege Vulnerability

CVE-2026-69432
HIGH 7.8

Volume Manager Driver Elevation of Privilege Vulnerability

CVE-2026-69433
HIGH 7.8

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2026-69436
HIGH 7.8

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2026-69444
HIGH 7.8

Microsoft Windows Speech Elevation of Privilege Vulnerability

CVE-2026-69445
HIGH 7.8

Windows Compressed Folder Elevation of Privilege Vulnerability

CVE-2026-69447
HIGH 7.8

Windows Audio Service Elevation of Privilege Vulnerability

CVE-2026-69455
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2026-69459
HIGH 7.8

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CVE-2026-69478
HIGH 7.8

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-69480
HIGH 7.8

Windows Partition Management Driver Elevation of Privilege Vulnerability

CVE-2026-69509
HIGH 7.8

Role: Windows Fax Service Elevation of Privilege Vulnerability

CVE-2026-69528
HIGH 7.8

Windows Shell Elevation of Privilege Vulnerability

CVE-2026-69534
HIGH 7.8

Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

CVE-2026-69535
HIGH 7.8

Windows Spaceport.sys Elevation of Privilege Vulnerability

CVE-2026-69538
HIGH 7.8

Windows Spaceport.sys Remote Code Execution Vulnerability

CVE-2026-69541
HIGH 7.8

Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

CVE-2026-69542
HIGH 7.8

Windows Camera Frame Server Monitor Elevation of Privilege Vulnerability

CVE-2026-69561
HIGH 7.8

Windows CD-ROM Driver Elevation of Privilege Vulnerability

CVE-2026-69576
HIGH 7.8

Graphic Fonts Elevation of Privilege Vulnerability

CVE-2026-69731
HIGH 7.8

HID Class Driver Elevation of Privilege Vulnerability

CVE-2026-69758
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-69785
HIGH 7.8

Windows Smart Card Elevation of Privilege Vulnerability

CVE-2026-69790
HIGH 7.8

Windows Credential Providers Elevation of Privilege Vulnerability

CVE-2026-69801
HIGH 7.8

Windows Audio Service Elevation of Privilege Vulnerability

CVE-2026-69821
HIGH 7.8

Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability

CVE-2026-70583
HIGH 7.8

Windows Core Messaging Elevation of Privilege Vulnerability

CVE-2026-70584
HIGH 7.8

Windows Core Messaging Elevation of Privilege Vulnerability

CVE-2026-78447
HIGH 7.8

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-83975
HIGH 7.8

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-83986
HIGH 7.8

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-83995
HIGH 7.8

Windows NTFS Elevation of Privilege Vulnerability

CVE-2026-70346
HIGH 7.8

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70347
HIGH 7.8

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70344
HIGH 7.8

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70345
HIGH 7.8

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-66799
HIGH 7.8

Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.

CVE-2026-65814
HIGH 7.8

Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-65786
HIGH 7.8

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-65787
HIGH 7.8

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-65790
HIGH 7.8

Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

CVE-2026-65773
HIGH 7.8

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-65774
HIGH 7.8

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-65775
HIGH 7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-65671
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.

CVE-2026-65672
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.

CVE-2026-62894
HIGH 7.8

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-62888
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-62890
HIGH 7.8

Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.

CVE-2026-62885
HIGH 7.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-62876
HIGH 7.8

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-62877
HIGH 7.8

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-62880
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-62832
HIGH 7.8

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62812
HIGH 7.8

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVE-2026-62803
HIGH 7.8

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVE-2026-62807
HIGH 7.8

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVE-2026-62811
HIGH 7.8

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-62797
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-62779
HIGH 7.8

Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.

CVE-2026-62783
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-62776
HIGH 7.8

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVE-2026-62777
HIGH 7.8

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-62768
HIGH 7.8

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-62770
HIGH 7.8

Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2026-62771
HIGH 7.8

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-62754
HIGH 7.8

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVE-2026-62755
HIGH 7.8

Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

CVE-2026-62758
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-62761
HIGH 7.8

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

CVE-2026-62751
HIGH 7.8

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2026-62752
HIGH 7.8

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVE-2026-62741
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-62747
HIGH 7.8

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62735
HIGH 7.8

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-62736
HIGH 7.8

Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

CVE-2026-62737
HIGH 7.8

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-62739
HIGH 7.8

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-62732
HIGH 7.8

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62733
HIGH 7.8

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-62722
HIGH 7.8

Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-62717
HIGH 7.8

Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

CVE-2026-62719
HIGH 7.8

Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

CVE-2026-62721
HIGH 7.8

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

CVE-2026-62711
HIGH 7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-62712
HIGH 7.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-62713
HIGH 7.8

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-62707
HIGH 7.8

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-62710
HIGH 7.8

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62696
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62698
HIGH 7.8

Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.

CVE-2026-62700
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-62701
HIGH 7.8

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62692
HIGH 7.8

Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-62695
HIGH 7.8

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-61937
HIGH 7.8

Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-61934
HIGH 7.8

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-61925
HIGH 7.8

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-61926
HIGH 7.8

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-61930
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-61923
HIGH 7.8

Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61367
HIGH 7.8

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61364
HIGH 7.8

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61365
HIGH 7.8

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61355
HIGH 7.8

Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61356
HIGH 7.8

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61357
HIGH 7.8

Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61358
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate …

CVE-2026-61359
HIGH 7.8

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-61349
HIGH 7.8

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61353
HIGH 7.8

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-59127
HIGH 7.8

Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-56174
HIGH 7.8

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVE-2026-54984
HIGH 7.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

CVE-2026-42976
HIGH 7.8

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

CVE-2026-58632
HIGH 7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-58613
HIGH 7.8

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58628
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to ele…

CVE-2026-58542
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-58538
HIGH 7.8

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58540
HIGH 7.8

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-58541
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2026-58532
HIGH 7.8

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-58536
HIGH 7.8

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58537
HIGH 7.8

Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-58527
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-58530
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVE-2026-57096
HIGH 7.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-57088
HIGH 7.8

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

CVE-2026-57091
HIGH 7.8

Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-56650
HIGH 7.8

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

CVE-2026-56643
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-56644
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-56189
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVE-2026-56182
HIGH 7.8

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-56175
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-56176
HIGH 7.8

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVE-2026-54124
HIGH 7.8

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

CVE-2026-54125
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-54115
HIGH 7.8

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

CVE-2026-50689
HIGH 7.8

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

CVE-2026-50688
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50679
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-50673
HIGH 7.8

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50667
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges…

CVE-2026-50655
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-50509
HIGH 7.8

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50501
HIGH 7.8

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVE-2026-50498
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-50499
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-50493
HIGH 7.8

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50494
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50484
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50486
HIGH 7.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50488
HIGH 7.8

Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate …

CVE-2026-50476
HIGH 7.8

Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.

CVE-2026-50478
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50479
HIGH 7.8

Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50469
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50471
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50461
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50462
HIGH 7.8

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-50466
HIGH 7.8

Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50454
HIGH 7.8

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

CVE-2026-50457
HIGH 7.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50458
HIGH 7.8

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50448
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50450
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized …

CVE-2026-50441
HIGH 7.8

Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50433
HIGH 7.8

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50435
HIGH 7.8

Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

CVE-2026-50436
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50427
HIGH 7.8

Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-50421
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate priv…

CVE-2026-50422
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50423
HIGH 7.8

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50425
HIGH 7.8

Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.

CVE-2026-50412
HIGH 7.8

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50417
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50405
HIGH 7.8

Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.

CVE-2026-50407
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50399
HIGH 7.8

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50400
HIGH 7.8

Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-50402
HIGH 7.8

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50391
HIGH 7.8

Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.

CVE-2026-50386
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50387
HIGH 7.8

Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.

CVE-2026-50388
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50378
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privi…

CVE-2026-50373
HIGH 7.8

Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-50367
HIGH 7.8

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50361
HIGH 7.8

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50362
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVE-2026-50363
HIGH 7.8

Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-50353
HIGH 7.8

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-50357
HIGH 7.8

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-50344
HIGH 7.8

Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.

CVE-2026-50346
HIGH 7.8

Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50347
HIGH 7.8

Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.

CVE-2026-50337
HIGH 7.8

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

CVE-2026-50343
HIGH 7.8

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50331
HIGH 7.8

Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.

CVE-2026-50332
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50335
HIGH 7.8

Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

CVE-2026-50326
HIGH 7.8

Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.

CVE-2026-50327
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

CVE-2026-50329
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50315
HIGH 7.8

Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

CVE-2026-50317
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to eleva…

CVE-2026-50321
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv…

CVE-2026-50309
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50313
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50305
HIGH 7.8

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50306
HIGH 7.8

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

CVE-2026-58609
HIGH 7.8

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

CVE-2026-58610
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVE-2026-58635
HIGH 7.8

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privil…

CVE-2026-58601
HIGH 7.8

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58602
HIGH 7.8

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-55004
HIGH 7.8

Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-54993
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

CVE-2026-55001
HIGH 7.8

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

CVE-2026-54986
HIGH 7.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54987
HIGH 7.8

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

CVE-2026-54991
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-54112
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg…

CVE-2026-54114
HIGH 7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54109
HIGH 7.8

Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-50697
HIGH 7.8

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50351
HIGH 7.8

Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.

CVE-2026-50311
HIGH 7.8

Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.

CVE-2026-50318
HIGH 7.8

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50333
HIGH 7.8

Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-50308
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-49808
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileg…

CVE-2026-50293
HIGH 7.8

Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.

CVE-2026-49800
HIGH 7.8

Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.

CVE-2026-49793
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-49796
HIGH 7.8

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

CVE-2026-49797
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-49792
HIGH 7.8

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-49783
HIGH 7.8

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-49175
HIGH 7.8

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-49176
HIGH 7.8

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

CVE-2026-49166
HIGH 7.8

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-49170
HIGH 7.8

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVE-2026-42982
HIGH 7.8

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-44800
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-8863
HIGH 7.8

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the bo…

CVE-2026-48574
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-48583
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-45658
HIGH 7.8

Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

CVE-2026-45656
HIGH 7.8

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

CVE-2026-45636
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-45637
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-45638
HIGH 7.8

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-45605
HIGH 7.8

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-45600
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-45592
HIGH 7.8

Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-45593
HIGH 7.8

Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.

CVE-2026-45586
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileg…

CVE-2026-45487
HIGH 7.8

Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVE-2026-44812
HIGH 7.8

Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

CVE-2026-44802
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-44803
HIGH 7.8

Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

CVE-2026-44809
HIGH 7.8

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-42989
HIGH 7.8

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

CVE-2026-42991
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42983
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-42986
HIGH 7.8

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-42977
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42978
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42979
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42980
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-42916
HIGH 7.8

Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-42905
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-42910
HIGH 7.8

Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

CVE-2026-42837
HIGH 7.8

Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-42828
HIGH 7.8

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-40404
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-40409
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-41092
HIGH 7.8

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

CVE-2026-33828
HIGH 7.8

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

CVE-2026-41088
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-40397
HIGH 7.8

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-40399
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg…

CVE-2026-40369
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-35417
HIGH 7.8

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVE-2026-34336
HIGH 7.8

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-33840
HIGH 7.8

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-33841
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-34330
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p…

CVE-2026-33834
HIGH 7.8

Windows Event Logging Service Elevation of Privilege Vulnerability

CVE-2026-33835
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-33837
HIGH 7.8

Windows TCP/IP Local Elevation of Privilege Vulnerability

CVE-2026-33838
HIGH 7.8

Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability

CVE-2026-34333
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-34334
HIGH 7.8

Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-34337
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-34338
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-34343
HIGH 7.8

Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability

CVE-2026-34344
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-34351
HIGH 7.8

Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-35415
HIGH 7.8

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

CVE-2026-35418
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-35420
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-35421
CRITICAL 7.8

Windows GDI Remote Code Execution Vulnerability

CVE-2026-40377
HIGH 7.8

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

CVE-2026-40382
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-40398
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-40407
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2026-40408
HIGH 7.8

Windows WAN ARP Driver Elevation of Privilege Vulnerability

CVE-2026-41095
HIGH 7.8

Data Deduplication Elevation of Privilege Vulnerability

CVE-2026-42896
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-33101
HIGH 7.8

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-33098
HIGH 7.8

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-32222
HIGH 7.8

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-32154
HIGH 7.8

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-32152
HIGH 7.8

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-20930
HIGH 7.8

Windows Management Services Elevation of Privilege Vulnerability

CVE-2026-26153
HIGH 7.8

Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability

CVE-2026-26156
HIGH 7.8

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-26159
HIGH 7.8

Remote Desktop Licensing Service Elevation of Privilege Vulnerability

CVE-2026-26160
HIGH 7.8

Remote Desktop Licensing Service Elevation of Privilege Vulnerability

CVE-2026-26161
HIGH 7.8

Windows Sensor Data Service Elevation of Privilege Vulnerability

CVE-2026-26162
HIGH 7.8

Windows OLE Elevation of Privilege Vulnerability

CVE-2026-26163
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-26168
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-26170
HIGH 7.8

PowerShell Elevation of Privilege Vulnerability

CVE-2026-26172
HIGH 7.8

Windows Push Notifications Elevation of Privilege Vulnerability

CVE-2026-26176
HIGH 7.8

Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability

CVE-2026-26179
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-26180
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-26181
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2026-26183
HIGH 7.8

Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability

CVE-2026-26184
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-27907
HIGH 7.8

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

CVE-2026-27909
HIGH 7.8

Windows Search Service Elevation of Privilege Vulnerability

CVE-2026-27910
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2026-27911
HIGH 7.8

Windows User Interface Core Elevation of Privilege Vulnerability

CVE-2026-27914
HIGH 7.8

Microsoft Management Console Elevation of Privilege Vulnerability

CVE-2026-27915
HIGH 7.8

Windows UPnP Device Host Elevation of Privilege Vulnerability

CVE-2026-27916
HIGH 7.8

Windows UPnP Device Host Elevation of Privilege Vulnerability

CVE-2026-27918
HIGH 7.8

Windows Shell Elevation of Privilege Vulnerability

CVE-2026-27919
HIGH 7.8

Windows UPnP Device Host Elevation of Privilege Vulnerability

CVE-2026-27920
HIGH 7.8

Windows UPnP Device Host Elevation of Privilege Vulnerability

CVE-2026-27923
HIGH 7.8

Desktop Window Manager Elevation of Privilege Vulnerability

CVE-2026-27927
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-32069
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-32074
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-32076
HIGH 7.8

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

CVE-2026-32077
HIGH 7.8

Windows UPnP Device Host Elevation of Privilege Vulnerability

CVE-2026-32078
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-32089
HIGH 7.8

Windows Speech Brokered Api Elevation of Privilege Vulnerability

CVE-2026-32090
HIGH 7.8

Windows Speech Brokered Api Elevation of Privilege Vulnerability

CVE-2026-32155
HIGH 7.8

Desktop Window Manager Elevation of Privilege Vulnerability

CVE-2026-32158
HIGH 7.8

Windows Push Notifications Elevation of Privilege Vulnerability

CVE-2026-32159
HIGH 7.8

Windows Push Notifications Elevation of Privilege Vulnerability

CVE-2026-32160
HIGH 7.8

Windows Push Notifications Elevation of Privilege Vulnerability

CVE-2026-32163
HIGH 7.8

Windows User Interface Core Elevation of Privilege Vulnerability

CVE-2026-32164
HIGH 7.8

Windows User Interface Core Elevation of Privilege Vulnerability

CVE-2026-32165
HIGH 7.8

Windows User Interface Core Elevation of Privilege Vulnerability

CVE-2026-32183
HIGH 7.8

Windows Snipping Tool Remote Code Execution Vulnerability

CVE-2026-24293
HIGH 7.8

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-24294
HIGH 7.8

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

CVE-2026-24289
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-23672
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-23673
HIGH 7.8

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

CVE-2026-24287
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-24290
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-24291
HIGH 7.8

Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability

CVE-2026-24292
HIGH 7.8

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2026-25165
HIGH 7.8

Performance Counters for Windows Elevation of Privilege Vulnerability

CVE-2026-25174
HIGH 7.8

Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

CVE-2026-25176
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-25187
HIGH 7.8

Winlogon Elevation of Privilege Vulnerability

CVE-2026-25190
HIGH 7.8

Windows GDI Remote Code Execution Vulnerability

CVE-2026-26128
HIGH 7.8

Windows SMB Server Elevation of Privilege Vulnerability

CVE-2026-26132
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21231
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21232
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21236
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21238
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21239
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21240
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21245
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21246
HIGH 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2026-21250 Exploit
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21251
HIGH 7.8

Cluster Client Failover (CCF) Elevation of Privilege Vulnerability

CVE-2026-20941
HIGH 7.8

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2026-20924
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20922
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-20923
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20873
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20874
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20877
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20918
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20867
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20870
HIGH 7.8

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20871
HIGH 7.8

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-20861
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20864
HIGH 7.8

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

CVE-2026-20865
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20866
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20857
HIGH 7.8

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-20858
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20859
HIGH 7.8

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-20860
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-20840
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-20843
HIGH 7.8

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-20832
HIGH 7.8

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

CVE-2026-20837
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-20826
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an autho…

CVE-2026-20831
HIGH 7.8

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-20820
HIGH 7.8

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-20822
HIGH 7.8

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-20816
HIGH 7.8

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-20817
HIGH 7.8

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-20809
HIGH 7.8

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

CVE-2026-20811
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2023-31096
HIGH 7.8

MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability

CVE-2024-55414
HIGH 7.8

Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability

CVE-2025-54100
HIGH 7.8

PowerShell Remote Code Execution Vulnerability

CVE-2025-55233
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-59516
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-59517
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-62454
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-62457
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-62461
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-62462
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-62464
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-62466
HIGH 7.8

Windows Client-Side Caching Elevation of Privilege Vulnerability

CVE-2025-62467
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-62470
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-62472
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-62474
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-62571
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-62572
HIGH 7.8

Application Information Service Elevation of Privilege Vulnerability

CVE-2025-64661
HIGH 7.8

Windows Shell Elevation of Privilege Vulnerability

CVE-2025-64673
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-64679
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-64680
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-59505
HIGH 7.8

Windows Smart Card Reader Elevation of Privilege Vulnerability

CVE-2025-59511
HIGH 7.8

Windows WLAN Service Elevation of Privilege Vulnerability

CVE-2025-59512
HIGH 7.8

Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability

CVE-2025-59514
HIGH 7.8

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVE-2025-60703
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2025-60705
HIGH 7.8

Windows Client-Side Caching Elevation of Privilege Vulnerability

CVE-2025-60707
HIGH 7.8

Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability

CVE-2025-60709
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-60713
HIGH 7.8

Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability

CVE-2025-60720
HIGH 7.8

Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability

CVE-2025-24052
HIGH 7.8

Windows Agere Modem Driver Elevation of Privilege Vulnerability

CVE-2025-50152
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-50175
HIGH 7.8

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-53150
HIGH 7.8

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-55328
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-55339
HIGH 7.8

Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability

CVE-2025-55677
HIGH 7.8

Windows Device Association Broker Service Elevation of Privilege Vulnerability

CVE-2025-55680
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-55692
HIGH 7.8

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2025-55694
HIGH 7.8

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2025-55696
HIGH 7.8

NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability

CVE-2025-55697
HIGH 7.8

Azure Local Elevation of Privilege Vulnerability

CVE-2025-55701
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-58714
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-58720
HIGH 7.8

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2025-58722
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-58728
HIGH 7.8

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-59187
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-59191
HIGH 7.8

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2025-59192
HIGH 7.8

Storport.sys Driver Elevation of Privilege Vulnerability

CVE-2025-59199
HIGH 7.8

Software Protection Platform (SPP) Elevation of Privilege Vulnerability

CVE-2025-59201
HIGH 7.8

Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability

CVE-2025-59207
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-59242
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-59254 Exploit
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-59255
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-59275
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59277
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59278
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59290
HIGH 7.8

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-53800
CRITICAL 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-54091
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-54092
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-54098
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-54102
HIGH 7.8

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2025-54111
HIGH 7.8

Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability

CVE-2025-54894
HIGH 7.8

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

CVE-2025-54895
HIGH 7.8

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability

CVE-2025-54912
HIGH 7.8

Windows BitLocker Elevation of Privilege Vulnerability

CVE-2025-54913
HIGH 7.8

Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability

CVE-2025-54916
HIGH 7.8

Windows NTFS Remote Code Execution Vulnerability

CVE-2025-55224
CRITICAL 7.8

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-55228
CRITICAL 7.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-49761
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-50155
HIGH 7.8

Windows Push Notifications Apps Elevation of Privilege Vulnerability

CVE-2025-50168
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2025-50170
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-50173
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-50176
CRITICAL 7.8

DirectX Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-53132
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2025-53133
HIGH 7.8

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-53141
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-53149
HIGH 7.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2025-53151
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-53154
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-53155
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-53723
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-53724
HIGH 7.8

Windows Push Notifications Apps Elevation of Privilege Vulnerability

CVE-2025-53725
HIGH 7.8

Windows Push Notifications Apps Elevation of Privilege Vulnerability

CVE-2025-53726
HIGH 7.8

Windows Push Notifications Apps Elevation of Privilege Vulnerability

CVE-2025-53789
HIGH 7.8

Windows StateRepository API Server file Elevation of Privilege Vulnerability

CVE-2025-55230
HIGH 7.8

Windows MBT Transport Driver Elevation of Privilege Vulnerability

CVE-2025-47159
HIGH 7.8

Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability

CVE-2025-47971
HIGH 7.8

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-47973
HIGH 7.8

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-47976
HIGH 7.8

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2025-47982
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-47985
HIGH 7.8

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2025-47987 Exploit
HIGH 7.8

Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability

CVE-2025-47991
HIGH 7.8

Windows Input Method Editor (IME) Elevation of Privilege Vulnerability

CVE-2025-47993
HIGH 7.8

Microsoft PC Manager Elevation of Privilege Vulnerability

CVE-2025-47996
HIGH 7.8

Windows MBT Transport Driver Elevation of Privilege Vulnerability

CVE-2025-48000
HIGH 7.8

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2025-48799
HIGH 7.8

Windows Update Service Elevation of Privilege Vulnerability

CVE-2025-48805
HIGH 7.8

Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability

CVE-2025-48806
HIGH 7.8

Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability

CVE-2025-48815
HIGH 7.8

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2025-48816
HIGH 7.8

HID Class Driver Elevation of Privilege Vulnerability

CVE-2025-48820
HIGH 7.8

Windows AppX Deployment Service Elevation of Privilege Vulnerability

CVE-2025-49659
HIGH 7.8

Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability

CVE-2025-49660
HIGH 7.8

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2025-49661
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-49665
HIGH 7.8

Workspace Broker Elevation of Privilege Vulnerability

CVE-2025-49667
HIGH 7.8

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-49675
HIGH 7.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2025-49679
HIGH 7.8

Windows Shell Elevation of Privilege Vulnerability

CVE-2025-49683 Exploit
HIGH 7.8

Microsoft Virtual Hard Disk Remote Code Execution Vulnerability

CVE-2025-49686
HIGH 7.8

Windows TCP/IP Driver Elevation of Privilege Vulnerability

CVE-2025-49689
HIGH 7.8

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-49693
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-49694
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-49721
HIGH 7.8

Windows Fast FAT File System Driver Elevation of Privilege Vulnerability

CVE-2025-49725
HIGH 7.8

Windows Notification Elevation of Privilege Vulnerability

CVE-2025-49726
HIGH 7.8

Windows Notification Elevation of Privilege Vulnerability

CVE-2025-49730 Exploit
HIGH 7.8

Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability

CVE-2025-49732
HIGH 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-49733
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2025-49742
HIGH 7.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-32712
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2025-32713
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-32714
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-32718
HIGH 7.8

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2025-33075
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-47955
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-30388
HIGH 7.8

Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

CVE-2025-24063
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-29970
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-30385
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-21204
HIGH 7.8

Windows Process Activation Elevation of Privilege Vulnerability

CVE-2025-24058
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-24060
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-24062
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-24073
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-24074
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-26639
HIGH 7.8

Windows USB Print Driver Elevation of Privilege Vulnerability

CVE-2025-26648
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-26666
HIGH 7.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-26674
HIGH 7.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-26675
HIGH 7.8

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVE-2025-26679
HIGH 7.8

RPC Endpoint Mapper Service Elevation of Privilege Vulnerability

CVE-2025-26688
HIGH 7.8

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-27476
HIGH 7.8

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-27490
HIGH 7.8

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-27727
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-27728
HIGH 7.8

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2025-27729
HIGH 7.8

Windows Shell Remote Code Execution Vulnerability

CVE-2025-27730
HIGH 7.8

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-27731
HIGH 7.8

Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability

CVE-2025-27739
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-29811
HIGH 7.8

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2025-29812
HIGH 7.8

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-21180
HIGH 7.8

Windows exFAT File System Remote Code Execution Vulnerability

CVE-2025-24044
HIGH 7.8

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-24046
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-24048
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-24050
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-24059
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-24061
HIGH 7.8

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2025-24066
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-24067
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-24072
HIGH 7.8

Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability

CVE-2025-24995
HIGH 7.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2025-21358
HIGH 7.8

Windows Core Messaging Elevation of Privileges Vulnerability

CVE-2025-21359
HIGH 7.8

Windows Kernel Security Feature Bypass Vulnerability

CVE-2025-21367
HIGH 7.8

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-21373
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-21375
HIGH 7.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2025-21420
HIGH 7.8

Windows Disk Cleanup Tool Elevation of Privilege Vulnerability

CVE-2025-21338
HIGH 7.8

GDI+ Remote Code Execution Vulnerability

CVE-2025-21234
HIGH 7.8

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-21235
HIGH 7.8

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-21275
HIGH 7.8

Windows App Package Installer Elevation of Privilege Vulnerability

CVE-2025-21281
HIGH 7.8

Microsoft COM for Windows Elevation of Privilege Vulnerability

CVE-2025-21287
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-21315
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-21325
HIGH 7.8

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVE-2025-21326
HIGH 7.8

Internet Explorer Remote Code Execution Vulnerability

CVE-2025-21372
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-21378
HIGH 7.8

Windows CSC Service Elevation of Privilege Vulnerability

CVE-2025-21382
HIGH 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2024-49072
HIGH 7.8

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-49076
HIGH 7.8

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

CVE-2024-49079
HIGH 7.8

Input Method Editor (IME) Remote Code Execution Vulnerability

CVE-2024-49088
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-49090
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-49114
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2024-43623
HIGH 7.8

Windows NT OS Kernel Elevation of Privilege Vulnerability

CVE-2024-43626
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2024-43629
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-43630
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-43636
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2024-43641
HIGH 7.8

Windows Registry Elevation of Privilege Vulnerability

CVE-2024-43644
HIGH 7.8

Windows Client-Side Caching Elevation of Privilege Vulnerability

CVE-2024-49019
HIGH 7.8

Active Directory Certificate Services Elevation of Privilege Vulnerability

CVE-2024-49046
HIGH 7.8

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2024-43583
HIGH 7.8

Winlogon Elevation of Privilege Vulnerability

CVE-2026-20852
HIGH 7.7

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

CVE-2026-20804
HIGH 7.7

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

CVE-2025-53139
HIGH 7.7

Windows Hello Security Feature Bypass Vulnerability

CVE-2025-55698
HIGH 7.7

DirectX Graphics Kernel Denial of Service Vulnerability

CVE-2025-59200
HIGH 7.7

Data Sharing Service Spoofing Vulnerability

CVE-2025-6965 Exploit
HIGH 7.7

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead…

CVE-2025-29833
CRITICAL 7.7

Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

CVE-2026-77893
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77895
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77886
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77888
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77889
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77890
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77501
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77502
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77498
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77499
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77494
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-73017
HIGH 7.5

Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.

CVE-2026-72989
HIGH 7.5

Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.

CVE-2026-72949
HIGH 7.5

Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.

CVE-2026-72954
HIGH 7.5

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

CVE-2026-72943
HIGH 7.5

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

CVE-2026-72928
HIGH 7.5

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

CVE-2026-72932
HIGH 7.5

Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.

CVE-2026-71330
HIGH 7.5

Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to dis…

CVE-2026-70587
HIGH 7.5

Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

CVE-2026-70065
HIGH 7.5

Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-69881
HIGH 7.5

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

CVE-2026-69890
HIGH 7.5

Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.

CVE-2026-69852
HIGH 7.5

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-69760
HIGH 7.5

Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network.

CVE-2026-69744
HIGH 7.5

Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.

CVE-2026-69631
HIGH 7.5

Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network.

CVE-2026-69607
HIGH 7.5

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

CVE-2026-69599
HIGH 7.5

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-69588
HIGH 7.5

Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

CVE-2026-69587
HIGH 7.5

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

CVE-2026-69539
HIGH 7.5

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-69514
HIGH 7.5

Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-69443
HIGH 7.5

Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.

CVE-2026-69428
HIGH 7.5

Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

CVE-2026-68887
HIGH 7.5

Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.

CVE-2026-62759
HIGH 7.5

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-62813
HIGH 7.5

Windows Active Directory Domain Services Remote Code Execution Vulnerability

CVE-2026-69329
HIGH 7.5

BranchCache Denial of Service Vulnerability

CVE-2026-69342
HIGH 7.5

Windows DHCP Server Denial of Service Vulnerability

CVE-2026-69397
HIGH 7.5

Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

CVE-2026-69429
HIGH 7.5

Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

CVE-2026-69793
HIGH 7.5

Windows TCP/IP Security Feature Bypass Vulnerability

CVE-2026-69809
HIGH 7.5

Windows Active Directory Domain Services Denial of Service Vulnerability

CVE-2026-70570
HIGH 7.5

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2026-81355
CRITICAL 7.5

Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability

CVE-2026-83989
HIGH 7.5

Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability

CVE-2026-84001
HIGH 7.5

Windows Key Distribution Center Denial of Service Vulnerability

CVE-2026-65681
HIGH 7.5

Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

CVE-2026-62787
HIGH 7.5

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

CVE-2026-61363
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-61352
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute…

CVE-2026-59132
HIGH 7.5

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

CVE-2026-59134
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-54113
HIGH 7.5

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

CVE-2026-58627
HIGH 7.5

Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-58531
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges …

CVE-2026-57089
HIGH 7.5

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.

CVE-2026-56648
HIGH 7.5

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-50685
HIGH 7.5

Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-50647
HIGH 7.5

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n…

CVE-2026-50505
HIGH 7.5

Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.

CVE-2026-50496
HIGH 7.5

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50500
HIGH 7.5

Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.

CVE-2026-50470
HIGH 7.5

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50463
HIGH 7.5

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

CVE-2026-50424
HIGH 7.5

Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

CVE-2026-50414
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50411
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-50368
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

CVE-2026-50355
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

CVE-2026-50330
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50328
HIGH 7.5

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

CVE-2026-50304
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

CVE-2026-54983
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-54119
HIGH 7.5

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

CVE-2026-50695
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

CVE-2026-50696
HIGH 7.5

Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

CVE-2026-49787
HIGH 7.5

Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVE-2026-49788
HIGH 7.5

Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVE-2026-49181
HIGH 7.5

Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-49171
HIGH 7.5

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVE-2026-40378
HIGH 7.5

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over …

CVE-2026-49160
HIGH 7.5

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVE-2026-48563
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47654
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-45639
HIGH 7.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-42992
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42993
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-44799
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-44801
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42913
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute…

CVE-2026-42908
HIGH 7.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-42909
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute…

CVE-2026-32161
CRITICAL 7.5

Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability

CVE-2026-35424
HIGH 7.5

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

CVE-2026-40405
HIGH 7.5

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40406
HIGH 7.5

Windows TCP/IP Information Disclosure Vulnerability

CVE-2026-33096
HIGH 7.5

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVE-2026-26154
HIGH 7.5

Windows Server Update Service (WSUS) Tampering Vulnerability

CVE-2026-32071
HIGH 7.5

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

CVE-2026-23674
HIGH 7.5

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2026-25181
HIGH 7.5

GDI+ Information Disclosure Vulnerability

CVE-2026-20846
HIGH 7.5

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

CVE-2026-21243
HIGH 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2026-20934
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20926
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20919
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20921
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20875
HIGH 7.5

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVE-2026-20854
HIGH 7.5

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

CVE-2026-20848
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20849
HIGH 7.5

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

CVE-2026-0386
HIGH 7.5

Windows Deployment Services Remote Code Execution Vulnerability

CVE-2025-64658
HIGH 7.5

Windows File Explorer Elevation of Privilege Vulnerability

CVE-2025-60704
HIGH 7.5

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-55326
HIGH 7.5

Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability

CVE-2025-58726
HIGH 7.5

Windows SMB Server Elevation of Privilege Vulnerability

CVE-2025-59502
MEDIUM 7.5

Remote Procedure Call Denial of Service Vulnerability

CVE-2025-53805
HIGH 7.5

HTTP.sys Denial of Service Vulnerability

CVE-2025-54919
HIGH 7.5

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-50169
HIGH 7.5

Windows SMB Remote Code Execution Vulnerability

CVE-2025-53722
HIGH 7.5

Windows Remote Desktop Services Denial of Service Vulnerability

CVE-2025-55231
HIGH 7.5

Windows Storage-based Management Service Remote Code Execution Vulnerability

CVE-2025-47984
HIGH 7.5

Windows GDI Information Disclosure Vulnerability

CVE-2025-48814
HIGH 7.5

Remote Desktop Licensing Service Security Feature Bypass Vulnerability

CVE-2025-32724
HIGH 7.5

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

CVE-2025-32725
HIGH 7.5

DHCP Server Service Denial of Service Vulnerability

CVE-2025-33050
HIGH 7.5

DHCP Server Service Denial of Service Vulnerability

CVE-2025-33056
HIGH 7.5

Windows Local Security Authority (LSA) Denial of Service Vulnerability

CVE-2025-33068
HIGH 7.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2025-26677
HIGH 7.5

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2025-29831
HIGH 7.5

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-29842
HIGH 7.5

UrlMon Security Feature Bypass Vulnerability

CVE-2025-29969
HIGH 7.5

MS-EVEN RPC Remote Code Execution Vulnerability

CVE-2025-26687
HIGH 7.5

Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-21174
HIGH 7.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2025-26641
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-26652
HIGH 7.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2025-26668
HIGH 7.5

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-26673
HIGH 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2025-26680
HIGH 7.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2025-26686
CRITICAL 7.5

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2025-27469
HIGH 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2025-27470
HIGH 7.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2025-27473
HIGH 7.5

HTTP.sys Denial of Service Vulnerability

CVE-2025-27479
HIGH 7.5

Kerberos Key Distribution Proxy Service Denial of Service Vulnerability

CVE-2025-27484
HIGH 7.5

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

CVE-2025-27485
HIGH 7.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2025-27486
HIGH 7.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2025-29810
HIGH 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2025-26634
HIGH 7.5

Windows Core Messaging Elevation of Privileges Vulnerability

CVE-2025-21181
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-21351
HIGH 7.5

Windows Active Directory Domain Services API Denial of Service Vulnerability

CVE-2025-21207
HIGH 7.5

Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability

CVE-2025-21218
HIGH 7.5

Windows Kerberos Denial of Service Vulnerability

CVE-2025-21220
HIGH 7.5

Microsoft Message Queuing Information Disclosure Vulnerability

CVE-2025-21230
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-21231
HIGH 7.5

IP Helper Denial of Service Vulnerability

CVE-2025-21251
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-21270
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-21276
HIGH 7.5

Windows MapUrlToZone Denial of Service Vulnerability

CVE-2025-21277
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-21285
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-21289
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-21290
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-21296
CRITICAL 7.5

BranchCache Remote Code Execution Vulnerability

CVE-2025-21300
HIGH 7.5

Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability

CVE-2025-21330
HIGH 7.5

Windows Remote Desktop Services Denial of Service Vulnerability

CVE-2025-21389
HIGH 7.5

Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability

CVE-2024-49075
HIGH 7.5

Windows Remote Desktop Services Denial of Service Vulnerability

CVE-2024-49096
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2024-49113
HIGH 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2024-49121
HIGH 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2024-49129
HIGH 7.5

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2024-43450
HIGH 7.5

Windows DNS Spoofing Vulnerability

CVE-2024-43452
HIGH 7.5

Windows Registry Elevation of Privilege Vulnerability

CVE-2024-43642
HIGH 7.5

Windows SMB Denial of Service Vulnerability

CVE-2024-30098
HIGH 7.5

Windows Cryptographic Services Security Feature Bypass Vulnerability

CVE-2026-69347
HIGH 7.4

Windows Fast FAT Driver Remote Code Execution Vulnerability

CVE-2026-54127
HIGH 7.4

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

CVE-2026-40413
HIGH 7.4

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40414
HIGH 7.4

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-32156
HIGH 7.4

Windows UPnP Device Host Remote Code Execution Vulnerability

CVE-2026-25167
HIGH 7.4

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2026-20844
HIGH 7.4

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

CVE-2025-48004
HIGH 7.4

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-55335
HIGH 7.4

Windows NTFS Elevation of Privilege Vulnerability

CVE-2025-55687
HIGH 7.4

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

CVE-2025-55693
HIGH 7.4

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-59189
HIGH 7.4

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-59206
HIGH 7.4

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

CVE-2025-59210
HIGH 7.4

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

CVE-2025-54103
HIGH 7.4

Windows Management Service Elevation of Privilege Vulnerability

CVE-2025-49690
HIGH 7.4

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

CVE-2025-29838
HIGH 7.4

Windows ExecutionContext Driver Elevation of Privilege Vulnerability

CVE-2025-21182
HIGH 7.4

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

CVE-2025-21183
HIGH 7.4

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

CVE-2026-50482
HIGH 7.3

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-58640
HIGH 7.3

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-49789
HIGH 7.3

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-49790
HIGH 7.3

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-32149
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21244 Exploit
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21247
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21248 Exploit
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-62565
HIGH 7.3

Windows File Explorer Elevation of Privilege Vulnerability

CVE-2025-25004
HIGH 7.3

PowerShell Elevation of Privilege Vulnerability

CVE-2025-54116
HIGH 7.3

Windows MultiPoint Services Elevation of Privilege Vulnerability

CVE-2025-54911
HIGH 7.3

Windows BitLocker Elevation of Privilege Vulnerability

CVE-2025-55236
CRITICAL 7.3

Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-50159
HIGH 7.3

Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability

CVE-2025-50161
HIGH 7.3

Win32k Elevation of Privilege Vulnerability

CVE-2025-49680
HIGH 7.3

Windows Performance Recorder (WPR) Denial of Service Vulnerability

CVE-2025-49682
HIGH 7.3

Windows Media Elevation of Privilege Vulnerability

CVE-2025-32721
HIGH 7.3

Windows Recovery Driver Elevation of Privilege Vulnerability

CVE-2025-24076 Exploit
HIGH 7.3

Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

CVE-2024-49107
HIGH 7.3

WmsRepair Service Elevation of Privilege Vulnerability

CVE-2025-53779
MEDIUM 7.2

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-49666
HIGH 7.2

Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability

CVE-2024-49089
HIGH 7.2

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-49091
HIGH 7.2

Windows Domain Name Service Remote Code Execution Vulnerability

CVE-2026-69688
HIGH 7.1

Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network.

CVE-2026-69602
HIGH 7.1

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.

CVE-2026-69597
HIGH 7.1

Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

CVE-2026-69536
HIGH 7.1

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-69482
HIGH 7.1

Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.

CVE-2026-69460
HIGH 7.1

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network.

CVE-2026-69396
HIGH 7.1

Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69366
HIGH 7.1

Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.

CVE-2026-69340
HIGH 7.1

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69313
HIGH 7.1

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69314
HIGH 7.1

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69305
HIGH 7.1

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

CVE-2026-69296
HIGH 7.1

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-68893
HIGH 7.1

Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-68889
HIGH 7.1

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-68846
HIGH 7.1

Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.

CVE-2026-68835
HIGH 7.1

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.

CVE-2026-69272
HIGH 7.1

Microsoft Standard XPS Elevation of Privilege Vulnerability

CVE-2026-69274
HIGH 7.1

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69336
HIGH 7.1

Microsoft Standard XPS Elevation of Privilege Vulnerability

CVE-2026-69337
HIGH 7.1

Windows Registry Elevation of Privilege Vulnerability

CVE-2026-69338
HIGH 7.1

Remote Desktop Gateway Service Elevation of Privilege Vulnerability

CVE-2026-69357
HIGH 7.1

Windows NDIS Elevation of Privilege Vulnerability

CVE-2026-69358
HIGH 7.1

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-69364
HIGH 7.1

Windows Print Spooler Components Elevation of Privilege Vulnerability

CVE-2026-69384
HIGH 7.1

Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability

CVE-2026-69451
HIGH 7.1

Windows Management Instrumentation Elevation of Privilege Vulnerability

CVE-2026-69553
HIGH 7.1

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2026-69706
HIGH 7.1

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69757
HIGH 7.1

Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-69761
HIGH 7.1

Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-69775
HIGH 7.1

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-50682
HIGH 7.1

Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.

CVE-2026-50465
HIGH 7.1

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVE-2026-50451
HIGH 7.1

Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-55144
HIGH 7.1

Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

CVE-2026-50354
HIGH 7.1

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49791
HIGH 7.1

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri…

CVE-2026-49165
HIGH 7.1

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVE-2026-47288
HIGH 7.1

Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.

CVE-2026-40401
HIGH 7.1

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-26151
HIGH 7.1

Remote Desktop Spoofing Vulnerability

CVE-2025-62570
HIGH 7.1

Windows Camera Frame Server Monitor Information Disclosure Vulnerability

CVE-2025-64720
HIGH 7.1

LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication

CVE-2025-65018
HIGH 7.1

LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`

CVE-2025-59208
HIGH 7.1

Windows MapUrlToZone Information Disclosure Vulnerability

CVE-2025-48819
HIGH 7.1

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

CVE-2025-48821
HIGH 7.1

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

CVE-2025-27491
CRITICAL 7.1

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-29809
HIGH 7.1

Windows Kerberos Security Feature Bypass Vulnerability

CVE-2025-25008
HIGH 7.1

Windows Server Elevation of Privilege Vulnerability

CVE-2025-21379
CRITICAL 7.1

DHCP Client Service Remote Code Execution Vulnerability

CVE-2025-21419
HIGH 7.1

Windows Setup Files Cleanup Elevation of Privilege Vulnerability

CVE-2025-21299
HIGH 7.1

Windows Kerberos Security Feature Bypass Vulnerability

CVE-2026-83999
HIGH 7.0

Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to e…

CVE-2026-83940
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-80093
HIGH 7.0

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-78457
HIGH 7.0

Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.

CVE-2026-77905
HIGH 7.0

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

CVE-2026-77894
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privi…

CVE-2026-73022
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-73005
HIGH 7.0

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

CVE-2026-73003
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-72963
HIGH 7.0

Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.

CVE-2026-72952
HIGH 7.0

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

CVE-2026-72930
HIGH 7.0

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.

CVE-2026-71353
HIGH 7.0

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-72926
HIGH 7.0

Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71351
HIGH 7.0

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71342
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-71332
HIGH 7.0

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

CVE-2026-71333
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-70585
HIGH 7.0

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

CVE-2026-70573
HIGH 7.0

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70577
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-70565
HIGH 7.0

Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.

CVE-2026-70567
HIGH 7.0

Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70568
HIGH 7.0

Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70562
HIGH 7.0

Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70283
HIGH 7.0

Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69911
HIGH 7.0

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69891
HIGH 7.0

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-69896
HIGH 7.0

Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69889
HIGH 7.0

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69859
HIGH 7.0

Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69866
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69834
HIGH 7.0

Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVE-2026-69838
HIGH 7.0

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-69816
HIGH 7.0

Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.

CVE-2026-69817
HIGH 7.0

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69818
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69814
HIGH 7.0

Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally.

CVE-2026-69791
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69692
HIGH 7.0

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69693
HIGH 7.0

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

CVE-2026-69694
HIGH 7.0

Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69682
HIGH 7.0

Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69648
HIGH 7.0

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

CVE-2026-69645
HIGH 7.0

Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

CVE-2026-69630
HIGH 7.0

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69621
HIGH 7.0

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69617
HIGH 7.0

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69610
HIGH 7.0

Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69613
HIGH 7.0

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

CVE-2026-69605
HIGH 7.0

Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69606
HIGH 7.0

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2026-69600
HIGH 7.0

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69578
HIGH 7.0

Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-69581
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69573
HIGH 7.0

Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69574
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69575
HIGH 7.0

Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

CVE-2026-69567
HIGH 7.0

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-69501
HIGH 7.0

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-69470
HIGH 7.0

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

CVE-2026-69472
HIGH 7.0

Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally.

CVE-2026-69473
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-69466
HIGH 7.0

Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-69430
HIGH 7.0

Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69422
HIGH 7.0

Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69413
HIGH 7.0

Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69404
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg…

CVE-2026-69379
HIGH 7.0

Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-69319
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevat…

CVE-2026-69310
HIGH 7.0

Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-69299
HIGH 7.0

Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.

CVE-2026-69287
HIGH 7.0

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-69281
HIGH 7.0

Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-68897
HIGH 7.0

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

CVE-2026-68884
HIGH 7.0

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-68847
HIGH 7.0

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

CVE-2026-68840
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv…

CVE-2026-68824
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an autho…

CVE-2026-68825
HIGH 7.0

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-62694
HIGH 7.0

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-50349
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-69275
HIGH 7.0

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2026-69279
HIGH 7.0

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-69280
HIGH 7.0

Windows Push Notifications Elevation of Privilege Vulnerability

CVE-2026-69292
HIGH 7.0

Remote Desktop Gateway Service Elevation of Privilege Vulnerability

CVE-2026-69300
HIGH 7.0

Windows Push Notifications Elevation of Privilege Vulnerability

CVE-2026-69309
HIGH 7.0

Windows Print Spooler Components Elevation of Privilege Vulnerability

CVE-2026-69311
HIGH 7.0

Windows Audio Service Elevation of Privilege Vulnerability

CVE-2026-69331
HIGH 7.0

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2026-69335
HIGH 7.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69341
HIGH 7.0

Windows Image Acquisition Elevation of Privilege Vulnerability

CVE-2026-69362
HIGH 7.0

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2026-69383
HIGH 7.0

Windows Shell Elevation of Privilege Vulnerability

CVE-2026-69385
HIGH 7.0

Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-69388
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2026-69394
HIGH 7.0

Windows Audio Service Elevation of Privilege Vulnerability

CVE-2026-69398
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2026-69401
HIGH 7.0

Audio Video Control Transport Protocol Elevation of Privilege Vulnerability

CVE-2026-69441
HIGH 7.0

Windows Installer Elevation of Privilege Vulnerability

CVE-2026-69448
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2026-69468
HIGH 7.0

Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability

CVE-2026-69488
HIGH 7.0

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-69492
HIGH 7.0

Windows Partition Management Driver Elevation of Privilege Vulnerability

CVE-2026-69498
HIGH 7.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69500
HIGH 7.0

Windows Image Acquisition Elevation of Privilege Vulnerability

CVE-2026-69516
HIGH 7.0

Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability

CVE-2026-69517
HIGH 7.0

Windows Wireless Networking Elevation of Privilege Vulnerability

CVE-2026-69540
HIGH 7.0

Windows Audio Service Elevation of Privilege Vulnerability

CVE-2026-69549
HIGH 7.0

Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

CVE-2026-69560
HIGH 7.0

Windows Work Folder Service Elevation of Privilege Vulnerability

CVE-2026-69563
HIGH 7.0

Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

CVE-2026-69564
HIGH 7.0

Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability

CVE-2026-69611
HIGH 7.0

Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

CVE-2026-69652
HIGH 7.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69654
HIGH 7.0

Windows Accounts Control Elevation of Privilege Vulnerability

CVE-2026-69708
HIGH 7.0

Windows Web Platform Storage Elevation of Privilege Vulnerability

CVE-2026-69711
HIGH 7.0

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-69779
HIGH 7.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-85360
HIGH 7.0

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-62727
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-70307
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-65788
HIGH 7.0

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-65776
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-65678
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-62908
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p…

CVE-2026-62892
HIGH 7.0

Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

CVE-2026-62788
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-62780
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-62773
HIGH 7.0

Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVE-2026-62774
HIGH 7.0

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-62766
HIGH 7.0

Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVE-2026-62748
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-62749
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-62753
HIGH 7.0

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-62729
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-62734
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-62723
HIGH 7.0

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62724
HIGH 7.0

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62725
HIGH 7.0

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62726
HIGH 7.0

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62728
HIGH 7.0

Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-61939
HIGH 7.0

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

CVE-2026-62690
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-61938
HIGH 7.0

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-61927
HIGH 7.0

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-61929
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-61366
HIGH 7.0

Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

CVE-2026-61361
HIGH 7.0

Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.

CVE-2026-61348
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-61346
HIGH 7.0

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-59122
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-59125
HIGH 7.0

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-59126
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to e…

CVE-2026-50472
HIGH 7.0

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

CVE-2026-58629
HIGH 7.0

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-58637
HIGH 7.0

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58619
HIGH 7.0

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58544
HIGH 7.0

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-57093
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-56173
HIGH 7.0

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

CVE-2026-50672
HIGH 7.0

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50674
HIGH 7.0

Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50669
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-50503
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50490
HIGH 7.0

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-50491
HIGH 7.0

Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-50459
HIGH 7.0

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50449
HIGH 7.0

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50452
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50410
HIGH 7.0

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50403
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50392
HIGH 7.0

Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-50393
HIGH 7.0

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-50396
HIGH 7.0

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-50397
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50390
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50371
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privilege…

CVE-2026-50372
HIGH 7.0

Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.

CVE-2026-50359
HIGH 7.0

Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.

CVE-2026-50358
HIGH 7.0

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50345
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50348
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50322
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50307
HIGH 7.0

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

CVE-2026-58526
HIGH 7.0

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-54996
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-54989
HIGH 7.0

Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.

CVE-2026-54129
HIGH 7.0

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-54111
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-50384
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate pr…

CVE-2026-50356
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele…

CVE-2026-50323
HIGH 7.0

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50325
HIGH 7.0

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-50297
HIGH 7.0

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-49806
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-50296
HIGH 7.0

Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49802
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-49803
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to…

CVE-2026-49805
HIGH 7.0

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-49183
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevat…

CVE-2026-49784
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele…

CVE-2026-48571
HIGH 7.0

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-48572
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p…

CVE-2026-49162
HIGH 7.0

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-47648
HIGH 7.0

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-45653
HIGH 7.0

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-45640
HIGH 7.0

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-45598
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-45601
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-45603
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-45596
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-45597
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized atta…

CVE-2026-42984
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-42911
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-42912
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-42836
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized atta…

CVE-2026-41108
HIGH 7.0

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-34335
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2025-54518
HIGH 7.0

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a dif…

CVE-2026-35416
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-34345
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-33839
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2026-34331
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2026-34340
HIGH 7.0

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-34341
HIGH 7.0

Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability

CVE-2026-34342
HIGH 7.0

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2026-34347
HIGH 7.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-40410
HIGH 7.0

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2026-42825
HIGH 7.0

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-33104
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p…

CVE-2026-33100
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-25184
HIGH 7.0

Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability

CVE-2026-26152
HIGH 7.0

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

CVE-2026-26165
HIGH 7.0

Windows Shell Elevation of Privilege Vulnerability

CVE-2026-26166
HIGH 7.0

Windows Shell Elevation of Privilege Vulnerability

CVE-2026-26173
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-26174
HIGH 7.0

Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

CVE-2026-26177
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-26182
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-27908
HIGH 7.0

Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability

CVE-2026-27917
HIGH 7.0

Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability

CVE-2026-27921
HIGH 7.0

Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability

CVE-2026-27922
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-27926
HIGH 7.0

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-27929
HIGH 7.0

Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability

CVE-2026-32068
HIGH 7.0

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2026-32070
HIGH 7.0

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2026-32073
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-32075
HIGH 7.0

Windows UPnP Device Host Elevation of Privilege Vulnerability

CVE-2026-32080
HIGH 7.0

Windows WalletService Elevation of Privilege Vulnerability

CVE-2026-32082
HIGH 7.0

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2026-32083
HIGH 7.0

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2026-32086
HIGH 7.0

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

CVE-2026-32087
HIGH 7.0

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

CVE-2026-32093
HIGH 7.0

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

CVE-2026-32150
HIGH 7.0

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

CVE-2026-32219
HIGH 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2026-24285
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-23671
HIGH 7.0

Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability

CVE-2026-24295
HIGH 7.0

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-24296
HIGH 7.0

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-25170
HIGH 7.0

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2026-25171
HIGH 7.0

Windows Authentication Elevation of Privilege Vulnerability

CVE-2026-25178
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-25179
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21234
HIGH 7.0

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2026-21237
HIGH 7.0

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVE-2026-21241
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21242
HIGH 7.0

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVE-2026-21253
HIGH 7.0

Mailslot File System Elevation of Privilege Vulnerability

CVE-2026-21508
HIGH 7.0

Windows Storage Elevation of Privilege Vulnerability

CVE-2026-21221
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz…

CVE-2026-20869
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacke…

CVE-2026-20863
HIGH 7.0

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20842
HIGH 7.0

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2026-20836
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile…

CVE-2026-20814
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile…

CVE-2026-20815
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz…

CVE-2026-20808
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elev…

CVE-2026-20830
HIGH 7.0

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

CVE-2025-54957
CRITICAL 7.0

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-62469
HIGH 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-62569
HIGH 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-62573
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-59506
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-59507
HIGH 7.0

Windows Speech Runtime Elevation of Privilege Vulnerability

CVE-2025-59508
HIGH 7.0

Windows Speech Recognition Elevation of Privilege Vulnerability

CVE-2025-59515
HIGH 7.0

Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

CVE-2025-60716
CRITICAL 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-60717
HIGH 7.0

Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

CVE-2025-60719
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-62213
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-62217
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-50174
HIGH 7.0

Windows Device Association Broker Service Elevation of Privilege Vulnerability

CVE-2025-55331
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-55340
HIGH 7.0

Windows Remote Desktop Protocol Security Feature Bypass

CVE-2025-55678
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-55681
HIGH 7.0

Desktop Window Manager Elevation of Privilege Vulnerability

CVE-2025-55684
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-55685
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-55686
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-55688
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-55689
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-55690
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-55691
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2025-58725
HIGH 7.0

Windows COM+ Event System Service Elevation of Privilege Vulnerability

CVE-2025-58727
HIGH 7.0

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2025-58730
HIGH 7.0

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-58731
HIGH 7.0

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-58732
HIGH 7.0

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-58733
HIGH 7.0

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-58734
HIGH 7.0

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-58735
HIGH 7.0

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-58736
HIGH 7.0

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-58737
HIGH 7.0

Remote Desktop Protocol Remote Code Execution Vulnerability

CVE-2025-58738
HIGH 7.0

Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-59193
HIGH 7.0

Windows Management Services Elevation of Privilege Vulnerability

CVE-2025-59194
HIGH 7.0

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-59195
HIGH 7.0

Windows Graphics Component Denial of Service Vulnerability

CVE-2025-59196
HIGH 7.0

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2025-59202
HIGH 7.0

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2025-59205
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-59261
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-59282
HIGH 7.0

Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-59289
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-49734
HIGH 7.0

PowerShell Direct Elevation of Privilege Vulnerability

CVE-2025-53802
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-53807
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-54093
HIGH 7.0

Windows TCP/IP Driver Elevation of Privilege Vulnerability

CVE-2025-54099
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-54105
HIGH 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-54108
HIGH 7.0

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

CVE-2025-54112
HIGH 7.0

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-54114
HIGH 7.0

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2025-54115
HIGH 7.0

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-55223
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-59215
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-59216
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-59220
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-49762
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-50158
HIGH 7.0

Windows NTFS Information Disclosure Vulnerability

CVE-2025-50167
HIGH 7.0

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-53134
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-53135
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-53137
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-53140
HIGH 7.0

Windows Kernel Transaction Manager Elevation of Privilege Vulnerability

CVE-2025-53142
HIGH 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-53147
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-53718
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-53721
HIGH 7.0

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2025-47975
HIGH 7.0

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2025-49678
HIGH 7.0

NTFS Elevation of Privilege Vulnerability

CVE-2025-49727
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2025-49744 Exploit
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-27468
HIGH 7.0

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2025-29841
HIGH 7.0

Universal Print Management Service Elevation of Privilege Vulnerability

CVE-2025-21191
HIGH 7.0

Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

CVE-2025-26640
HIGH 7.0

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-26649
HIGH 7.0

Windows Secure Channel Elevation of Privilege Vulnerability

CVE-2025-26665
HIGH 7.0

Windows upnphost.dll Elevation of Privilege Vulnerability

CVE-2025-27478
HIGH 7.0

Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

CVE-2025-27492
HIGH 7.0

Windows Secure Channel Elevation of Privilege Vulnerability

CVE-2025-27732
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-21184
HIGH 7.0

Windows Core Messaging Elevation of Privileges Vulnerability

CVE-2025-21414
HIGH 7.0

Windows Core Messaging Elevation of Privileges Vulnerability

CVE-2024-49084
HIGH 7.0

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-49095
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2024-49097
HIGH 7.0

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

CVE-2020-17103
HIGH 7.0

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-78451
MEDIUM 6.8

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-77892
MEDIUM 6.8

No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-72999
MEDIUM 6.8

Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-72985
MEDIUM 6.8

Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-71350
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71348
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71349
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71329
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-69566
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-69490
MEDIUM 6.8

Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-69415
MEDIUM 6.8

Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-68833
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-62702
MEDIUM 6.8

Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

CVE-2026-62699
MEDIUM 6.8

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-58528
MEDIUM 6.8

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-50668
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-50492
MEDIUM 6.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-50426
MEDIUM 6.8

Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.

CVE-2026-50298
MEDIUM 6.8

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-50299
MEDIUM 6.8

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-49168
MEDIUM 6.8

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-50507
MEDIUM 6.8

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-45608
MEDIUM 6.8

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

CVE-2026-45585
MEDIUM 6.8

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerabi…

CVE-2026-32223
MEDIUM 6.8

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2025-49751
HIGH 6.8

Windows Hyper-V Denial of Service Vulnerability

CVE-2025-47999
HIGH 6.8

Windows Hyper-V Denial of Service Vulnerability

CVE-2025-48001
HIGH 6.8

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-48003
HIGH 6.8

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-48800
HIGH 6.8

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-48804
HIGH 6.8

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-48818
HIGH 6.8

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-26637
HIGH 6.8

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-21349
HIGH 6.8

Windows Remote Desktop Configuration Service Tampering Vulnerability

CVE-2025-21211
HIGH 6.8

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-49073
HIGH 6.8

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2024-49077
HIGH 6.8

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2024-49078
HIGH 6.8

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2024-49082
HIGH 6.8

Windows File Explorer Information Disclosure Vulnerability

CVE-2024-49083
HIGH 6.8

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2024-49092
HIGH 6.8

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2024-49110
HIGH 6.8

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2024-43449
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43634
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43637
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43638
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43643
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2026-72948
MEDIUM 6.7

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-72935
MEDIUM 6.7

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-71339
MEDIUM 6.7

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-69350
HIGH 6.7

Windows Overlay Filter Elevation of Privilege Vulnerability

CVE-2026-69373
HIGH 6.7

Windows Overlay Filter Elevation of Privilege Vulnerability

CVE-2026-69449
HIGH 6.7

Windows BitLocker Remote Code Execution Vulnerability

CVE-2026-72927
HIGH 6.7

Winsock Elevation of Privilege Vulnerability

CVE-2026-70330
MEDIUM 6.7

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-70304
MEDIUM 6.7

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-65799
MEDIUM 6.7

Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-65795
MEDIUM 6.7

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-65797
MEDIUM 6.7

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-65798
MEDIUM 6.7

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-62881
MEDIUM 6.7

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-62883
MEDIUM 6.7

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-62769
MEDIUM 6.7

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-32170
MEDIUM 6.7

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

CVE-2026-21530
HIGH 6.7

Windows Rich Text Edit Elevation of Privilege Vulnerability

CVE-2026-41097
HIGH 6.7

Secure Boot Security Feature Bypass Vulnerability

CVE-2026-20876
MEDIUM 6.7

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2025-53808
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-53810
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-54094
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-54104
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-54109
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-54915
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-55226
CRITICAL 6.7

Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-48807
CRITICAL 6.7

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-49743
HIGH 6.7

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-48803
HIGH 6.7

Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability

CVE-2025-48811
HIGH 6.7

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

CVE-2025-3052
HIGH 6.7

Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass

CVE-2025-26681
HIGH 6.7

Win32k Elevation of Privilege Vulnerability

CVE-2024-7344
HIGH 6.7

Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot Bypass

CVE-2024-43631
HIGH 6.7

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVE-2024-43646
HIGH 6.7

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVE-2023-24932
HIGH 6.7

Secure Boot Security Feature Bypass Vulnerability

CVE-2026-69469
MEDIUM 6.6

Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-61920
MEDIUM 6.6

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a…

CVE-2026-49804
MEDIUM 6.6

Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2025-2884
MEDIUM 6.6

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with…

CVE-2025-24987
HIGH 6.6

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2025-24988
HIGH 6.6

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2025-21226
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21227
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21228
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21229
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21232
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21249
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21255
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21256
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21258
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21260
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21261
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21263
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21265
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21310
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21324
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21327
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-21341
HIGH 6.6

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2024-49081
HIGH 6.6

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

CVE-2024-49094
HIGH 6.6

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

CVE-2024-49101
HIGH 6.6

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

CVE-2024-49109
HIGH 6.6

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

CVE-2024-49111
HIGH 6.6

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

CVE-2026-78453
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

CVE-2026-72942
MEDIUM 6.5

Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.

CVE-2026-72939
MEDIUM 6.5

Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.

CVE-2026-70019
MEDIUM 6.5

Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.

CVE-2026-69839
MEDIUM 6.5

Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.

CVE-2026-69781
MEDIUM 6.5

Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.

CVE-2026-69624
MEDIUM 6.5

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

CVE-2026-69374
MEDIUM 6.5

Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.

CVE-2026-68898
MEDIUM 6.5

Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network.

CVE-2026-69267
MEDIUM 6.5

Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.

CVE-2026-62801
MEDIUM 6.5

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security featu…

CVE-2026-62762
HIGH 6.5

Windows Active Directory Domain Services Denial of Service Vulnerability

CVE-2026-69297
HIGH 6.5

Windows DHCP Server Information Disclosure Vulnerability

CVE-2026-69395
HIGH 6.5

Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability

CVE-2026-69497
HIGH 6.5

Windows DHCP Server Denial of Service Vulnerability

CVE-2026-77896
HIGH 6.5

Windows Remote Desktop Client Denial of Service Vulnerability

CVE-2026-65794
MEDIUM 6.5

Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-65785
MEDIUM 6.5

Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.

CVE-2026-62814
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVE-2026-62782
MEDIUM 6.5

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-62750
MEDIUM 6.5

Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.

CVE-2026-62742
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVE-2026-62745
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVE-2026-62718
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVE-2026-62720
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVE-2026-62714
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVE-2026-62715
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVE-2026-62716
MEDIUM 6.5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVE-2026-61921
MEDIUM 6.5

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-61924
MEDIUM 6.5

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-61918
MEDIUM 6.5

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-59138
MEDIUM 6.5

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

CVE-2026-61345
MEDIUM 6.5

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

CVE-2026-58546
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58539
MEDIUM 6.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58533
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58535
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-57982
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

CVE-2026-56168
MEDIUM 6.5

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVE-2026-54126
MEDIUM 6.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50504
MEDIUM 6.5

Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

CVE-2026-50497
MEDIUM 6.5

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

CVE-2026-50445
MEDIUM 6.5

Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50376
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50366
MEDIUM 6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVE-2026-57976
MEDIUM 6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVE-2026-57979
MEDIUM 6.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-55003
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-49799
MEDIUM 6.5

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

CVE-2026-34348
MEDIUM 6.5

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

CVE-2026-42907
MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

CVE-2026-42903
MEDIUM 6.5

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2026-34350
HIGH 6.5

Windows Storport Miniport Driver Denial of Service Vulnerability

CVE-2026-35422
HIGH 6.5

Windows TCP/IP Driver Security Feature Bypass Vulnerability

CVE-2026-26155
HIGH 6.5

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

CVE-2026-27925
HIGH 6.5

Windows UPnP Device Host Information Disclosure Vulnerability

CVE-2026-32151
HIGH 6.5

Windows Shell Information Disclosure Vulnerability

CVE-2026-20925
MEDIUM 6.5

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-20872
MEDIUM 6.5

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-20847
MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

CVE-2026-20812
MEDIUM 6.5

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

CVE-2025-62463
HIGH 6.5

DirectX Graphics Kernel Denial of Service Vulnerability

CVE-2025-62465
HIGH 6.5

DirectX Graphics Kernel Denial of Service Vulnerability

CVE-2025-62473
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-64670
HIGH 6.5

Windows DirectX Information Disclosure Vulnerability

CVE-2025-60708
HIGH 6.5

Storvsp.sys Driver Denial of Service Vulnerability

CVE-2025-55700
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-58717
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-58729
HIGH 6.5

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVE-2025-58739
HIGH 6.5

Microsoft Windows File Explorer Spoofing Vulnerability

CVE-2025-59185
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-59214
HIGH 6.5

Microsoft Windows File Explorer Spoofing Vulnerability

CVE-2025-59244
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-59257
HIGH 6.5

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVE-2025-59259
HIGH 6.5

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVE-2025-53796
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-53797
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-53798
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-53806
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-53809
HIGH 6.5

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

CVE-2025-54095
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-54096
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-54097
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-55225
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-50154 Exploit
HIGH 6.5

Microsoft Windows File Explorer Spoofing Vulnerability

CVE-2025-50166
HIGH 6.5

Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure Vulnerability

CVE-2025-50172
HIGH 6.5

DirectX Graphics Kernel Denial of Service Vulnerability

CVE-2025-53716
HIGH 6.5

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

CVE-2025-47978
HIGH 6.5

Windows Kerberos Denial of Service Vulnerability

CVE-2025-49670
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49671
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-49681
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-32715
HIGH 6.5

Remote Desktop Protocol Client Information Disclosure Vulnerability

CVE-2025-33057
HIGH 6.5

Windows Local Security Authority (LSA) Denial of Service Vulnerability

CVE-2025-29830
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29832
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29835
HIGH 6.5

Windows Remote Access Connection Manager Information Disclosure Vulnerability

CVE-2025-29836
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29958
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29959
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29960
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29961
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-21197
HIGH 6.5

Windows NTFS Information Disclosure Vulnerability

CVE-2025-21203
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-26651
HIGH 6.5

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVE-2025-26664
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-26667
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-26672
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-26676
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-27474
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-27738
HIGH 6.5

Windows Resilient File System (ReFS) Information Disclosure Vulnerability

CVE-2025-24071 Exploit
HIGH 6.5

Microsoft Windows File Explorer Spoofing Vulnerability

CVE-2025-24996
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-21212
HIGH 6.5

Internet Connection Sharing (ICS) Denial of Service Vulnerability

CVE-2025-21216
HIGH 6.5

Internet Connection Sharing (ICS) Denial of Service Vulnerability

CVE-2025-21254
HIGH 6.5

Internet Connection Sharing (ICS) Denial of Service Vulnerability

CVE-2025-21352
HIGH 6.5

Internet Connection Sharing (ICS) Denial of Service Vulnerability

CVE-2025-21377
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-21193
HIGH 6.5

Active Directory Federation Server Spoofing Vulnerability

CVE-2025-21217
HIGH 6.5

Windows NTLM Spoofing Vulnerability

CVE-2025-21272
HIGH 6.5

Windows COM Server Information Disclosure Vulnerability

CVE-2025-21288
HIGH 6.5

Windows COM Server Information Disclosure Vulnerability

CVE-2025-21301
HIGH 6.5

Windows Geolocation Service Information Disclosure Vulnerability

CVE-2025-21308
HIGH 6.5

Windows Themes Spoofing Vulnerability

CVE-2025-21313
HIGH 6.5

Windows Security Account Manager (SAM) Denial of Service Vulnerability

CVE-2025-21314
HIGH 6.5

Windows SmartScreen Spoofing Vulnerability

CVE-2026-77887
MEDIUM 6.4

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

CVE-2026-77891
MEDIUM 6.4

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

CVE-2026-71338
MEDIUM 6.4

Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

CVE-2026-69878
MEDIUM 6.4

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally.

CVE-2026-70582
HIGH 6.4

Windows Management Instrumentation Elevation of Privilege Vulnerability

CVE-2026-62708
MEDIUM 6.4

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-57097
MEDIUM 6.4

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-55000
MEDIUM 6.4

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-21265
MEDIUM 6.4

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affect…

CVE-2026-58543
MEDIUM 6.3

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-50374
MEDIUM 6.3

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.

CVE-2026-50375
MEDIUM 6.3

Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2025-60723
HIGH 6.3

DirectX Graphics Kernel Denial of Service Vulnerability

CVE-2025-48813
HIGH 6.3

Virtual Secure Mode Spoofing Vulnerability

CVE-2026-57095
MEDIUM 6.2

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50420
MEDIUM 6.2

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.

CVE-2026-49807
MEDIUM 6.2

Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.

CVE-2026-50294
MEDIUM 6.2

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.

CVE-2026-40380
HIGH 6.2

Windows Volume Manager Extension Driver Remote Code Execution Vulnerability

CVE-2026-32072
HIGH 6.2

Active Directory Spoofing Vulnerability

CVE-2026-25168
HIGH 6.2

Windows Graphics Component Denial of Service Vulnerability

CVE-2026-25169
HIGH 6.2

Windows Graphics Component Denial of Service Vulnerability

CVE-2026-20851
MEDIUM 6.2

Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.

CVE-2026-20821
MEDIUM 6.2

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

CVE-2026-20818
HIGH 6.2

Windows Kernel Information Disclosure Vulnerability

CVE-2025-59258
HIGH 6.2

Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability

CVE-2025-47980
CRITICAL 6.2

Windows Imaging Component Information Disclosure Vulnerability

CVE-2025-29955
HIGH 6.2

Windows Hyper-V Denial of Service Vulnerability

CVE-2025-29957
HIGH 6.2

Windows Deployment Services Denial of Service Vulnerability

CVE-2025-21278
HIGH 6.2

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2024-38203
HIGH 6.2

Windows Package Library Manager Information Disclosure Vulnerability

CVE-2026-50661
MEDIUM 6.1

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-50495
MEDIUM 6.1

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVE-2026-50453
MEDIUM 6.1

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-50383
MEDIUM 6.1

Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

CVE-2026-49174
MEDIUM 6.1

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVE-2026-26169
HIGH 6.1

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2026-32088
HIGH 6.1

Windows Biometric Service Security Feature Bypass Vulnerability

CVE-2025-55330
HIGH 6.1

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-55332
HIGH 6.1

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-55333
HIGH 6.1

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-55337
HIGH 6.1

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-55338
HIGH 6.1

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-55682
HIGH 6.1

Windows BitLocker Security Feature Bypass Vulnerability

CVE-2025-21202
HIGH 6.1

Windows Recovery Environment Agent Elevation of Privilege Vulnerability

CVE-2026-25250
MEDIUM 6.0

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

CVE-2026-58638
MEDIUM 6.0

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

CVE-2025-27735
HIGH 6.0

Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability

CVE-2025-21347
HIGH 6.0

Windows Deployment Services Denial of Service Vulnerability

CVE-2026-78523
MEDIUM 5.9

Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.

CVE-2026-72978
MEDIUM 5.9

Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a net…

CVE-2026-70091
MEDIUM 5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over…

CVE-2026-70124
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-69929
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-69930
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-69803
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-68819
MEDIUM 5.9

Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.

CVE-2026-6727
MEDIUM 5.9

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may …

CVE-2026-56649
MEDIUM 5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to e…

CVE-2026-50324
MEDIUM 5.9

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n…

CVE-2025-48823
HIGH 5.9

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2025-30394
HIGH 5.9

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2025-27471
HIGH 5.9

Microsoft Streaming Service Denial of Service Vulnerability

CVE-2025-21350
HIGH 5.9

Windows Kerberos Denial of Service Vulnerability

CVE-2025-21225
HIGH 5.9

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2025-21242
HIGH 5.9

Windows Kerberos Information Disclosure Vulnerability

CVE-2024-38264
HIGH 5.9

Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability

CVE-2026-69723
MEDIUM 5.7

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a netwo…

CVE-2026-69591
MEDIUM 5.7

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.

CVE-2026-69569
MEDIUM 5.7

Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.

CVE-2026-69572
MEDIUM 5.7

Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network.

CVE-2026-69552
MEDIUM 5.7

Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a n…

CVE-2026-69507
MEDIUM 5.7

Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose…

CVE-2026-69416
MEDIUM 5.7

Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

CVE-2026-69393
MEDIUM 5.7

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network.

CVE-2026-69372
MEDIUM 5.7

Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network.

CVE-2026-69349
MEDIUM 5.7

Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.

CVE-2026-68874
MEDIUM 5.7

Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network.

CVE-2026-69317
HIGH 5.7

Windows Remote Desktop Client Information Disclosure Vulnerability

CVE-2026-69405
HIGH 5.7

Windows DHCP Server Denial of Service Vulnerability

CVE-2026-69637
HIGH 5.7

Windows DHCP Server Denial of Service Vulnerability

CVE-2026-69679
HIGH 5.7

Windows DHCP Server Denial of Service Vulnerability

CVE-2026-23670
HIGH 5.7

Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability

CVE-2025-50156
HIGH 5.7

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-50157
HIGH 5.7

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-53138
HIGH 5.7

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-53148
HIGH 5.7

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-53153
HIGH 5.7

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-53719
HIGH 5.7

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-48002
HIGH 5.7

Windows Hyper-V Information Disclosure Vulnerability

CVE-2025-49722
HIGH 5.7

Windows Print Spooler Denial of Service Vulnerability

CVE-2025-29974
HIGH 5.7

Windows Kernel Information Disclosure Vulnerability

CVE-2026-69832
MEDIUM 5.6

Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-59130
MEDIUM 5.6

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

CVE-2026-59131
MEDIUM 5.6

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

CVE-2024-36350
CRITICAL 5.6

AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue

CVE-2024-36357
CRITICAL 5.6

AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue

CVE-2025-21336
HIGH 5.6

Windows Cryptographic Information Disclosure Vulnerability

CVE-2026-83501
MEDIUM 5.5

Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

CVE-2026-77491
MEDIUM 5.5

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

CVE-2026-73004
MEDIUM 5.5

Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.

CVE-2026-73008
MEDIUM 5.5

Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.

CVE-2026-72964
MEDIUM 5.5

Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.

CVE-2026-72966
MEDIUM 5.5

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

CVE-2026-71341
MEDIUM 5.5

Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.

CVE-2026-70290
MEDIUM 5.5

Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-70145
MEDIUM 5.5

Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

CVE-2026-69808
MEDIUM 5.5

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-69770
MEDIUM 5.5

Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

CVE-2026-69741
MEDIUM 5.5

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

CVE-2026-69684
MEDIUM 5.5

Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.

CVE-2026-69672
MEDIUM 5.5

Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.

CVE-2026-69674
MEDIUM 5.5

Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally.

CVE-2026-69627
MEDIUM 5.5

Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.

CVE-2026-69616
MEDIUM 5.5

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.

CVE-2026-69618
MEDIUM 5.5

Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.

CVE-2026-69609
MEDIUM 5.5

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-69568
MEDIUM 5.5

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.

CVE-2026-69554
MEDIUM 5.5

Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.

CVE-2026-69527
MEDIUM 5.5

Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally.

CVE-2026-69504
MEDIUM 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-69457
MEDIUM 5.5

Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.

CVE-2026-69406
MEDIUM 5.5

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-69403
MEDIUM 5.5

Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.

CVE-2026-69390
MEDIUM 5.5

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

CVE-2026-69369
MEDIUM 5.5

Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally.

CVE-2026-69351
MEDIUM 5.5

Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclo…

CVE-2026-69353
MEDIUM 5.5

Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally.

CVE-2026-69344
MEDIUM 5.5

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

CVE-2026-69343
MEDIUM 5.5

Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

CVE-2026-69318
MEDIUM 5.5

Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.

CVE-2026-69315
MEDIUM 5.5

Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information loc…

CVE-2026-69294
MEDIUM 5.5

Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

CVE-2026-69286
MEDIUM 5.5

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.

CVE-2026-69288
MEDIUM 5.5

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

CVE-2026-68886
MEDIUM 5.5

Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.

CVE-2026-68873
MEDIUM 5.5

Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information local…

CVE-2026-68851
MEDIUM 5.5

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-68831
MEDIUM 5.5

Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

CVE-2026-68830
MEDIUM 5.5

Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose …

CVE-2026-68843
HIGH 5.5

Microsoft Office Word Information Disclosure Vulnerability

CVE-2026-68852
HIGH 5.5

Microsoft Account Information Disclosure Vulnerability

CVE-2026-68881
HIGH 5.5

Microsoft Standard XPS Information Disclosure Vulnerability

CVE-2026-68895
HIGH 5.5

Internet Storage Name Service Information Disclosure Vulnerability

CVE-2026-69303
HIGH 5.5

Push Message Routing Service Information Disclosure Vulnerability

CVE-2026-69308
HIGH 5.5

Microsoft Standard XPS Information Disclosure Vulnerability

CVE-2026-69321
HIGH 5.5

Windows Power Dependency Coordinator Tampering Vulnerability

CVE-2026-69345
HIGH 5.5

Microsoft Standard XPS Information Disclosure Vulnerability

CVE-2026-69367
HIGH 5.5

Microsoft Standard XPS Information Disclosure Vulnerability

CVE-2026-69376
HIGH 5.5

Microsoft Standard XPS Information Disclosure Vulnerability

CVE-2026-69453
HIGH 5.5

Microsoft Windows Search Component Tampering Vulnerability

CVE-2026-69531
HIGH 5.5

Microsoft Windows Speech Tampering Vulnerability

CVE-2026-69794
HIGH 5.5

Windows Encrypting File System (EFS) Information Disclosure Vulnerability

CVE-2026-72937
HIGH 5.5

Windows Storage Port Driver Information Disclosure Vulnerability

CVE-2026-77492
HIGH 5.5

Windows Storage Port Driver Information Disclosure Vulnerability

CVE-2026-83991
HIGH 5.5

Windows Cloud Files Mini Filter Driver Tampering Vulnerability

CVE-2026-65784
MEDIUM 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-65662
MEDIUM 5.5

Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.

CVE-2026-62887
MEDIUM 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-62798
MEDIUM 5.5

Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-62793
MEDIUM 5.5

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-62796
MEDIUM 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-62786
MEDIUM 5.5

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-62743
MEDIUM 5.5

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-62746
MEDIUM 5.5

Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-62738
MEDIUM 5.5

Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.

CVE-2026-62740
MEDIUM 5.5

Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.

CVE-2026-62730
MEDIUM 5.5

Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

CVE-2026-62703
MEDIUM 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-62709
MEDIUM 5.5

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

CVE-2026-61936
MEDIUM 5.5

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

CVE-2026-61933
MEDIUM 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-61928
MEDIUM 5.5

Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

CVE-2026-61360
MEDIUM 5.5

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.

CVE-2026-61347
MEDIUM 5.5

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.

CVE-2026-59136
MEDIUM 5.5

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

CVE-2026-59137
MEDIUM 5.5

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.

CVE-2026-59135
MEDIUM 5.5

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

CVE-2026-59128
MEDIUM 5.5

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.

CVE-2026-58545
MEDIUM 5.5

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-58547
MEDIUM 5.5

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-57083
MEDIUM 5.5

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

CVE-2026-57084
MEDIUM 5.5

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

CVE-2026-57085
MEDIUM 5.5

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

CVE-2026-56184
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-50690
MEDIUM 5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

CVE-2026-50681
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVE-2026-50483
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.

CVE-2026-50475
MEDIUM 5.5

Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50473
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-50455
MEDIUM 5.5

Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

CVE-2026-50456
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-50442
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-50434
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50437
MEDIUM 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-50430
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50431
MEDIUM 5.5

Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

CVE-2026-50409
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.

CVE-2026-50401
MEDIUM 5.5

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.

CVE-2026-50394
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVE-2026-50389
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-50377
MEDIUM 5.5

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50352
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVE-2026-50339
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-50341
MEDIUM 5.5

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-50334
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.

CVE-2026-49177
MEDIUM 5.5

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

CVE-2026-58614
MEDIUM 5.5

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-54997
MEDIUM 5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

CVE-2026-50381
MEDIUM 5.5

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information local…

CVE-2026-50350
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information lo…

CVE-2026-50316
MEDIUM 5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50300
MEDIUM 5.5

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50303
MEDIUM 5.5

Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.

CVE-2026-50295
MEDIUM 5.5

Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.

CVE-2026-49801
MEDIUM 5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

CVE-2026-49180
MEDIUM 5.5

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca…

CVE-2026-40422
MEDIUM 5.5

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-41087
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-33842
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-34328
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

CVE-2026-34346
MEDIUM 5.5

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

CVE-2026-34349
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVE-2026-48566
MEDIUM 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-45604
MEDIUM 5.5

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-45606
MEDIUM 5.5

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

CVE-2026-45634
MEDIUM 5.5

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

CVE-2026-45594
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat…

CVE-2026-44805
MEDIUM 5.5

Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.

CVE-2026-42973
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42968
MEDIUM 5.5

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

CVE-2026-42969
MEDIUM 5.5

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42970
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42971
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42972
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-42915
MEDIUM 5.5

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

CVE-2026-42906
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

CVE-2026-34339
HIGH 5.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2026-35419
HIGH 5.5

Windows DWM Core Library Information Disclosure Vulnerability

CVE-2026-20806
HIGH 5.5

Windows COM Server Information Disclosure Vulnerability

CVE-2026-27930
HIGH 5.5

Windows GDI Information Disclosure Vulnerability

CVE-2026-27931
HIGH 5.5

Windows GDI Information Disclosure Vulnerability

CVE-2026-32079
HIGH 5.5

Web Account Manager Information Disclosure Vulnerability

CVE-2026-32081
HIGH 5.5

Package Catalog Information Disclosure Vulnerability

CVE-2026-32084
HIGH 5.5

Windows Print Spooler Information Disclosure Vulnerability

CVE-2026-32085
HIGH 5.5

Remote Procedure Call Information Disclosure Vulnerability

CVE-2026-32181
HIGH 5.5

Connected User Experiences and Telemetry Service Denial of Service Vulnerability

CVE-2026-32212
HIGH 5.5

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

CVE-2026-32214
HIGH 5.5

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

CVE-2026-32215
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2026-32217
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2026-32218
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2026-25180
HIGH 5.5

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

CVE-2026-25186
HIGH 5.5

Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability

CVE-2026-21222
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2026-20939
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20932
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20937
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20862
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

CVE-2026-20838
MEDIUM 5.5

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-20839
MEDIUM 5.5

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

CVE-2026-20835
MEDIUM 5.5

Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

CVE-2026-20827
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose inform…

CVE-2026-20829
MEDIUM 5.5

Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

CVE-2026-20823
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20824
MEDIUM 5.5

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-20833
HIGH 5.5

Windows Kerberos Information Disclosure Vulnerability

CVE-2025-62468
HIGH 5.5

Windows Defender Firewall Service Information Disclosure Vulnerability

CVE-2025-59509
HIGH 5.5

Windows Speech Recognition Information Disclosure Vulnerability

CVE-2025-59510
HIGH 5.5

Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability

CVE-2025-59513
HIGH 5.5

Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability

CVE-2025-60706
HIGH 5.5

Windows Hyper-V Information Disclosure Vulnerability

CVE-2025-62208
HIGH 5.5

Windows License Manager Information Disclosure Vulnerability

CVE-2025-62209
HIGH 5.5

Windows License Manager Information Disclosure Vulnerability

CVE-2025-47979
HIGH 5.5

Microsoft Failover Cluster Information Disclosure Vulnerability

CVE-2025-55325
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-55336
HIGH 5.5

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVE-2025-55676
HIGH 5.5

Windows USB Video Class System Driver Information Disclosure Vulnerability

CVE-2025-55683
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2025-55695
HIGH 5.5

Windows WLAN AutoConfig Service Information Disclosure Vulnerability

CVE-2025-55699
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2025-59184
HIGH 5.5

Storage Spaces Direct Information Disclosure Vulnerability

CVE-2025-59186
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2025-59188
HIGH 5.5

Microsoft Failover Cluster Information Disclosure Vulnerability

CVE-2025-59190
HIGH 5.5

Windows Search Service Denial of Service Vulnerability

CVE-2025-59197
HIGH 5.5

Windows ETL Channel Information Disclosure Vulnerability

CVE-2025-59203
HIGH 5.5

Windows State Repository API Server File Information Disclosure Vulnerability

CVE-2025-59204
HIGH 5.5

Windows Management Services Information Disclosure Vulnerability

CVE-2025-59209
HIGH 5.5

Windows Push Notification Information Disclosure Vulnerability

CVE-2025-59211
HIGH 5.5

Windows Push Notification Information Disclosure Vulnerability

CVE-2025-59253
HIGH 5.5

Windows Search Service Denial of Service Vulnerability

CVE-2025-59260
HIGH 5.5

Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability

CVE-2025-53799
CRITICAL 5.5

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

CVE-2025-53803
HIGH 5.5

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2025-53804
HIGH 5.5

Windows Kernel-Mode Driver Information Disclosure Vulnerability

CVE-2025-53136
HIGH 5.5

NT OS Kernel Information Disclosure Vulnerability

CVE-2025-53156
HIGH 5.5

Windows Storage Port Driver Information Disclosure Vulnerability

CVE-2025-26636
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2025-48808
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2025-48809
HIGH 5.5

Windows Secure Kernel Mode Information Disclosure Vulnerability

CVE-2025-48810
HIGH 5.5

Windows Secure Kernel Mode Information Disclosure Vulnerability

CVE-2025-49658
HIGH 5.5

Windows Transport Driver Interface (TDI) Translation Driver Information Disclosure Vulnerability

CVE-2025-49664
HIGH 5.5

Windows User-Mode Driver Framework Host Information Disclosure Vulnerability

CVE-2025-49684
HIGH 5.5

Windows Storage Port Driver Information Disclosure Vulnerability

CVE-2025-24065
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-24068
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-24069
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-32719
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-32720
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-32722
HIGH 5.5

Windows Storage Port Driver Information Disclosure Vulnerability

CVE-2025-33052
HIGH 5.5

Windows DWM Core Library Information Disclosure Vulnerability

CVE-2025-33055
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33058
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33059
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33060
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33061
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33062
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33063
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33065
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-29829
HIGH 5.5

Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability

CVE-2025-29837
HIGH 5.5

Windows Installer Information Disclosure Vulnerability

CVE-2025-27736
HIGH 5.5

Windows Power Dependency Coordinator Information Disclosure Vulnerability

CVE-2025-27742
HIGH 5.5

NTFS Information Disclosure Vulnerability

CVE-2025-24992
HIGH 5.5

Windows NTFS Information Disclosure Vulnerability

CVE-2025-21257
HIGH 5.5

Windows WLAN AutoConfig Service Information Disclosure Vulnerability

CVE-2025-21274
HIGH 5.5

Windows Event Tracing Denial of Service Vulnerability

CVE-2025-21280
HIGH 5.5

Windows Virtual Trusted Platform Module Denial of Service Vulnerability

CVE-2025-21284
HIGH 5.5

Windows Virtual Trusted Platform Module Denial of Service Vulnerability

CVE-2025-21316
HIGH 5.5

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2025-21317
HIGH 5.5

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2025-21318
HIGH 5.5

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2025-21319
HIGH 5.5

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2025-21320
HIGH 5.5

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2025-21321
HIGH 5.5

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2025-21323
HIGH 5.5

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2025-21340
HIGH 5.5

Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability

CVE-2025-21374
HIGH 5.5

Windows CSC Service Information Disclosure Vulnerability

CVE-2021-45985
HIGH 5.5

Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-read

CVE-2020-35538
HIGH 5.5

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2026-45595
MEDIUM 5.4

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-35423
HIGH 5.4

Windows 11 Telnet Client Information Disclosure Vulnerability

CVE-2025-47160
HIGH 5.4

Windows Shortcut Files Security Feature Bypass Vulnerability

CVE-2025-29956
HIGH 5.4

Windows SMB Information Disclosure Vulnerability

CVE-2026-78446
MEDIUM 5.3

Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.

CVE-2026-70575
HIGH 5.3

Windows Schannel Denial of Service Vulnerability

CVE-2026-65777
MEDIUM 5.3

Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

CVE-2026-62757
MEDIUM 5.3

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-50432
MEDIUM 5.3

Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.

CVE-2026-50415
MEDIUM 5.3

Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.

CVE-2026-44806
MEDIUM 5.3

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

CVE-2026-45655
MEDIUM 5.3

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-42914
MEDIUM 5.3

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2023-20585
HIGH 5.3

AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability

CVE-2026-25185
HIGH 5.3

Windows Shell Link Processing Spoofing Vulnerability

CVE-2026-20927
MEDIUM 5.3

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service…

CVE-2025-62567
HIGH 5.3

Windows Hyper-V Denial of Service Vulnerability

CVE-2025-55229
HIGH 5.3

Windows Certificate Spoofing Vulnerability

CVE-2026-50418
MEDIUM 5.1

Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-55679
HIGH 5.1

Windows Kernel Information Disclosure Vulnerability

CVE-2025-33069
HIGH 5.1

Windows App Control for Business Security Feature Bypass Vulnerability

CVE-2025-26644
HIGH 5.1

Windows Hello Spoofing Vulnerability

CVE-2026-61368
MEDIUM 5.0

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2025-59198
HIGH 5.0

Windows Search Service Denial of Service Vulnerability

CVE-2026-69474
MEDIUM 4.8

Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.

CVE-2026-50684
MEDIUM 4.8

Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attac…

CVE-2025-21179
HIGH 4.8

DHCP Client Service Denial of Service Vulnerability

CVE-2026-72931
MEDIUM 4.7

Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.

CVE-2026-69895
MEDIUM 4.7

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

CVE-2026-69853
MEDIUM 4.7

Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-69483
MEDIUM 4.7

Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally.

CVE-2026-69316
MEDIUM 4.7

Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

CVE-2026-68849
MEDIUM 4.7

Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally.

CVE-2026-68891
HIGH 4.7

Microsoft Standard XPS Information Disclosure Vulnerability

CVE-2026-69792
HIGH 4.7

Windows Win32K Security Feature Bypass Vulnerability

CVE-2026-50310
MEDIUM 4.7

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.

CVE-2026-50312
MEDIUM 4.7

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-49167
MEDIUM 4.7

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2025-58719
HIGH 4.7

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2026-78508
MEDIUM 4.6

Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-78452
MEDIUM 4.6

Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-69548
MEDIUM 4.6

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-69381
MEDIUM 4.6

Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-61350
MEDIUM 4.6

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-49794
MEDIUM 4.6

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-20928
HIGH 4.6

Windows Recovery Environment Security Feature Bypass Vulnerability

CVE-2026-26175
HIGH 4.6

Windows Boot Manager Security Feature Bypass Vulnerability

CVE-2026-20834
MEDIUM 4.6

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

CVE-2026-20828
MEDIUM 4.6

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2025-21213
HIGH 4.6

Secure Boot Security Feature Bypass Vulnerability

CVE-2025-21215
HIGH 4.6

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-49087
HIGH 4.6

Windows Mobile Broadband Driver Information Disclosure Vulnerability

CVE-2026-50485
MEDIUM 4.5

Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

CVE-2026-72980
MEDIUM 4.4

Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.

CVE-2026-69713
HIGH 4.4

Windows Secure Boot Security Feature Bypass Vulnerability

CVE-2026-32209
HIGH 4.4

Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability

CVE-2026-32220
MEDIUM 4.4

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

CVE-2026-20962
MEDIUM 4.4

Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.

CVE-2026-20825
MEDIUM 4.4

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2025-47969
HIGH 4.4

Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability

CVE-2025-24997
HIGH 4.4

DirectX Graphics Kernel File Denial of Service Vulnerability

CVE-2026-78516
MEDIUM 4.3

Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-73019
MEDIUM 4.3

Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-33829 Exploit
MEDIUM 4.3

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-20936
MEDIUM 4.3

Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.

CVE-2025-54107
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-54917
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-21247
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-24055
HIGH 4.3

Windows USB Video Class System Driver Information Disclosure Vulnerability

CVE-2025-21189
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-21219
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-21268
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-21269
HIGH 4.3

Windows HTML Platforms Security Feature Bypass Vulnerability

CVE-2025-21328
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-21329
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-21332
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2024-49098
HIGH 4.3

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

CVE-2024-49099
HIGH 4.3

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

CVE-2024-49103
HIGH 4.3

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

CVE-2026-50302
MEDIUM 4.2

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

CVE-2025-21210
HIGH 4.2

Windows BitLocker Information Disclosure Vulnerability

CVE-2025-21214
HIGH 4.2

Windows BitLocker Information Disclosure Vulnerability

CVE-2025-29839
HIGH 4.0

Windows Multiple UNC Provider Driver Information Disclosure Vulnerability

CVE-2026-45642
LOW 3.9

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a…

CVE-2025-49760
MEDIUM 3.5

Windows Storage Spoofing Vulnerability

CVE-2026-50419
LOW 3.3

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50416
LOW 3.3

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-21249
HIGH 3.3

Windows NTLM Spoofing Vulnerability

CVE-2025-59284
HIGH 3.3

Windows NTLM Spoofing Vulnerability

CVE-2025-21337
HIGH 3.3

Windows NTFS Elevation of Privilege Vulnerability

CVE-2025-59280
HIGH 3.1

Windows SMB Client Tampering Vulnerability

CVE-2025-59294
HIGH 2.1

Windows Taskbar Live Preview Information Disclosure Vulnerability

CVE-2024-9157
HIGH

Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability

Déployer ce correctif Windows sur votre flotte

Appaloosa pousse les mises à jour Windows et vérifie leur application sur tout votre parc.

Gérer Windows avec Appaloosa