Windows
Windows Windows Server 2025
Advisory officiel1724 CVE corrigées par cette release.
- Date de sortie
- 2020-12-08
- Fin de support
- —
- CVE corrigées
- 1724
- KEV CISA
- 38
- Critique
- 94
- Élevé
- 1472
- En attente NVD
- 0
CVE corrigées
| CVE | Sévérité | KEV | Publié | Description |
|---|---|---|---|---|
|
CVE-2025-59287
KEV
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
CRITICAL 9.8 | KEV | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | |
|
CVE-2026-21510
KEV
Windows Shell Security Feature Bypass Vulnerability |
HIGH 8.8 | KEV | Windows Shell Security Feature Bypass Vulnerability | |
|
CVE-2026-21513
KEV
MSHTML Framework Security Feature Bypass Vulnerability |
HIGH 8.8 | KEV | MSHTML Framework Security Feature Bypass Vulnerability | |
|
CVE-2025-33053
KEV
Internet Shortcut Files Remote Code Execution Vulnerability |
HIGH 8.8 | KEV | Internet Shortcut Files Remote Code Execution Vulnerability | |
|
CVE-2025-33073
KEV
Windows SMB Client Elevation of Privilege Vulnerability |
HIGH 8.8 | KEV | Windows SMB Client Elevation of Privilege Vulnerability | |
|
CVE-2024-49039
KEV
Windows Task Scheduler Elevation of Privilege Vulnerability |
HIGH 8.8 | KEV | Windows Task Scheduler Elevation of Privilege Vulnerability | |
|
CVE-2026-56155
KEV
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacke… |
HIGH 7.8 | KEV | Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-21519
KEV
Desktop Window Manager Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Desktop Window Manager Elevation of Privilege Vulnerability | |
|
CVE-2026-21533
KEV
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Remote Desktop Services Elevation of Privilege Vulnerability | |
|
CVE-2025-62221
KEV
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-60710
KEV
Host Process for Windows Tasks Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Host Process for Windows Tasks Elevation of Privilege Vulnerability | |
|
CVE-2025-24990
KEV
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Agere Modem Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-59230
KEV
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
|
CVE-2025-30400
KEV
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-32701
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-32706
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-32709
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-29824
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-24985
KEV
Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
HIGH 7.8 | KEV | Windows Fast FAT File System Driver Remote Code Execution Vulnerability | |
|
CVE-2025-24993
KEV
Windows NTFS Remote Code Execution Vulnerability |
HIGH 7.8 | KEV | Windows NTFS Remote Code Execution Vulnerability | |
|
CVE-2025-21418
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-21333
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
|
CVE-2025-21334
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
|
CVE-2025-21335
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
|
CVE-2024-49138
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | KEV | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-30397
KEV
Scripting Engine Memory Corruption Vulnerability |
HIGH 7.5 | KEV | Scripting Engine Memory Corruption Vulnerability | |
|
CVE-2025-21391
KEV
Windows Storage Elevation of Privilege Vulnerability |
HIGH 7.1 | KEV | Windows Storage Elevation of Privilege Vulnerability | |
|
CVE-2025-62215
KEV
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.0 | KEV | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-26633
KEV
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature lo… |
HIGH 7.0 | KEV | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | |
|
CVE-2025-24054
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
HIGH 6.5 | KEV | NTLM Hash Disclosure Spoofing Vulnerability | |
|
CVE-2024-43451
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
HIGH 6.5 | KEV | NTLM Hash Disclosure Spoofing Vulnerability | |
|
CVE-2026-21525
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability |
MEDIUM 6.2 | KEV | Windows Remote Access Connection Manager Denial of Service Vulnerability | |
|
CVE-2026-20805
KEV
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to … |
MEDIUM 5.5 | KEV | Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | |
|
CVE-2025-24991
KEV
Windows NTFS Information Disclosure Vulnerability |
HIGH 5.5 | KEV | Windows NTFS Information Disclosure Vulnerability | |
|
CVE-2013-3900
KEV
WinVerifyTrust Signature Validation Vulnerability |
MEDIUM 5.5 | KEV | WinVerifyTrust Signature Validation Vulnerability | |
|
CVE-2025-47827
KEV
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 |
HIGH 4.6 | KEV | MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 | |
|
CVE-2025-24984
KEV
Windows NTFS Information Disclosure Vulnerability |
HIGH 4.6 | KEV | Windows NTFS Information Disclosure Vulnerability | |
|
CVE-2026-32202
KEV
Windows Shell Spoofing Vulnerability |
HIGH 4.3 | KEV | Windows Shell Spoofing Vulnerability | |
|
CVE-2026-57092
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. |
CRITICAL 9.9 | — | Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2025-49708
Microsoft Graphics Component Elevation of Privilege Vulnerability |
CRITICAL 9.9 | — | Microsoft Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2026-56190
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-56188
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network d… |
CRITICAL 9.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to… | |
|
CVE-2026-56159
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50518
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50447
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-54990
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-49172
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42990
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-47291
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-45657
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-44815
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-41089
Windows Netlogon Remote Code Execution Vulnerability |
CRITICAL 9.8 | — | Windows Netlogon Remote Code Execution Vulnerability | |
|
CVE-2026-41096
Windows DNS Client Remote Code Execution Vulnerability |
CRITICAL 9.8 | — | Windows DNS Client Remote Code Execution Vulnerability | |
|
CVE-2026-33824
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | |
|
CVE-2025-60724
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a netwo… |
CRITICAL 9.8 | — | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | |
|
CVE-2025-53766
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | |
|
CVE-2025-50165
Windows Graphics Component Remote Code Execution Vulnerability |
CRITICAL 9.8 | — | Windows Graphics Component Remote Code Execution Vulnerability | |
|
CVE-2025-47981
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability |
CRITICAL 9.8 | — | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | |
|
CVE-2025-21298
Windows OLE Remote Code Execution Vulnerability |
CRITICAL 9.8 | — | Windows OLE Remote Code Execution Vulnerability | |
|
CVE-2025-21307
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
CRITICAL 9.8 | — | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | |
|
CVE-2025-21311
Windows NTLM V1 Elevation of Privilege Vulnerability |
CRITICAL 9.8 | — | Windows NTLM V1 Elevation of Privilege Vulnerability | |
|
CVE-2024-49112
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
CRITICAL 9.8 | — | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | |
|
CVE-2024-43639
Windows KDC Proxy Remote Code Execution Vulnerability |
CRITICAL 9.8 | — | Windows KDC Proxy Remote Code Execution Vulnerability | |
|
CVE-2016-9535
tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or … |
CRITICAL 9.8 | — | tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when d… | |
|
CVE-2026-50380
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.6 | — | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42904
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent net… |
CRITICAL 9.6 | — | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | |
|
CVE-2026-49798
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
CRITICAL 9.3 | — | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-45602
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. |
CRITICAL 9.1 | — | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | |
|
CVE-2025-50171
Remote Desktop Spoofing Vulnerability |
HIGH 9.1 | — | Remote Desktop Spoofing Vulnerability | |
|
CVE-2026-58626
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
HIGH 8.8 | — | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | |
|
CVE-2026-58594
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. |
HIGH 8.8 | — | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-58534
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges l… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-57094
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-57090
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-57087
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-56647
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate… |
HIGH 8.8 | — | Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-56194
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a ne… |
HIGH 8.8 | — | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-54121
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privil… |
HIGH 8.8 | — | Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50692
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50687
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50670
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50666
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a n… |
HIGH 8.8 | — | Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50489
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50474
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 8.8 | — | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50477
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50444
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate … |
HIGH 8.8 | — | Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50413
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50398
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an … |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50385
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50382
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. |
HIGH 8.8 | — | Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | |
|
CVE-2026-50369
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
HIGH 8.8 | — | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50370
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netw… |
HIGH 8.8 | — | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | |
|
CVE-2026-50360
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate pri… |
HIGH 8.8 | — | Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-58608
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Co… |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker t… | |
|
CVE-2026-54999
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an… |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… | |
|
CVE-2026-54982
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker … |
HIGH 8.8 | — | Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | |
|
CVE-2026-54107
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an… |
HIGH 8.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg… | |
|
CVE-2026-49795
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 8.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49178
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a net… |
HIGH 8.8 | — | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | |
|
CVE-2026-48564
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. |
HIGH 8.8 | — | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | |
|
CVE-2026-47653
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 8.8 | — | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-47289
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 8.8 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-45648
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a ne… |
HIGH 8.8 | — | Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | |
|
CVE-2026-42985
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 8.8 | — | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-34329
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
|
CVE-2026-40403
Windows Graphics Component Remote Code Execution Vulnerability |
CRITICAL 8.8 | — | Windows Graphics Component Remote Code Execution Vulnerability | |
|
CVE-2026-32225
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a netwo… |
HIGH 8.8 | — | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | |
|
CVE-2026-26167
Windows Push Notifications Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Push Notifications Elevation of Privilege Vulnerability | |
|
CVE-2026-26178
Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability | |
|
CVE-2026-32157
Remote Desktop Client Remote Code Execution Vulnerability |
CRITICAL 8.8 | — | Remote Desktop Client Remote Code Execution Vulnerability | |
|
CVE-2026-23669
RPC Runtime Library Remote Code Execution Vulnerability |
HIGH 8.8 | — | RPC Runtime Library Remote Code Execution Vulnerability | |
|
CVE-2026-24283
Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-25177
Active Directory Domain Services Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Active Directory Domain Services Elevation of Privilege Vulnerability | |
|
CVE-2026-25188
Windows Telephony Service Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Elevation of Privilege Vulnerability | |
|
CVE-2026-21255
Windows Hyper-V Security Feature Bypass Vulnerability |
HIGH 8.8 | — | Windows Hyper-V Security Feature Bypass Vulnerability | |
|
CVE-2026-20868
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execu… |
HIGH 8.8 | — | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2025-62456
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | |
|
CVE-2025-62549
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-64678
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-58715
Windows Speech Runtime Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Speech Runtime Elevation of Privilege Vulnerability | |
|
CVE-2025-58716
Windows Speech Runtime Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Speech Runtime Elevation of Privilege Vulnerability | |
|
CVE-2025-58718
Remote Desktop Client Remote Code Execution Vulnerability |
HIGH 8.8 | — | Remote Desktop Client Remote Code Execution Vulnerability | |
|
CVE-2025-59295
Windows URL Parsing Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows URL Parsing Remote Code Execution Vulnerability | |
|
CVE-2025-54106
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-54110
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-54113
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-54918
Windows NTLM Elevation of Privilege Vulnerability |
CRITICAL 8.8 | — | Windows NTLM Elevation of Privilege Vulnerability | |
|
CVE-2025-55234
Windows SMB Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows SMB Elevation of Privilege Vulnerability | |
|
CVE-2025-49757
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-50163
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-53131
Windows Media Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Media Remote Code Execution Vulnerability | |
|
CVE-2025-53143
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
|
CVE-2025-53144
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
|
CVE-2025-53145
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
|
CVE-2025-53778
Windows NTLM Elevation of Privilege Vulnerability |
CRITICAL 8.8 | — | Windows NTLM Elevation of Privilege Vulnerability | |
|
CVE-2025-47986
Universal Print Management Service Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Universal Print Management Service Elevation of Privilege Vulnerability | |
|
CVE-2025-47998
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-48817
Remote Desktop Client Remote Code Execution Vulnerability |
HIGH 8.8 | — | Remote Desktop Client Remote Code Execution Vulnerability | |
|
CVE-2025-48824
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49657
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49663
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49668
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49669
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49672
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49673
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49674
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49676
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49687
Windows Input Method Editor (IME) Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | |
|
CVE-2025-49688
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49723
Windows StateRepository API Server file Tampering Vulnerability |
HIGH 8.8 | — | Windows StateRepository API Server file Tampering Vulnerability | |
|
CVE-2025-49724
Windows Connected Devices Platform Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Connected Devices Platform Service Remote Code Execution Vulnerability | |
|
CVE-2025-49729
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49740
Windows SmartScreen Security Feature Bypass Vulnerability |
HIGH 8.8 | — | Windows SmartScreen Security Feature Bypass Vulnerability | |
|
CVE-2025-49753
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-33064
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-33066
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-29962
Windows Media Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Media Remote Code Execution Vulnerability | |
|
CVE-2025-29963
Windows Media Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Media Remote Code Execution Vulnerability | |
|
CVE-2025-29964
Windows Media Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Media Remote Code Execution Vulnerability | |
|
CVE-2025-29966
Remote Desktop Client Remote Code Execution Vulnerability |
CRITICAL 8.8 | — | Remote Desktop Client Remote Code Execution Vulnerability | |
|
CVE-2025-29967
Remote Desktop Client Remote Code Execution Vulnerability |
CRITICAL 8.8 | — | Remote Desktop Client Remote Code Execution Vulnerability | |
|
CVE-2025-21205
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21221
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21222
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-26647
Windows Kerberos Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Kerberos Elevation of Privilege Vulnerability | |
|
CVE-2025-26669
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-27477
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-27481
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-27740
Active Directory Certificate Services Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Active Directory Certificate Services Elevation of Privilege Vulnerability | |
|
CVE-2025-24051
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-24056
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-26645
Remote Desktop Client Remote Code Execution Vulnerability |
CRITICAL 8.8 | — | Remote Desktop Client Remote Code Execution Vulnerability | |
|
CVE-2025-21190
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21200
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21201
Windows Telephony Server Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Server Remote Code Execution Vulnerability | |
|
CVE-2025-21208
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-21368
Microsoft Digest Authentication Remote Code Execution Vulnerability |
HIGH 8.8 | — | Microsoft Digest Authentication Remote Code Execution Vulnerability | |
|
CVE-2025-21369
Microsoft Digest Authentication Remote Code Execution Vulnerability |
HIGH 8.8 | — | Microsoft Digest Authentication Remote Code Execution Vulnerability | |
|
CVE-2025-21371
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21406
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21407
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21410
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-21223
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21233
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21236
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21237
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21238
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21239
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21240
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21241
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21243
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21244
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21245
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21246
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21248
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21250
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21252
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21266
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21273
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21282
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21286
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21292
Windows Search Service Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Search Service Elevation of Privilege Vulnerability | |
|
CVE-2025-21293
Active Directory Domain Services Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Active Directory Domain Services Elevation of Privilege Vulnerability | |
|
CVE-2025-21302
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21303
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21305
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21306
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21339
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21409
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21411
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21413
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2025-21417
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2024-49080
Windows IP Routing Management Snapin Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | |
|
CVE-2024-49085
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2024-49086
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2024-49093
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | |
|
CVE-2024-49102
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2024-49104
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2024-49117
Windows Hyper-V Remote Code Execution Vulnerability |
CRITICAL 8.8 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2024-49125
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2024-43620
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2024-43621
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2024-43622
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2024-43624
Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability |
HIGH 8.8 | — | Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability | |
|
CVE-2024-43627
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2024-43628
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2024-43635
Windows Telephony Service Remote Code Execution Vulnerability |
HIGH 8.8 | — | Windows Telephony Service Remote Code Execution Vulnerability | |
|
CVE-2026-27928
Windows Hello Security Feature Bypass Vulnerability |
HIGH 8.7 | — | Windows Hello Security Feature Bypass Vulnerability | |
|
CVE-2025-48822
Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability |
CRITICAL 8.6 | — | Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability | |
|
CVE-2025-27737
Windows Security Zone Mapping Security Feature Bypass Vulnerability |
HIGH 8.6 | — | Windows Security Zone Mapping Security Feature Bypass Vulnerability | |
|
CVE-2026-50340
Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. |
HIGH 8.5 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-54128
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. |
HIGH 8.4 | — | Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-54992
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code loc… |
HIGH 8.4 | — | Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-54122
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
HIGH 8.4 | — | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-49184
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 8.4 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-45641
Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to exe… |
HIGH 8.4 | — | Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-45607
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. |
HIGH 8.4 | — | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-44810
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. |
HIGH 8.4 | — | Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-32221
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
HIGH 8.4 | — | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-32091
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 8.4 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2026-32162
Windows COM Elevation of Privilege Vulnerability |
HIGH 8.4 | — | Windows COM Elevation of Privilege Vulnerability | |
|
CVE-2025-33067
Windows Task Scheduler Elevation of Privilege Vulnerability |
HIGH 8.4 | — | Windows Task Scheduler Elevation of Privilege Vulnerability | |
|
CVE-2025-26678
Windows Defender Application Control Security Feature Bypass Vulnerability |
HIGH 8.4 | — | Windows Defender Application Control Security Feature Bypass Vulnerability | |
|
CVE-2025-24084
Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability |
CRITICAL 8.4 | — | Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability | |
|
CVE-2024-49105
Remote Desktop Client Remote Code Execution Vulnerability |
CRITICAL 8.4 | — | Remote Desktop Client Remote Code Execution Vulnerability | |
|
CVE-2026-56181
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofin… |
HIGH 8.3 | — | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | |
|
CVE-2026-50680
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
HIGH 8.2 | — | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50429
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. |
HIGH 8.2 | — | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-47652
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. |
HIGH 8.2 | — | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | |
|
CVE-2026-56186
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. |
HIGH 8.1 | — | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | |
|
CVE-2026-50686
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute… |
HIGH 8.1 | — | Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50487
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. |
HIGH 8.1 | — | Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. | |
|
CVE-2026-50460
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 8.1 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… | |
|
CVE-2026-50439
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a networ… |
HIGH 8.1 | — | Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-54995
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a n… |
HIGH 8.1 | — | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50694
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over … |
HIGH 8.1 | — | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-49164
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a n… |
HIGH 8.1 | — | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42900
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows… |
HIGH 8.1 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri… | |
|
CVE-2026-45635
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthori… |
HIGH 8.1 | — | Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a netw… | |
|
CVE-2026-45599
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. |
HIGH 8.1 | — | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42981
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code o… |
HIGH 8.1 | — | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42987
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
HIGH 8.1 | — | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42974
Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a ne… |
HIGH 8.1 | — | Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-40415
Windows TCP/IP Remote Code Execution Vulnerability |
HIGH 8.1 | — | Windows TCP/IP Remote Code Execution Vulnerability | |
|
CVE-2026-33827
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an… |
HIGH 8.1 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… | |
|
CVE-2026-20856
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a netwo… |
HIGH 8.1 | — | Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | |
|
CVE-2025-50177
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
|
CVE-2025-33054
Remote Desktop Spoofing Vulnerability |
HIGH 8.1 | — | Remote Desktop Spoofing Vulnerability | |
|
CVE-2025-49735
Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability | |
|
CVE-2025-29828
Windows Schannel Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Schannel Remote Code Execution Vulnerability | |
|
CVE-2025-32710
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2025-33070
Windows Netlogon Elevation of Privilege Vulnerability |
CRITICAL 8.1 | — | Windows Netlogon Elevation of Privilege Vulnerability | |
|
CVE-2025-33071
Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability | |
|
CVE-2025-26663
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | |
|
CVE-2025-26670
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability | |
|
CVE-2025-26671
Windows Remote Desktop Services Remote Code Execution Vulnerability |
HIGH 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2025-27480
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2025-27482
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2025-24035
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2025-24045
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2025-24064
Windows Domain Name Service Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Domain Name Service Remote Code Execution Vulnerability | |
|
CVE-2025-21376
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | |
|
CVE-2025-21224
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability |
HIGH 8.1 | — | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | |
|
CVE-2025-21294
Microsoft Digest Authentication Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Microsoft Digest Authentication Remote Code Execution Vulnerability | |
|
CVE-2025-21295
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | |
|
CVE-2025-21297
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2025-21309
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49106
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49108
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49115
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49116
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49118
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
|
CVE-2024-49119
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49120
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49122
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
|
CVE-2024-49123
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49124
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability | |
|
CVE-2024-49126
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | |
|
CVE-2024-49127
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | |
|
CVE-2024-49128
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-49132
Windows Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL 8.1 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2024-43625
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability |
CRITICAL 8.1 | — | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | |
|
CVE-2026-50683
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent … |
HIGH 8.0 | — | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network. | |
|
CVE-2026-50502
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute co… |
HIGH 8.0 | — | Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. | |
|
CVE-2026-50365
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent netwo… |
HIGH 8.0 | — | Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. | |
|
CVE-2026-49169
Use after free in DNS Server allows an authorized attacker to execute code over a network. |
HIGH 8.0 | — | Use after free in DNS Server allows an authorized attacker to execute code over a network. | |
|
CVE-2026-42975
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adj… |
HIGH 8.0 | — | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | |
|
CVE-2026-40400
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. |
HIGH 8.0 | — | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | |
|
CVE-2026-34332
Windows Kernel-Mode Driver Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Kernel-Mode Driver Remote Code Execution Vulnerability | |
|
CVE-2026-33826
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent ne… |
HIGH 8.0 | — | Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. | |
|
CVE-2026-27912
Windows Kerberos Elevation of Privilege Vulnerability |
HIGH 8.0 | — | Windows Kerberos Elevation of Privilege Vulnerability | |
|
CVE-2026-25172
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2026-25173
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2026-26111
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2026-20931
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges … |
HIGH 8.0 | — | External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. | |
|
CVE-2025-60715
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-62452
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-50160
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-50162
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-50164
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-53720
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-47972
Windows Input Method Editor (IME) Elevation of Privilege Vulnerability |
HIGH 8.0 | — | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | |
|
CVE-2025-49691
Windows Miracast Wireless Display Remote Code Execution Vulnerability |
HIGH 8.0 | — | Windows Miracast Wireless Display Remote Code Execution Vulnerability | |
|
CVE-2025-27487
Remote Desktop Client Remote Code Execution Vulnerability |
HIGH 8.0 | — | Remote Desktop Client Remote Code Execution Vulnerability | |
|
CVE-2026-48575
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
HIGH 7.9 | — | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-48576
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
HIGH 7.9 | — | No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-48578
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. |
HIGH 7.9 | — | Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-48568
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
HIGH 7.9 | — | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-48570
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
HIGH 7.9 | — | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-48573
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
HIGH 7.9 | — | No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-47656
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. |
HIGH 7.9 | — | Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-45654
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
HIGH 7.9 | — | Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-45588
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
HIGH 7.9 | — | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-58632
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58613
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58628
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Network… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to ele… | |
|
CVE-2026-58542
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-58538
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58540
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58541
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate p… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58532
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58536
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58537
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges lo… |
HIGH 7.8 | — | Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58527
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-58530
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loca… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-57096
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-57088
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locall… |
HIGH 7.8 | — | Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-57091
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56650
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56643
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56644
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56189
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locall… |
HIGH 7.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-56182
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56175
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56176
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54124
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-54125
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-54115
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50689
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50688
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50679
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges lo… |
HIGH 7.8 | — | Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50673
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50667
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an a… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges… | |
|
CVE-2026-50655
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50509
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevat… |
HIGH 7.8 | — | Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50501
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loc… |
HIGH 7.8 | — | Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50498
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-50499
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges loca… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50493
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50494
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-50484
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50486
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50488
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service a… |
HIGH 7.8 | — | Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate … | |
|
CVE-2026-50476
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50478
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50479
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50469
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized at… |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50471
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50461
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50462
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to… |
HIGH 7.8 | — | External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50466
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50454
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50457
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50458
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50448
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50450
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Ar… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized … | |
|
CVE-2026-50441
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileg… |
HIGH 7.8 | — | Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50433
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50435
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50436
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50427
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50421
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allow… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate priv… | |
|
CVE-2026-50422
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50423
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50425
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50412
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50417
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-50405
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate… |
HIGH 7.8 | — | Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50407
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges … |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50399
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50400
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50402
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50391
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50386
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50387
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50388
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50378
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privi… | |
|
CVE-2026-50373
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges local… |
HIGH 7.8 | — | Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50367
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to … |
HIGH 7.8 | — | Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50361
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50362
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loca… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50363
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50353
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50357
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |
|
CVE-2026-50344
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50346
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50347
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50337
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50343
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50331
Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50332
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50335
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50326
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50327
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | |
|
CVE-2026-50329
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50315
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50317
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating System… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to eleva… | |
|
CVE-2026-50321
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allow… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv… | |
|
CVE-2026-50309
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-50313
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-50305
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50306
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58609
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-58610
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locall… |
HIGH 7.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-58635
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows … |
HIGH 7.8 | — | Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privil… | |
|
CVE-2026-58601
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileg… |
HIGH 7.8 | — | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58602
Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-55004
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54993
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locall… |
HIGH 7.8 | — | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-55001
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54986
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54987
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54991
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-54112
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg… | |
|
CVE-2026-54114
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54109
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code lo… |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |
|
CVE-2026-50697
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorize… |
HIGH 7.8 | — | Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50351
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges … |
HIGH 7.8 | — | Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50311
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50318
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges… |
HIGH 7.8 | — | Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50333
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileg… |
HIGH 7.8 | — | Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50308
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-49808
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileg… | |
|
CVE-2026-50293
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49800
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to ele… |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49793
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locall… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |
|
CVE-2026-49796
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-49797
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-49792
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | |
|
CVE-2026-49783
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a sec… |
HIGH 7.8 | — | Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-49175
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49176
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49166
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49170
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate priv… |
HIGH 7.8 | — | Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42982
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate … |
HIGH 7.8 | — | Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-44800
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notificatio… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… | |
|
CVE-2026-8863
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative pr… |
HIGH 7.8 | — | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the bo… | |
|
CVE-2026-48574
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-48583
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45658
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. |
HIGH 7.8 | — | Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-45656
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. |
HIGH 7.8 | — | Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-45636
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-45637
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45638
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pr… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45605
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45600
Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attac… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45592
Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges lo… |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45593
Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45586
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an… |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileg… | |
|
CVE-2026-45487
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attac… |
HIGH 7.8 | — | Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-44812
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-44802
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-44803
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-44809
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42989
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate pri… |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42991
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notificatio… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… | |
|
CVE-2026-42983
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42986
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42977
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notificatio… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… | |
|
CVE-2026-42978
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notificatio… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… | |
|
CVE-2026-42979
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notificatio… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… | |
|
CVE-2026-42980
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges loca… |
HIGH 7.8 | — | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42916
Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42905
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42910
Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42837
Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges l… |
HIGH 7.8 | — | Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42828
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loc… |
HIGH 7.8 | — | Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-40404
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-40409
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-41092
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-33828
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-41088
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows a… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… | |
|
CVE-2026-40397
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-40399
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg… | |
|
CVE-2026-40369
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-35417
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-34336
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-33840
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-33841
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-34330
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX al… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p… | |
|
CVE-2026-33834
Windows Event Logging Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Event Logging Service Elevation of Privilege Vulnerability | |
|
CVE-2026-33835
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-33837
Windows TCP/IP Local Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows TCP/IP Local Elevation of Privilege Vulnerability | |
|
CVE-2026-33838
Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability | |
|
CVE-2026-34333
Windows Win32k Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Win32k Elevation of Privilege Vulnerability | |
|
CVE-2026-34334
Windows TCP/IP Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows TCP/IP Elevation of Privilege Vulnerability | |
|
CVE-2026-34337
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-34338
Windows Telephony Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Telephony Service Elevation of Privilege Vulnerability | |
|
CVE-2026-34343
Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability | |
|
CVE-2026-34344
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-34351
Windows TCP/IP Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows TCP/IP Elevation of Privilege Vulnerability | |
|
CVE-2026-35415
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
|
CVE-2026-35418
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-35420
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-35421
Windows GDI Remote Code Execution Vulnerability |
CRITICAL 7.8 | — | Windows GDI Remote Code Execution Vulnerability | |
|
CVE-2026-40377
Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | |
|
CVE-2026-40382
Windows Telephony Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Telephony Service Elevation of Privilege Vulnerability | |
|
CVE-2026-40398
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Remote Desktop Services Elevation of Privilege Vulnerability | |
|
CVE-2026-40407
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-40408
Windows WAN ARP Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows WAN ARP Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-41095
Data Deduplication Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Data Deduplication Elevation of Privilege Vulnerability | |
|
CVE-2026-42896
Windows DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2026-33101
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-33098
Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges loca… |
HIGH 7.8 | — | Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-32222
Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-32154
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-32152
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20930
Windows Management Services Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Management Services Elevation of Privilege Vulnerability | |
|
CVE-2026-26153
Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-26156
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2026-26159
Remote Desktop Licensing Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Remote Desktop Licensing Service Elevation of Privilege Vulnerability | |
|
CVE-2026-26160
Remote Desktop Licensing Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Remote Desktop Licensing Service Elevation of Privilege Vulnerability | |
|
CVE-2026-26161
Windows Sensor Data Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Sensor Data Service Elevation of Privilege Vulnerability | |
|
CVE-2026-26162
Windows OLE Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows OLE Elevation of Privilege Vulnerability | |
|
CVE-2026-26163
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-26168
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-26170
PowerShell Elevation of Privilege Vulnerability |
HIGH 7.8 | — | PowerShell Elevation of Privilege Vulnerability | |
|
CVE-2026-26172
Windows Push Notifications Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Push Notifications Elevation of Privilege Vulnerability | |
|
CVE-2026-26176
Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability | |
|
CVE-2026-26179
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-26180
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-26181
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2026-26183
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | |
|
CVE-2026-26184
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2026-27907
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
|
CVE-2026-27909
Windows Search Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Search Service Elevation of Privilege Vulnerability | |
|
CVE-2026-27910
Windows Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Installer Elevation of Privilege Vulnerability | |
|
CVE-2026-27911
Windows User Interface Core Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows User Interface Core Elevation of Privilege Vulnerability | |
|
CVE-2026-27914
Microsoft Management Console Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Management Console Elevation of Privilege Vulnerability | |
|
CVE-2026-27915
Windows UPnP Device Host Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
|
CVE-2026-27916
Windows UPnP Device Host Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
|
CVE-2026-27918
Windows Shell Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Shell Elevation of Privilege Vulnerability | |
|
CVE-2026-27919
Windows UPnP Device Host Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
|
CVE-2026-27920
Windows UPnP Device Host Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
|
CVE-2026-27923
Desktop Window Manager Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Desktop Window Manager Elevation of Privilege Vulnerability | |
|
CVE-2026-27927
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2026-32069
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2026-32074
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2026-32076
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
|
CVE-2026-32077
Windows UPnP Device Host Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
|
CVE-2026-32078
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2026-32089
Windows Speech Brokered Api Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Speech Brokered Api Elevation of Privilege Vulnerability | |
|
CVE-2026-32090
Windows Speech Brokered Api Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Speech Brokered Api Elevation of Privilege Vulnerability | |
|
CVE-2026-32155
Desktop Window Manager Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Desktop Window Manager Elevation of Privilege Vulnerability | |
|
CVE-2026-32158
Windows Push Notifications Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Push Notifications Elevation of Privilege Vulnerability | |
|
CVE-2026-32159
Windows Push Notifications Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Push Notifications Elevation of Privilege Vulnerability | |
|
CVE-2026-32160
Windows Push Notifications Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Push Notifications Elevation of Privilege Vulnerability | |
|
CVE-2026-32163
Windows User Interface Core Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows User Interface Core Elevation of Privilege Vulnerability | |
|
CVE-2026-32164
Windows User Interface Core Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows User Interface Core Elevation of Privilege Vulnerability | |
|
CVE-2026-32165
Windows User Interface Core Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows User Interface Core Elevation of Privilege Vulnerability | |
|
CVE-2026-32183
Windows Snipping Tool Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows Snipping Tool Remote Code Execution Vulnerability | |
|
CVE-2026-24293
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate priv… |
HIGH 7.8 | — | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-24294
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-24289
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-23672
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-23673
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-24287
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-24290
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2026-24291
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability | |
|
CVE-2026-24292
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2026-25165
Performance Counters for Windows Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Performance Counters for Windows Elevation of Privilege Vulnerability | |
|
CVE-2026-25174
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Extensible File Allocation Table Elevation of Privilege Vulnerability | |
|
CVE-2026-25176
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-25187
Winlogon Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Winlogon Elevation of Privilege Vulnerability | |
|
CVE-2026-25190
Windows GDI Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows GDI Remote Code Execution Vulnerability | |
|
CVE-2026-26128
Windows SMB Server Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows SMB Server Elevation of Privilege Vulnerability | |
|
CVE-2026-26132
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-21231
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-21232
Windows HTTP.sys Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows HTTP.sys Elevation of Privilege Vulnerability | |
|
CVE-2026-21236
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-21238
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-21239
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-21240
Windows HTTP.sys Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows HTTP.sys Elevation of Privilege Vulnerability | |
|
CVE-2026-21245
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2026-21246
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2026-21250
Windows HTTP.sys Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows HTTP.sys Elevation of Privilege Vulnerability | |
|
CVE-2026-21251
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Cluster Client Failover (CCF) Elevation of Privilege Vulnerability | |
|
CVE-2026-20941
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized a… |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20924
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20922
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-20923
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20873
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servi… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… | |
|
CVE-2026-20874
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servi… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… | |
|
CVE-2026-20877
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20918
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servi… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… | |
|
CVE-2026-20867
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servi… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… | |
|
CVE-2026-20870
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20871
Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20861
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servi… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… | |
|
CVE-2026-20864
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate priv… |
HIGH 7.8 | — | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20865
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20866
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servi… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… | |
|
CVE-2026-20857
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privil… |
HIGH 7.8 | — | Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20858
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20859
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20860
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows a… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… | |
|
CVE-2026-20840
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-20843
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pr… |
HIGH 7.8 | — | Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20832
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | |
|
CVE-2026-20837
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-20826
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Inte… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an autho… | |
|
CVE-2026-20831
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized… |
HIGH 7.8 | — | Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20820
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20822
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20816
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privile… |
HIGH 7.8 | — | Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20817
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to… |
HIGH 7.8 | — | Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20809
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate pri… |
HIGH 7.8 | — | Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20811
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker t… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2023-31096
MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-55414
Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-54100
PowerShell Remote Code Execution Vulnerability |
HIGH 7.8 | — | PowerShell Remote Code Execution Vulnerability | |
|
CVE-2025-55233
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2025-59516
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Storage VSP Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-59517
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Storage VSP Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-62454
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-62457
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-62461
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2025-62462
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2025-62464
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2025-62466
Windows Client-Side Caching Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Client-Side Caching Elevation of Privilege Vulnerability | |
|
CVE-2025-62467
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2025-62470
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-62472
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
|
CVE-2025-62474
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
|
CVE-2025-62571
Windows Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Installer Elevation of Privilege Vulnerability | |
|
CVE-2025-62572
Application Information Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Application Information Service Elevation of Privilege Vulnerability | |
|
CVE-2025-64661
Windows Shell Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Shell Elevation of Privilege Vulnerability | |
|
CVE-2025-64673
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Storage VSP Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-64679
Windows DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-64680
Windows DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-59505
Windows Smart Card Reader Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Smart Card Reader Elevation of Privilege Vulnerability | |
|
CVE-2025-59511
Windows WLAN Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows WLAN Service Elevation of Privilege Vulnerability | |
|
CVE-2025-59512
Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability | |
|
CVE-2025-59514
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | |
|
CVE-2025-60703
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Remote Desktop Services Elevation of Privilege Vulnerability | |
|
CVE-2025-60705
Windows Client-Side Caching Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Client-Side Caching Elevation of Privilege Vulnerability | |
|
CVE-2025-60707
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-60709
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-60713
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | |
|
CVE-2025-60720
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-24052
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Agere Modem Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-50152
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-50175
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-53150
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-55328
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-55339
Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-55677
Windows Device Association Broker Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Device Association Broker Service Elevation of Privilege Vulnerability | |
|
CVE-2025-55680
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-55692
Windows Error Reporting Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Error Reporting Service Elevation of Privilege Vulnerability | |
|
CVE-2025-55694
Windows Error Reporting Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Error Reporting Service Elevation of Privilege Vulnerability | |
|
CVE-2025-55696
NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability | |
|
CVE-2025-55697
Azure Local Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Azure Local Elevation of Privilege Vulnerability | |
|
CVE-2025-55701
Windows Authentication Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Authentication Elevation of Privilege Vulnerability | |
|
CVE-2025-58714
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-58720
Windows Cryptographic Services Information Disclosure Vulnerability |
HIGH 7.8 | — | Windows Cryptographic Services Information Disclosure Vulnerability | |
|
CVE-2025-58722
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-58728
Windows Bluetooth Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Bluetooth Service Elevation of Privilege Vulnerability | |
|
CVE-2025-59187
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-59191
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2025-59192
Storport.sys Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Storport.sys Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-59199
Software Protection Platform (SPP) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Software Protection Platform (SPP) Elevation of Privilege Vulnerability | |
|
CVE-2025-59201
Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability | |
|
CVE-2025-59207
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-59242
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-59254
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-59255
Windows DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-59275
Windows Authentication Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Authentication Elevation of Privilege Vulnerability | |
|
CVE-2025-59277
Windows Authentication Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Authentication Elevation of Privilege Vulnerability | |
|
CVE-2025-59278
Windows Authentication Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Authentication Elevation of Privilege Vulnerability | |
|
CVE-2025-59290
Windows Bluetooth Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Bluetooth Service Elevation of Privilege Vulnerability | |
|
CVE-2025-53800
Windows Graphics Component Elevation of Privilege Vulnerability |
CRITICAL 7.8 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-54091
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-54092
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-54098
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-54102
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2025-54111
Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability | |
|
CVE-2025-54894
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | |
|
CVE-2025-54895
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability |
HIGH 7.8 | — | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability | |
|
CVE-2025-54912
Windows BitLocker Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows BitLocker Elevation of Privilege Vulnerability | |
|
CVE-2025-54913
Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability | |
|
CVE-2025-54916
Windows NTFS Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows NTFS Remote Code Execution Vulnerability | |
|
CVE-2025-55224
Windows Hyper-V Remote Code Execution Vulnerability |
CRITICAL 7.8 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2025-55228
Windows Graphics Component Remote Code Execution Vulnerability |
CRITICAL 7.8 | — | Windows Graphics Component Remote Code Execution Vulnerability | |
|
CVE-2025-49761
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-50155
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Push Notifications Apps Elevation of Privilege Vulnerability | |
|
CVE-2025-50168
Win32k Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2025-50170
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-50173
Windows Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Installer Elevation of Privilege Vulnerability | |
|
CVE-2025-50176
DirectX Graphics Kernel Remote Code Execution Vulnerability |
CRITICAL 7.8 | — | DirectX Graphics Kernel Remote Code Execution Vulnerability | |
|
CVE-2025-53132
Win32k Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2025-53133
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-53141
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-53149
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-53151
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-53154
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-53155
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-53723
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-53724
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Push Notifications Apps Elevation of Privilege Vulnerability | |
|
CVE-2025-53725
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Push Notifications Apps Elevation of Privilege Vulnerability | |
|
CVE-2025-53726
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Push Notifications Apps Elevation of Privilege Vulnerability | |
|
CVE-2025-53789
Windows StateRepository API Server file Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows StateRepository API Server file Elevation of Privilege Vulnerability | |
|
CVE-2025-55230
Windows MBT Transport Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows MBT Transport Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-47159
Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability | |
|
CVE-2025-47971
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | |
|
CVE-2025-47973
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | |
|
CVE-2025-47976
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | |
|
CVE-2025-47982
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Storage VSP Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-47985
Windows Event Tracing Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Event Tracing Elevation of Privilege Vulnerability | |
|
CVE-2025-47987
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | |
|
CVE-2025-47991
Windows Input Method Editor (IME) Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | |
|
CVE-2025-47993
Microsoft PC Manager Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft PC Manager Elevation of Privilege Vulnerability | |
|
CVE-2025-47996
Windows MBT Transport Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows MBT Transport Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-48000
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2025-48799
Windows Update Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Update Service Elevation of Privilege Vulnerability | |
|
CVE-2025-48805
Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability |
HIGH 7.8 | — | Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | |
|
CVE-2025-48806
Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability |
HIGH 7.8 | — | Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | |
|
CVE-2025-48815
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | |
|
CVE-2025-48816
HID Class Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | HID Class Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-48820
Windows AppX Deployment Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows AppX Deployment Service Elevation of Privilege Vulnerability | |
|
CVE-2025-49659
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-49660
Windows Event Tracing Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Event Tracing Elevation of Privilege Vulnerability | |
|
CVE-2025-49661
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-49665
Workspace Broker Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Workspace Broker Elevation of Privilege Vulnerability | |
|
CVE-2025-49667
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | |
|
CVE-2025-49675
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-49679
Windows Shell Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Shell Elevation of Privilege Vulnerability | |
|
CVE-2025-49683
Microsoft Virtual Hard Disk Remote Code Execution Vulnerability |
HIGH 7.8 | — | Microsoft Virtual Hard Disk Remote Code Execution Vulnerability | |
|
CVE-2025-49686
Windows TCP/IP Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows TCP/IP Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-49689
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | |
|
CVE-2025-49693
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-49694
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-49721
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-49725
Windows Notification Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Notification Elevation of Privilege Vulnerability | |
|
CVE-2025-49726
Windows Notification Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Notification Elevation of Privilege Vulnerability | |
|
CVE-2025-49730
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-49732
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-49733
Win32k Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2025-49742
Windows Graphics Component Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows Graphics Component Remote Code Execution Vulnerability | |
|
CVE-2025-32712
Win32k Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2025-32713
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-32714
Windows Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Installer Elevation of Privilege Vulnerability | |
|
CVE-2025-32718
Windows SMB Client Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows SMB Client Elevation of Privilege Vulnerability | |
|
CVE-2025-33075
Windows Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Installer Elevation of Privilege Vulnerability | |
|
CVE-2025-47955
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
|
CVE-2025-30388
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
|
CVE-2025-24063
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-29970
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-30385
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-21204
Windows Process Activation Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Process Activation Elevation of Privilege Vulnerability | |
|
CVE-2025-24058
Windows DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-24060
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-24062
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-24073
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-24074
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2025-26639
Windows USB Print Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows USB Print Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-26648
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-26666
Windows Media Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows Media Remote Code Execution Vulnerability | |
|
CVE-2025-26674
Windows Media Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows Media Remote Code Execution Vulnerability | |
|
CVE-2025-26675
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Subsystem for Linux Elevation of Privilege Vulnerability | |
|
CVE-2025-26679
RPC Endpoint Mapper Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | RPC Endpoint Mapper Service Elevation of Privilege Vulnerability | |
|
CVE-2025-26688
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | |
|
CVE-2025-27476
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-27490
Windows Bluetooth Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Bluetooth Service Elevation of Privilege Vulnerability | |
|
CVE-2025-27727
Windows Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Installer Elevation of Privilege Vulnerability | |
|
CVE-2025-27728
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-27729
Windows Shell Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows Shell Remote Code Execution Vulnerability | |
|
CVE-2025-27730
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-27731
Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability | |
|
CVE-2025-27739
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-29811
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-29812
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | DirectX Graphics Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-21180
Windows exFAT File System Remote Code Execution Vulnerability |
HIGH 7.8 | — | Windows exFAT File System Remote Code Execution Vulnerability | |
|
CVE-2025-24044
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | |
|
CVE-2025-24046
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-24048
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-24050
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-24059
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-24061
Windows Mark of the Web Security Feature Bypass Vulnerability |
HIGH 7.8 | — | Windows Mark of the Web Security Feature Bypass Vulnerability | |
|
CVE-2025-24066
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-24067
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-24072
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability | |
|
CVE-2025-24995
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-21358
Windows Core Messaging Elevation of Privileges Vulnerability |
HIGH 7.8 | — | Windows Core Messaging Elevation of Privileges Vulnerability | |
|
CVE-2025-21359
Windows Kernel Security Feature Bypass Vulnerability |
HIGH 7.8 | — | Windows Kernel Security Feature Bypass Vulnerability | |
|
CVE-2025-21367
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | |
|
CVE-2025-21373
Windows Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Installer Elevation of Privilege Vulnerability | |
|
CVE-2025-21375
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-21420
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Disk Cleanup Tool Elevation of Privilege Vulnerability | |
|
CVE-2025-21338
GDI+ Remote Code Execution Vulnerability |
HIGH 7.8 | — | GDI+ Remote Code Execution Vulnerability | |
|
CVE-2025-21234
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-21235
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-21275
Windows App Package Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows App Package Installer Elevation of Privilege Vulnerability | |
|
CVE-2025-21281
Microsoft COM for Windows Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft COM for Windows Elevation of Privilege Vulnerability | |
|
CVE-2025-21287
Windows Installer Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Installer Elevation of Privilege Vulnerability | |
|
CVE-2025-21315
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-21325
Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | |
|
CVE-2025-21326
Internet Explorer Remote Code Execution Vulnerability |
HIGH 7.8 | — | Internet Explorer Remote Code Execution Vulnerability | |
|
CVE-2025-21372
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-21378
Windows CSC Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows CSC Service Elevation of Privilege Vulnerability | |
|
CVE-2025-21382
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2024-49072
Windows Task Scheduler Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Task Scheduler Elevation of Privilege Vulnerability | |
|
CVE-2024-49076
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | |
|
CVE-2024-49079
Input Method Editor (IME) Remote Code Execution Vulnerability |
HIGH 7.8 | — | Input Method Editor (IME) Remote Code Execution Vulnerability | |
|
CVE-2024-49088
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-49090
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-49114
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-43623
Windows NT OS Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows NT OS Kernel Elevation of Privilege Vulnerability | |
|
CVE-2024-43626
Windows Telephony Service Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Telephony Service Elevation of Privilege Vulnerability | |
|
CVE-2024-43629
Windows DWM Core Library Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows DWM Core Library Elevation of Privilege Vulnerability | |
|
CVE-2024-43630
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2024-43636
Win32k Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2024-43641
Windows Registry Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Registry Elevation of Privilege Vulnerability | |
|
CVE-2024-43644
Windows Client-Side Caching Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Client-Side Caching Elevation of Privilege Vulnerability | |
|
CVE-2024-49019
Active Directory Certificate Services Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Active Directory Certificate Services Elevation of Privilege Vulnerability | |
|
CVE-2024-49046
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | |
|
CVE-2024-43583
Winlogon Elevation of Privilege Vulnerability |
HIGH 7.8 | — | Winlogon Elevation of Privilege Vulnerability | |
|
CVE-2026-20852
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. |
HIGH 7.7 | — | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | |
|
CVE-2026-20804
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. |
HIGH 7.7 | — | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | |
|
CVE-2025-53139
Windows Hello Security Feature Bypass Vulnerability |
HIGH 7.7 | — | Windows Hello Security Feature Bypass Vulnerability | |
|
CVE-2025-55698
DirectX Graphics Kernel Denial of Service Vulnerability |
HIGH 7.7 | — | DirectX Graphics Kernel Denial of Service Vulnerability | |
|
CVE-2025-59200
Data Sharing Service Spoofing Vulnerability |
HIGH 7.7 | — | Data Sharing Service Spoofing Vulnerability | |
|
CVE-2025-6965
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the numb… |
HIGH 7.7 | — | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead… | |
|
CVE-2025-29833
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability |
CRITICAL 7.7 | — | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability | |
|
CVE-2026-58627
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
HIGH 7.5 | — | Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-58531
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an au… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges … | |
|
CVE-2026-57089
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute c… |
HIGH 7.5 | — | Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-56648
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to eleva… |
HIGH 7.5 | — | Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50685
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. |
HIGH 7.5 | — | Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. | |
|
CVE-2026-50647
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauth… |
HIGH 7.5 | — | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n… | |
|
CVE-2026-50505
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. |
HIGH 7.5 | — | Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. | |
|
CVE-2026-50496
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a… |
HIGH 7.5 | — | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50500
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. |
HIGH 7.5 | — | Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-50470
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a… |
HIGH 7.5 | — | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50463
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. |
HIGH 7.5 | — | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50424
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a netwo… |
HIGH 7.5 | — | Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50414
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an … |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50411
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny ser… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50368
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service ove… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50355
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service ove… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50330
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a networ… |
HIGH 7.5 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. | |
|
CVE-2026-50328
Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. |
HIGH 7.5 | — | Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. | |
|
CVE-2026-50304
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service ove… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-54983
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny ser… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-54119
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to d… |
HIGH 7.5 | — | Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50695
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service ove… |
HIGH 7.5 | — | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-50696
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny serv… |
HIGH 7.5 | — | Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-49787
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny servic… |
HIGH 7.5 | — | Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-49788
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a n… |
HIGH 7.5 | — | Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-49181
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges ove… |
HIGH 7.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. | |
|
CVE-2026-49171
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
HIGH 7.5 | — | Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-40378
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an una… |
HIGH 7.5 | — | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over … | |
|
CVE-2026-49160
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. |
HIGH 7.5 | — | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-48563
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 7.5 | — | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-47654
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 7.5 | — | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-45639
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
HIGH 7.5 | — | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-42992
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 7.5 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42993
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 7.5 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-44799
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 7.5 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-44801
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 7.5 | — | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42913
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client al… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… | |
|
CVE-2026-42908
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
HIGH 7.5 | — | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-42909
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client al… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… | |
|
CVE-2026-32161
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability |
CRITICAL 7.5 | — | Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability | |
|
CVE-2026-35424
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
HIGH 7.5 | — | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | |
|
CVE-2026-40405
Windows TCP/IP Denial of Service Vulnerability |
HIGH 7.5 | — | Windows TCP/IP Denial of Service Vulnerability | |
|
CVE-2026-40406
Windows TCP/IP Information Disclosure Vulnerability |
HIGH 7.5 | — | Windows TCP/IP Information Disclosure Vulnerability | |
|
CVE-2026-33096
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. |
HIGH 7.5 | — | Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-26154
Windows Server Update Service (WSUS) Tampering Vulnerability |
HIGH 7.5 | — | Windows Server Update Service (WSUS) Tampering Vulnerability | |
|
CVE-2026-32071
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | |
|
CVE-2026-23674
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 7.5 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2026-25181
GDI+ Information Disclosure Vulnerability |
HIGH 7.5 | — | GDI+ Information Disclosure Vulnerability | |
|
CVE-2026-20846
GDI+ Denial of Service Vulnerability |
HIGH 7.5 | — | GDI+ Denial of Service Vulnerability | |
|
CVE-2026-21243
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | |
|
CVE-2026-20934
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allow… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… | |
|
CVE-2026-20926
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allow… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… | |
|
CVE-2026-20919
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allow… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… | |
|
CVE-2026-20921
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allow… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… | |
|
CVE-2026-20875
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker … |
HIGH 7.5 | — | Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-20854
Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute c… |
HIGH 7.5 | — | Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | |
|
CVE-2026-20848
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allow… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… | |
|
CVE-2026-20849
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privil… |
HIGH 7.5 | — | Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | |
|
CVE-2026-0386
Windows Deployment Services Remote Code Execution Vulnerability |
HIGH 7.5 | — | Windows Deployment Services Remote Code Execution Vulnerability | |
|
CVE-2025-64658
Windows File Explorer Elevation of Privilege Vulnerability |
HIGH 7.5 | — | Windows File Explorer Elevation of Privilege Vulnerability | |
|
CVE-2025-60704
Windows Kerberos Elevation of Privilege Vulnerability |
HIGH 7.5 | — | Windows Kerberos Elevation of Privilege Vulnerability | |
|
CVE-2025-55326
Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability |
HIGH 7.5 | — | Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability | |
|
CVE-2025-58726
Windows SMB Server Elevation of Privilege Vulnerability |
HIGH 7.5 | — | Windows SMB Server Elevation of Privilege Vulnerability | |
|
CVE-2025-59502
Remote Procedure Call Denial of Service Vulnerability |
MEDIUM 7.5 | — | Remote Procedure Call Denial of Service Vulnerability | |
|
CVE-2025-53805
HTTP.sys Denial of Service Vulnerability |
HIGH 7.5 | — | HTTP.sys Denial of Service Vulnerability | |
|
CVE-2025-54919
Windows Graphics Component Remote Code Execution Vulnerability |
HIGH 7.5 | — | Windows Graphics Component Remote Code Execution Vulnerability | |
|
CVE-2025-50169
Windows SMB Remote Code Execution Vulnerability |
HIGH 7.5 | — | Windows SMB Remote Code Execution Vulnerability | |
|
CVE-2025-53722
Windows Remote Desktop Services Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Remote Desktop Services Denial of Service Vulnerability | |
|
CVE-2025-55231
Windows Storage-based Management Service Remote Code Execution Vulnerability |
HIGH 7.5 | — | Windows Storage-based Management Service Remote Code Execution Vulnerability | |
|
CVE-2025-47984
Windows GDI Information Disclosure Vulnerability |
HIGH 7.5 | — | Windows GDI Information Disclosure Vulnerability | |
|
CVE-2025-48814
Remote Desktop Licensing Service Security Feature Bypass Vulnerability |
HIGH 7.5 | — | Remote Desktop Licensing Service Security Feature Bypass Vulnerability | |
|
CVE-2025-32724
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | |
|
CVE-2025-32725
DHCP Server Service Denial of Service Vulnerability |
HIGH 7.5 | — | DHCP Server Service Denial of Service Vulnerability | |
|
CVE-2025-33050
DHCP Server Service Denial of Service Vulnerability |
HIGH 7.5 | — | DHCP Server Service Denial of Service Vulnerability | |
|
CVE-2025-33056
Windows Local Security Authority (LSA) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Local Security Authority (LSA) Denial of Service Vulnerability | |
|
CVE-2025-33068
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | |
|
CVE-2025-26677
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | |
|
CVE-2025-29831
Windows Remote Desktop Services Remote Code Execution Vulnerability |
HIGH 7.5 | — | Windows Remote Desktop Services Remote Code Execution Vulnerability | |
|
CVE-2025-29842
UrlMon Security Feature Bypass Vulnerability |
HIGH 7.5 | — | UrlMon Security Feature Bypass Vulnerability | |
|
CVE-2025-29969
MS-EVEN RPC Remote Code Execution Vulnerability |
HIGH 7.5 | — | MS-EVEN RPC Remote Code Execution Vulnerability | |
|
CVE-2025-26687
Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. |
HIGH 7.5 | — | Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. | |
|
CVE-2025-21174
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | |
|
CVE-2025-26641
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-26652
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | |
|
CVE-2025-26668
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 7.5 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-26673
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | |
|
CVE-2025-26680
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | |
|
CVE-2025-26686
Windows TCP/IP Remote Code Execution Vulnerability |
CRITICAL 7.5 | — | Windows TCP/IP Remote Code Execution Vulnerability | |
|
CVE-2025-27469
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | |
|
CVE-2025-27470
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | |
|
CVE-2025-27473
HTTP.sys Denial of Service Vulnerability |
HIGH 7.5 | — | HTTP.sys Denial of Service Vulnerability | |
|
CVE-2025-27479
Kerberos Key Distribution Proxy Service Denial of Service Vulnerability |
HIGH 7.5 | — | Kerberos Key Distribution Proxy Service Denial of Service Vulnerability | |
|
CVE-2025-27484
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability |
HIGH 7.5 | — | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability | |
|
CVE-2025-27485
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | |
|
CVE-2025-27486
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | |
|
CVE-2025-29810
Active Directory Domain Services Elevation of Privilege Vulnerability |
HIGH 7.5 | — | Active Directory Domain Services Elevation of Privilege Vulnerability | |
|
CVE-2025-26634
Windows Core Messaging Elevation of Privileges Vulnerability |
HIGH 7.5 | — | Windows Core Messaging Elevation of Privileges Vulnerability | |
|
CVE-2025-21181
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-21351
Windows Active Directory Domain Services API Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Active Directory Domain Services API Denial of Service Vulnerability | |
|
CVE-2025-21207
Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability | |
|
CVE-2025-21218
Windows Kerberos Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Kerberos Denial of Service Vulnerability | |
|
CVE-2025-21220
Microsoft Message Queuing Information Disclosure Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing Information Disclosure Vulnerability | |
|
CVE-2025-21230
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-21231
IP Helper Denial of Service Vulnerability |
HIGH 7.5 | — | IP Helper Denial of Service Vulnerability | |
|
CVE-2025-21251
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-21270
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-21276
Windows MapUrlToZone Denial of Service Vulnerability |
HIGH 7.5 | — | Windows MapUrlToZone Denial of Service Vulnerability | |
|
CVE-2025-21277
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-21285
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-21289
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-21290
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2025-21296
BranchCache Remote Code Execution Vulnerability |
CRITICAL 7.5 | — | BranchCache Remote Code Execution Vulnerability | |
|
CVE-2025-21300
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability | |
|
CVE-2025-21330
Windows Remote Desktop Services Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Remote Desktop Services Denial of Service Vulnerability | |
|
CVE-2025-21389
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability | |
|
CVE-2024-49075
Windows Remote Desktop Services Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Remote Desktop Services Denial of Service Vulnerability | |
|
CVE-2024-49096
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
HIGH 7.5 | — | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
|
CVE-2024-49113
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | |
|
CVE-2024-49121
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | |
|
CVE-2024-49129
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
HIGH 7.5 | — | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | |
|
CVE-2024-43450
Windows DNS Spoofing Vulnerability |
HIGH 7.5 | — | Windows DNS Spoofing Vulnerability | |
|
CVE-2024-43452
Windows Registry Elevation of Privilege Vulnerability |
HIGH 7.5 | — | Windows Registry Elevation of Privilege Vulnerability | |
|
CVE-2024-43642
Windows SMB Denial of Service Vulnerability |
HIGH 7.5 | — | Windows SMB Denial of Service Vulnerability | |
|
CVE-2024-30098
Windows Cryptographic Services Security Feature Bypass Vulnerability |
HIGH 7.5 | — | Windows Cryptographic Services Security Feature Bypass Vulnerability | |
|
CVE-2026-54127
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. |
HIGH 7.4 | — | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-40413
Windows TCP/IP Denial of Service Vulnerability |
HIGH 7.4 | — | Windows TCP/IP Denial of Service Vulnerability | |
|
CVE-2026-40414
Windows TCP/IP Denial of Service Vulnerability |
HIGH 7.4 | — | Windows TCP/IP Denial of Service Vulnerability | |
|
CVE-2026-32156
Windows UPnP Device Host Remote Code Execution Vulnerability |
HIGH 7.4 | — | Windows UPnP Device Host Remote Code Execution Vulnerability | |
|
CVE-2026-25167
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2026-20844
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. |
HIGH 7.4 | — | Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2025-48004
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-55335
Windows NTFS Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows NTFS Elevation of Privilege Vulnerability | |
|
CVE-2025-55687
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | |
|
CVE-2025-55693
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-59189
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-59206
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | |
|
CVE-2025-59210
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | |
|
CVE-2025-54103
Windows Management Service Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows Management Service Elevation of Privilege Vulnerability | |
|
CVE-2025-49690
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | |
|
CVE-2025-29838
Windows ExecutionContext Driver Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows ExecutionContext Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-21182
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | |
|
CVE-2025-21183
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
HIGH 7.4 | — | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | |
|
CVE-2026-50482
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.3 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-58640
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.3 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-49789
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.3 | — | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49790
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | |
|
CVE-2026-32149
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH 7.3 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2026-21244
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH 7.3 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2026-21247
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH 7.3 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2026-21248
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH 7.3 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2025-62565
Windows File Explorer Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Windows File Explorer Elevation of Privilege Vulnerability | |
|
CVE-2025-25004
PowerShell Elevation of Privilege Vulnerability |
HIGH 7.3 | — | PowerShell Elevation of Privilege Vulnerability | |
|
CVE-2025-54116
Windows MultiPoint Services Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Windows MultiPoint Services Elevation of Privilege Vulnerability | |
|
CVE-2025-54911
Windows BitLocker Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Windows BitLocker Elevation of Privilege Vulnerability | |
|
CVE-2025-55236
Graphics Kernel Remote Code Execution Vulnerability |
CRITICAL 7.3 | — | Graphics Kernel Remote Code Execution Vulnerability | |
|
CVE-2025-50159
Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability | |
|
CVE-2025-50161
Win32k Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2025-49680
Windows Performance Recorder (WPR) Denial of Service Vulnerability |
HIGH 7.3 | — | Windows Performance Recorder (WPR) Denial of Service Vulnerability | |
|
CVE-2025-49682
Windows Media Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Windows Media Elevation of Privilege Vulnerability | |
|
CVE-2025-32721
Windows Recovery Driver Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Windows Recovery Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-24076
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
HIGH 7.3 | — | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | |
|
CVE-2024-49107
WmsRepair Service Elevation of Privilege Vulnerability |
HIGH 7.3 | — | WmsRepair Service Elevation of Privilege Vulnerability | |
|
CVE-2025-53779
Windows Kerberos Elevation of Privilege Vulnerability |
MEDIUM 7.2 | — | Windows Kerberos Elevation of Privilege Vulnerability | |
|
CVE-2025-49666
Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability |
HIGH 7.2 | — | Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability | |
|
CVE-2024-49089
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 7.2 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2024-49091
Windows Domain Name Service Remote Code Execution Vulnerability |
HIGH 7.2 | — | Windows Domain Name Service Remote Code Execution Vulnerability | |
|
CVE-2026-50682
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. |
HIGH 7.1 | — | Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. | |
|
CVE-2026-50465
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
HIGH 7.1 | — | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-50451
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized a… |
HIGH 7.1 | — | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-55144
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. |
HIGH 7.1 | — | Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-50354
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.1 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49791
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allo… |
HIGH 7.1 | — | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri… | |
|
CVE-2026-49165
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information loca… |
HIGH 7.1 | — | Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally. | |
|
CVE-2026-47288
Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent netwo… |
HIGH 7.1 | — | Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. | |
|
CVE-2026-40401
Windows TCP/IP Denial of Service Vulnerability |
HIGH 7.1 | — | Windows TCP/IP Denial of Service Vulnerability | |
|
CVE-2026-26151
Remote Desktop Spoofing Vulnerability |
HIGH 7.1 | — | Remote Desktop Spoofing Vulnerability | |
|
CVE-2025-62570
Windows Camera Frame Server Monitor Information Disclosure Vulnerability |
HIGH 7.1 | — | Windows Camera Frame Server Monitor Information Disclosure Vulnerability | |
|
CVE-2025-64720
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication |
HIGH 7.1 | — | LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication | |
|
CVE-2025-65018
LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` |
HIGH 7.1 | — | LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` | |
|
CVE-2025-59208
Windows MapUrlToZone Information Disclosure Vulnerability |
HIGH 7.1 | — | Windows MapUrlToZone Information Disclosure Vulnerability | |
|
CVE-2025-48819
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability |
HIGH 7.1 | — | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability | |
|
CVE-2025-48821
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability |
HIGH 7.1 | — | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability | |
|
CVE-2025-27491
Windows Hyper-V Remote Code Execution Vulnerability |
CRITICAL 7.1 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2025-29809
Windows Kerberos Security Feature Bypass Vulnerability |
HIGH 7.1 | — | Windows Kerberos Security Feature Bypass Vulnerability | |
|
CVE-2025-25008
Windows Server Elevation of Privilege Vulnerability |
HIGH 7.1 | — | Windows Server Elevation of Privilege Vulnerability | |
|
CVE-2025-21379
DHCP Client Service Remote Code Execution Vulnerability |
CRITICAL 7.1 | — | DHCP Client Service Remote Code Execution Vulnerability | |
|
CVE-2025-21419
Windows Setup Files Cleanup Elevation of Privilege Vulnerability |
HIGH 7.1 | — | Windows Setup Files Cleanup Elevation of Privilege Vulnerability | |
|
CVE-2025-21299
Windows Kerberos Security Feature Bypass Vulnerability |
HIGH 7.1 | — | Windows Kerberos Security Feature Bypass Vulnerability | |
|
CVE-2026-58629
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58637
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58619
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58544
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-57093
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56173
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50672
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50674
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50669
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Servic… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… | |
|
CVE-2026-50503
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50490
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50491
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50459
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-50449
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50452
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… | |
|
CVE-2026-50410
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50403
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50392
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50393
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50396
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50397
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50390
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevat… |
HIGH 7.0 | — | Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50371
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an … |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privilege… | |
|
CVE-2026-50372
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50359
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50358
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50345
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50348
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… | |
|
CVE-2026-50322
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… | |
|
CVE-2026-50307
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-58526
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54996
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-54989
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privi… |
HIGH 7.0 | — | Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54129
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54111
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-50384
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service all… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate pr… | |
|
CVE-2026-50356
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App St… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele… | |
|
CVE-2026-50323
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50325
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50297
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49806
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-50296
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49802
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-49803
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment … |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to… | |
|
CVE-2026-49805
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49183
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevat… | |
|
CVE-2026-49784
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App St… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele… | |
|
CVE-2026-48571
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-48572
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer al… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p… | |
|
CVE-2026-49162
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-47648
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45653
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45640
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45598
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functi… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… | |
|
CVE-2026-45601
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functi… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… | |
|
CVE-2026-45603
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functi… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… | |
|
CVE-2026-45596
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-45597
Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (u… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized atta… | |
|
CVE-2026-42984
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42911
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42912
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Servic… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… | |
|
CVE-2026-42836
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servi… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized atta… | |
|
CVE-2026-41108
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-34335
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2025-54518
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker t… |
HIGH 7.0 | — | Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a dif… | |
|
CVE-2026-35416
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows a… |
HIGH 7.0 | — | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… | |
|
CVE-2026-34345
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows a… |
HIGH 7.0 | — | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… | |
|
CVE-2026-33839
Win32k Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2026-34331
Win32k Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2026-34340
Windows Projected File System Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Projected File System Elevation of Privilege Vulnerability | |
|
CVE-2026-34341
Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability | |
|
CVE-2026-34342
Windows Print Spooler Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Print Spooler Elevation of Privilege Vulnerability | |
|
CVE-2026-34347
Windows Win32k Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Win32k Elevation of Privilege Vulnerability | |
|
CVE-2026-40410
Windows SMB Client Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows SMB Client Elevation of Privilege Vulnerability | |
|
CVE-2026-42825
Windows Telephony Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Telephony Service Elevation of Privilege Vulnerability | |
|
CVE-2026-33104
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX al… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p… | |
|
CVE-2026-33100
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-25184
Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability | |
|
CVE-2026-26152
Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | |
|
CVE-2026-26165
Windows Shell Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Shell Elevation of Privilege Vulnerability | |
|
CVE-2026-26166
Windows Shell Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Shell Elevation of Privilege Vulnerability | |
|
CVE-2026-26173
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-26174
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | |
|
CVE-2026-26177
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-26182
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-27908
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability | |
|
CVE-2026-27917
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability | |
|
CVE-2026-27921
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability | |
|
CVE-2026-27922
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-27926
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-27929
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-32068
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | |
|
CVE-2026-32070
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-32073
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-32075
Windows UPnP Device Host Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
|
CVE-2026-32080
Windows WalletService Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows WalletService Elevation of Privilege Vulnerability | |
|
CVE-2026-32082
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | |
|
CVE-2026-32083
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | |
|
CVE-2026-32086
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | |
|
CVE-2026-32087
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | |
|
CVE-2026-32093
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | |
|
CVE-2026-32150
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | |
|
CVE-2026-32219
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2026-24285
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-23671
Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-24295
Windows Device Association Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Device Association Service Elevation of Privilege Vulnerability | |
|
CVE-2026-24296
Windows Device Association Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Device Association Service Elevation of Privilege Vulnerability | |
|
CVE-2026-25170
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2026-25171
Windows Authentication Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Authentication Elevation of Privilege Vulnerability | |
|
CVE-2026-25178
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-25179
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-21234
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2026-21237
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Subsystem for Linux Elevation of Privilege Vulnerability | |
|
CVE-2026-21241
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2026-21242
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Subsystem for Linux Elevation of Privilege Vulnerability | |
|
CVE-2026-21253
Mailslot File System Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Mailslot File System Elevation of Privilege Vulnerability | |
|
CVE-2026-21508
Windows Storage Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Storage Elevation of Privilege Vulnerability | |
|
CVE-2026-21221
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Manage… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz… | |
|
CVE-2026-20869
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Ma… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacke… | |
|
CVE-2026-20863
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20842
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-20836
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile… | |
|
CVE-2026-20814
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows a… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile… | |
|
CVE-2026-20815
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Manage… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz… | |
|
CVE-2026-20808
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Obje… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elev… | |
|
CVE-2026-20830
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | |
|
CVE-2025-54957
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
HIGH 7.0 | — | Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. | |
|
CVE-2025-62469
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-62569
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-62573
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | DirectX Graphics Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-59506
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | DirectX Graphics Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-59507
Windows Speech Runtime Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Speech Runtime Elevation of Privilege Vulnerability | |
|
CVE-2025-59508
Windows Speech Recognition Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Speech Recognition Elevation of Privilege Vulnerability | |
|
CVE-2025-59515
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Broadcast DVR User Service Elevation of Privilege Vulnerability | |
|
CVE-2025-60716
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
CRITICAL 7.0 | — | DirectX Graphics Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-60717
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Broadcast DVR User Service Elevation of Privilege Vulnerability | |
|
CVE-2025-60719
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-62213
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-62217
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-50174
Windows Device Association Broker Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Device Association Broker Service Elevation of Privilege Vulnerability | |
|
CVE-2025-55331
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-55340
Windows Remote Desktop Protocol Security Feature Bypass |
HIGH 7.0 | — | Windows Remote Desktop Protocol Security Feature Bypass | |
|
CVE-2025-55678
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | DirectX Graphics Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-55681
Desktop Window Manager Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Desktop Window Manager Elevation of Privilege Vulnerability | |
|
CVE-2025-55684
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-55685
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-55686
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-55688
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-55689
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-55690
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-55691
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2025-58725
Windows COM+ Event System Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows COM+ Event System Service Elevation of Privilege Vulnerability | |
|
CVE-2025-58727
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2025-58730
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-58731
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-58732
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-58733
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-58734
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-58735
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-58736
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-58737
Remote Desktop Protocol Remote Code Execution Vulnerability |
HIGH 7.0 | — | Remote Desktop Protocol Remote Code Execution Vulnerability | |
|
CVE-2025-58738
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-59193
Windows Management Services Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Management Services Elevation of Privilege Vulnerability | |
|
CVE-2025-59194
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-59195
Windows Graphics Component Denial of Service Vulnerability |
HIGH 7.0 | — | Windows Graphics Component Denial of Service Vulnerability | |
|
CVE-2025-59196
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | |
|
CVE-2025-59202
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Remote Desktop Services Elevation of Privilege Vulnerability | |
|
CVE-2025-59205
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-59261
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-59282
Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability |
HIGH 7.0 | — | Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | |
|
CVE-2025-59289
Windows Bluetooth Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Bluetooth Service Elevation of Privilege Vulnerability | |
|
CVE-2025-49734
PowerShell Direct Elevation of Privilege Vulnerability |
HIGH 7.0 | — | PowerShell Direct Elevation of Privilege Vulnerability | |
|
CVE-2025-53802
Windows Bluetooth Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Bluetooth Service Elevation of Privilege Vulnerability | |
|
CVE-2025-53807
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-54093
Windows TCP/IP Driver Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows TCP/IP Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-54099
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-54105
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-54108
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | |
|
CVE-2025-54112
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | |
|
CVE-2025-54114
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2025-54115
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-55223
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | DirectX Graphics Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-59215
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-59216
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-59220
Windows Bluetooth Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Bluetooth Service Elevation of Privilege Vulnerability | |
|
CVE-2025-49762
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-50158
Windows NTFS Information Disclosure Vulnerability |
HIGH 7.0 | — | Windows NTFS Information Disclosure Vulnerability | |
|
CVE-2025-50167
Windows Hyper-V Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Hyper-V Elevation of Privilege Vulnerability | |
|
CVE-2025-53134
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-53135
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | DirectX Graphics Kernel Elevation of Privilege Vulnerability | |
|
CVE-2025-53137
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-53140
Windows Kernel Transaction Manager Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Kernel Transaction Manager Elevation of Privilege Vulnerability | |
|
CVE-2025-53142
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Microsoft Brokering File System Elevation of Privilege Vulnerability | |
|
CVE-2025-53147
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-53718
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
|
CVE-2025-53721
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2025-47975
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | |
|
CVE-2025-49678
NTFS Elevation of Privilege Vulnerability |
HIGH 7.0 | — | NTFS Elevation of Privilege Vulnerability | |
|
CVE-2025-49727
Win32k Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2025-49744
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-27468
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-29841
Universal Print Management Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Universal Print Management Service Elevation of Privilege Vulnerability | |
|
CVE-2025-21191
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | |
|
CVE-2025-26640
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-26649
Windows Secure Channel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Secure Channel Elevation of Privilege Vulnerability | |
|
CVE-2025-26665
Windows upnphost.dll Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows upnphost.dll Elevation of Privilege Vulnerability | |
|
CVE-2025-27478
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | |
|
CVE-2025-27492
Windows Secure Channel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Secure Channel Elevation of Privilege Vulnerability | |
|
CVE-2025-27732
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-21184
Windows Core Messaging Elevation of Privileges Vulnerability |
HIGH 7.0 | — | Windows Core Messaging Elevation of Privileges Vulnerability | |
|
CVE-2025-21414
Windows Core Messaging Elevation of Privileges Vulnerability |
HIGH 7.0 | — | Windows Core Messaging Elevation of Privileges Vulnerability | |
|
CVE-2024-49084
Windows Kernel Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Kernel Elevation of Privilege Vulnerability | |
|
CVE-2024-49095
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2024-49097
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | |
|
CVE-2020-17103
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-58528
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informa… |
MEDIUM 6.8 | — | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | |
|
CVE-2026-50668
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. |
MEDIUM 6.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-50492
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with… |
MEDIUM 6.8 | — | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. | |
|
CVE-2026-50426
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. |
MEDIUM 6.8 | — | Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. | |
|
CVE-2026-50298
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a ph… |
MEDIUM 6.8 | — | Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-50299
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a … |
MEDIUM 6.8 | — | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. | |
|
CVE-2026-49168
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges w… |
MEDIUM 6.8 | — | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-50507
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security … |
MEDIUM 6.8 | — | Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | |
|
CVE-2026-45608
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. |
MEDIUM 6.8 | — | Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-45585
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey".… |
MEDIUM 6.8 | — | Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerabi… | |
|
CVE-2026-32223
Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a phy… |
MEDIUM 6.8 | — | Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2025-49751
Windows Hyper-V Denial of Service Vulnerability |
HIGH 6.8 | — | Windows Hyper-V Denial of Service Vulnerability | |
|
CVE-2025-47999
Windows Hyper-V Denial of Service Vulnerability |
HIGH 6.8 | — | Windows Hyper-V Denial of Service Vulnerability | |
|
CVE-2025-48001
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.8 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-48003
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.8 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-48800
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.8 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-48804
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.8 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-48818
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.8 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-26637
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.8 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-21349
Windows Remote Desktop Configuration Service Tampering Vulnerability |
HIGH 6.8 | — | Windows Remote Desktop Configuration Service Tampering Vulnerability | |
|
CVE-2025-21211
Secure Boot Security Feature Bypass Vulnerability |
HIGH 6.8 | — | Secure Boot Security Feature Bypass Vulnerability | |
|
CVE-2024-49073
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-49077
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-49078
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-49082
Windows File Explorer Information Disclosure Vulnerability |
HIGH 6.8 | — | Windows File Explorer Information Disclosure Vulnerability | |
|
CVE-2024-49083
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-49092
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-49110
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-43449
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-43634
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-43637
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-43638
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | |
|
CVE-2024-43643
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
HIGH 6.8 | — | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | |
|
CVE-2026-32170
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-21530
Windows Rich Text Edit Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Rich Text Edit Elevation of Privilege Vulnerability | |
|
CVE-2026-41097
Secure Boot Security Feature Bypass Vulnerability |
HIGH 6.7 | — | Secure Boot Security Feature Bypass Vulnerability | |
|
CVE-2026-20876
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elev… |
MEDIUM 6.7 | — | Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | |
|
CVE-2025-53808
Windows Defender Firewall Service Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Defender Firewall Service Elevation of Privilege Vulnerability | |
|
CVE-2025-53810
Windows Defender Firewall Service Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Defender Firewall Service Elevation of Privilege Vulnerability | |
|
CVE-2025-54094
Windows Defender Firewall Service Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Defender Firewall Service Elevation of Privilege Vulnerability | |
|
CVE-2025-54104
Windows Defender Firewall Service Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Defender Firewall Service Elevation of Privilege Vulnerability | |
|
CVE-2025-54109
Windows Defender Firewall Service Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Defender Firewall Service Elevation of Privilege Vulnerability | |
|
CVE-2025-54915
Windows Defender Firewall Service Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Defender Firewall Service Elevation of Privilege Vulnerability | |
|
CVE-2025-55226
Graphics Kernel Remote Code Execution Vulnerability |
CRITICAL 6.7 | — | Graphics Kernel Remote Code Execution Vulnerability | |
|
CVE-2025-48807
Windows Hyper-V Remote Code Execution Vulnerability |
CRITICAL 6.7 | — | Windows Hyper-V Remote Code Execution Vulnerability | |
|
CVE-2025-49743
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Graphics Component Elevation of Privilege Vulnerability | |
|
CVE-2025-48803
Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability | |
|
CVE-2025-48811
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | |
|
CVE-2025-3052
Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass |
HIGH 6.7 | — | Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass | |
|
CVE-2025-26681
Win32k Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Win32k Elevation of Privilege Vulnerability | |
|
CVE-2024-7344
Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot Bypass |
HIGH 6.7 | — | Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot Bypass | |
|
CVE-2024-43631
Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | |
|
CVE-2024-43646
Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
HIGH 6.7 | — | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | |
|
CVE-2023-24932
Secure Boot Security Feature Bypass Vulnerability |
HIGH 6.7 | — | Secure Boot Security Feature Bypass Vulnerability | |
|
CVE-2026-49804
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a phy… |
MEDIUM 6.6 | — | Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2025-2884
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack… |
MEDIUM 6.6 | — | TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with… | |
|
CVE-2025-24987
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-24988
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | |
|
CVE-2025-21226
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21227
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21228
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21229
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21232
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21249
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21255
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21256
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21258
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21260
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21261
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21263
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21265
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21310
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21324
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21327
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2025-21341
Windows Digital Media Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Windows Digital Media Elevation of Privilege Vulnerability | |
|
CVE-2024-49081
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | |
|
CVE-2024-49094
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | |
|
CVE-2024-49101
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | |
|
CVE-2024-49109
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | |
|
CVE-2024-49111
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability |
HIGH 6.6 | — | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | |
|
CVE-2026-58546
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-58539
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-58533
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-58535
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-57982
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. | |
|
CVE-2026-56168
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. |
MEDIUM 6.5 | — | Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. | |
|
CVE-2026-54126
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50504
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50497
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netw… |
MEDIUM 6.5 | — | Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50445
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50376
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-50366
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a netwo… |
MEDIUM 6.5 | — | Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. | |
|
CVE-2026-57976
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a netwo… |
MEDIUM 6.5 | — | Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. | |
|
CVE-2026-57979
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-55003
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-49799
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized at… |
MEDIUM 6.5 | — | Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. | |
|
CVE-2026-34348
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information ove… |
MEDIUM 6.5 | — | Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | |
|
CVE-2026-42907
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose i… |
MEDIUM 6.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. | |
|
CVE-2026-42903
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. |
MEDIUM 6.5 | — | Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. | |
|
CVE-2026-34350
Windows Storport Miniport Driver Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Storport Miniport Driver Denial of Service Vulnerability | |
|
CVE-2026-35422
Windows TCP/IP Driver Security Feature Bypass Vulnerability |
HIGH 6.5 | — | Windows TCP/IP Driver Security Feature Bypass Vulnerability | |
|
CVE-2026-26155
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
HIGH 6.5 | — | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | |
|
CVE-2026-27925
Windows UPnP Device Host Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows UPnP Device Host Information Disclosure Vulnerability | |
|
CVE-2026-32151
Windows Shell Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Shell Information Disclosure Vulnerability | |
|
CVE-2026-20925
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a networ… |
MEDIUM 6.5 | — | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | |
|
CVE-2026-20872
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a networ… |
MEDIUM 6.5 | — | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | |
|
CVE-2026-20847
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform sp… |
MEDIUM 6.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. | |
|
CVE-2026-20812
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perf… |
MEDIUM 6.5 | — | Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. | |
|
CVE-2025-62463
DirectX Graphics Kernel Denial of Service Vulnerability |
HIGH 6.5 | — | DirectX Graphics Kernel Denial of Service Vulnerability | |
|
CVE-2025-62465
DirectX Graphics Kernel Denial of Service Vulnerability |
HIGH 6.5 | — | DirectX Graphics Kernel Denial of Service Vulnerability | |
|
CVE-2025-62473
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-64670
Windows DirectX Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows DirectX Information Disclosure Vulnerability | |
|
CVE-2025-60708
Storvsp.sys Driver Denial of Service Vulnerability |
HIGH 6.5 | — | Storvsp.sys Driver Denial of Service Vulnerability | |
|
CVE-2025-55700
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-58717
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-58729
Windows Local Session Manager (LSM) Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Local Session Manager (LSM) Denial of Service Vulnerability | |
|
CVE-2025-58739
Microsoft Windows File Explorer Spoofing Vulnerability |
HIGH 6.5 | — | Microsoft Windows File Explorer Spoofing Vulnerability | |
|
CVE-2025-59185
NTLM Hash Disclosure Spoofing Vulnerability |
HIGH 6.5 | — | NTLM Hash Disclosure Spoofing Vulnerability | |
|
CVE-2025-59214
Microsoft Windows File Explorer Spoofing Vulnerability |
HIGH 6.5 | — | Microsoft Windows File Explorer Spoofing Vulnerability | |
|
CVE-2025-59244
NTLM Hash Disclosure Spoofing Vulnerability |
HIGH 6.5 | — | NTLM Hash Disclosure Spoofing Vulnerability | |
|
CVE-2025-59257
Windows Local Session Manager (LSM) Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Local Session Manager (LSM) Denial of Service Vulnerability | |
|
CVE-2025-59259
Windows Local Session Manager (LSM) Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Local Session Manager (LSM) Denial of Service Vulnerability | |
|
CVE-2025-53796
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-53797
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-53798
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-53806
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-53809
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | |
|
CVE-2025-54095
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-54096
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-54097
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-55225
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-50154
Microsoft Windows File Explorer Spoofing Vulnerability |
HIGH 6.5 | — | Microsoft Windows File Explorer Spoofing Vulnerability | |
|
CVE-2025-50166
Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure Vulnerability | |
|
CVE-2025-50172
DirectX Graphics Kernel Denial of Service Vulnerability |
HIGH 6.5 | — | DirectX Graphics Kernel Denial of Service Vulnerability | |
|
CVE-2025-53716
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | |
|
CVE-2025-47978
Windows Kerberos Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Kerberos Denial of Service Vulnerability | |
|
CVE-2025-49670
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
|
CVE-2025-49671
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-49681
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-32715
Remote Desktop Protocol Client Information Disclosure Vulnerability |
HIGH 6.5 | — | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
|
CVE-2025-33057
Windows Local Security Authority (LSA) Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Local Security Authority (LSA) Denial of Service Vulnerability | |
|
CVE-2025-29830
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-29832
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-29835
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Remote Access Connection Manager Information Disclosure Vulnerability | |
|
CVE-2025-29836
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-29958
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-29959
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-29960
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-29961
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-21197
Windows NTFS Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows NTFS Information Disclosure Vulnerability | |
|
CVE-2025-21203
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-26651
Windows Local Session Manager (LSM) Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Local Session Manager (LSM) Denial of Service Vulnerability | |
|
CVE-2025-26664
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-26667
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-26672
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-26676
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-27474
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-27738
Windows Resilient File System (ReFS) Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Resilient File System (ReFS) Information Disclosure Vulnerability | |
|
CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability |
HIGH 6.5 | — | Microsoft Windows File Explorer Spoofing Vulnerability | |
|
CVE-2025-24996
NTLM Hash Disclosure Spoofing Vulnerability |
HIGH 6.5 | — | NTLM Hash Disclosure Spoofing Vulnerability | |
|
CVE-2025-21212
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
HIGH 6.5 | — | Internet Connection Sharing (ICS) Denial of Service Vulnerability | |
|
CVE-2025-21216
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
HIGH 6.5 | — | Internet Connection Sharing (ICS) Denial of Service Vulnerability | |
|
CVE-2025-21254
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
HIGH 6.5 | — | Internet Connection Sharing (ICS) Denial of Service Vulnerability | |
|
CVE-2025-21352
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
HIGH 6.5 | — | Internet Connection Sharing (ICS) Denial of Service Vulnerability | |
|
CVE-2025-21377
NTLM Hash Disclosure Spoofing Vulnerability |
HIGH 6.5 | — | NTLM Hash Disclosure Spoofing Vulnerability | |
|
CVE-2025-21193
Active Directory Federation Server Spoofing Vulnerability |
HIGH 6.5 | — | Active Directory Federation Server Spoofing Vulnerability | |
|
CVE-2025-21217
Windows NTLM Spoofing Vulnerability |
HIGH 6.5 | — | Windows NTLM Spoofing Vulnerability | |
|
CVE-2025-21272
Windows COM Server Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows COM Server Information Disclosure Vulnerability | |
|
CVE-2025-21288
Windows COM Server Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows COM Server Information Disclosure Vulnerability | |
|
CVE-2025-21301
Windows Geolocation Service Information Disclosure Vulnerability |
HIGH 6.5 | — | Windows Geolocation Service Information Disclosure Vulnerability | |
|
CVE-2025-21308
Windows Themes Spoofing Vulnerability |
HIGH 6.5 | — | Windows Themes Spoofing Vulnerability | |
|
CVE-2025-21313
Windows Security Account Manager (SAM) Denial of Service Vulnerability |
HIGH 6.5 | — | Windows Security Account Manager (SAM) Denial of Service Vulnerability | |
|
CVE-2025-21314
Windows SmartScreen Spoofing Vulnerability |
HIGH 6.5 | — | Windows SmartScreen Spoofing Vulnerability | |
|
CVE-2026-57097
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical att… |
MEDIUM 6.4 | — | Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. | |
|
CVE-2026-55000
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
MEDIUM 6.4 | — | Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-21265
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching e… |
MEDIUM 6.4 | — | Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affect… | |
|
CVE-2026-58543
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver… |
MEDIUM 6.3 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… | |
|
CVE-2026-50374
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a phy… |
MEDIUM 6.3 | — | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack. | |
|
CVE-2026-50375
Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.3 | — | Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2025-60723
DirectX Graphics Kernel Denial of Service Vulnerability |
HIGH 6.3 | — | DirectX Graphics Kernel Denial of Service Vulnerability | |
|
CVE-2025-48813
Virtual Secure Mode Spoofing Vulnerability |
HIGH 6.3 | — | Virtual Secure Mode Spoofing Vulnerability | |
|
CVE-2026-57095
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate… |
MEDIUM 6.2 | — | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. | |
|
CVE-2026-50420
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally. |
MEDIUM 6.2 | — | Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-49807
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclo… |
MEDIUM 6.2 | — | Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-50294
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized att… |
MEDIUM 6.2 | — | Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-40380
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability |
HIGH 6.2 | — | Windows Volume Manager Extension Driver Remote Code Execution Vulnerability | |
|
CVE-2026-32072
Active Directory Spoofing Vulnerability |
HIGH 6.2 | — | Active Directory Spoofing Vulnerability | |
|
CVE-2026-25168
Windows Graphics Component Denial of Service Vulnerability |
HIGH 6.2 | — | Windows Graphics Component Denial of Service Vulnerability | |
|
CVE-2026-25169
Windows Graphics Component Denial of Service Vulnerability |
HIGH 6.2 | — | Windows Graphics Component Denial of Service Vulnerability | |
|
CVE-2026-20851
Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose informa… |
MEDIUM 6.2 | — | Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-20821
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized atta… |
MEDIUM 6.2 | — | Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-20818
Windows Kernel Information Disclosure Vulnerability |
HIGH 6.2 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2025-59258
Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability |
HIGH 6.2 | — | Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability | |
|
CVE-2025-47980
Windows Imaging Component Information Disclosure Vulnerability |
CRITICAL 6.2 | — | Windows Imaging Component Information Disclosure Vulnerability | |
|
CVE-2025-29955
Windows Hyper-V Denial of Service Vulnerability |
HIGH 6.2 | — | Windows Hyper-V Denial of Service Vulnerability | |
|
CVE-2025-29957
Windows Deployment Services Denial of Service Vulnerability |
HIGH 6.2 | — | Windows Deployment Services Denial of Service Vulnerability | |
|
CVE-2025-21278
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
HIGH 6.2 | — | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | |
|
CVE-2024-38203
Windows Package Library Manager Information Disclosure Vulnerability |
HIGH 6.2 | — | Windows Package Library Manager Information Disclosure Vulnerability | |
|
CVE-2026-50661
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a p… |
MEDIUM 6.1 | — | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | |
|
CVE-2026-50495
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
MEDIUM 6.1 | — | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-50453
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informa… |
MEDIUM 6.1 | — | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | |
|
CVE-2026-50383
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
MEDIUM 6.1 | — | Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | |
|
CVE-2026-49174
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tamperin… |
MEDIUM 6.1 | — | Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-26169
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 6.1 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2026-32088
Windows Biometric Service Security Feature Bypass Vulnerability |
HIGH 6.1 | — | Windows Biometric Service Security Feature Bypass Vulnerability | |
|
CVE-2025-55330
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.1 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-55332
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.1 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-55333
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.1 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-55337
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.1 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-55338
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.1 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-55682
Windows BitLocker Security Feature Bypass Vulnerability |
HIGH 6.1 | — | Windows BitLocker Security Feature Bypass Vulnerability | |
|
CVE-2025-21202
Windows Recovery Environment Agent Elevation of Privilege Vulnerability |
HIGH 6.1 | — | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | |
|
CVE-2026-58638
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. |
MEDIUM 6.0 | — | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-25250
MITRE: CVE-2026-25250 Secure Boot disable Eazy Fix |
HIGH 6.0 | — | MITRE: CVE-2026-25250 Secure Boot disable Eazy Fix | |
|
CVE-2025-27735
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
HIGH 6.0 | — | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | |
|
CVE-2025-21347
Windows Deployment Services Denial of Service Vulnerability |
HIGH 6.0 | — | Windows Deployment Services Denial of Service Vulnerability | |
|
CVE-2026-56649
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File Sys… |
MEDIUM 5.9 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to e… | |
|
CVE-2026-50324
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauth… |
MEDIUM 5.9 | — | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n… | |
|
CVE-2025-48823
Windows Cryptographic Services Information Disclosure Vulnerability |
HIGH 5.9 | — | Windows Cryptographic Services Information Disclosure Vulnerability | |
|
CVE-2025-30394
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
HIGH 5.9 | — | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | |
|
CVE-2025-27471
Microsoft Streaming Service Denial of Service Vulnerability |
HIGH 5.9 | — | Microsoft Streaming Service Denial of Service Vulnerability | |
|
CVE-2025-21350
Windows Kerberos Denial of Service Vulnerability |
HIGH 5.9 | — | Windows Kerberos Denial of Service Vulnerability | |
|
CVE-2025-21225
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
HIGH 5.9 | — | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | |
|
CVE-2025-21242
Windows Kerberos Information Disclosure Vulnerability |
HIGH 5.9 | — | Windows Kerberos Information Disclosure Vulnerability | |
|
CVE-2024-38264
Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability |
HIGH 5.9 | — | Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability | |
|
CVE-2026-23670
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
HIGH 5.7 | — | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | |
|
CVE-2025-50156
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 5.7 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-50157
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 5.7 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-53138
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 5.7 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-53148
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 5.7 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-53153
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 5.7 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-53719
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
HIGH 5.7 | — | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | |
|
CVE-2025-48002
Windows Hyper-V Information Disclosure Vulnerability |
HIGH 5.7 | — | Windows Hyper-V Information Disclosure Vulnerability | |
|
CVE-2025-49722
Windows Print Spooler Denial of Service Vulnerability |
HIGH 5.7 | — | Windows Print Spooler Denial of Service Vulnerability | |
|
CVE-2025-29974
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.7 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2024-36350
AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue |
CRITICAL 5.6 | — | AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue | |
|
CVE-2024-36357
AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue |
CRITICAL 5.6 | — | AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue | |
|
CVE-2025-21336
Windows Cryptographic Information Disclosure Vulnerability |
HIGH 5.6 | — | Windows Cryptographic Information Disclosure Vulnerability | |
|
CVE-2026-58545
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
MEDIUM 5.5 | — | Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-58547
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges lo… |
MEDIUM 5.5 | — | Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-57083
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informati… |
MEDIUM 5.5 | — | Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-57084
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-57085
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | |
|
CVE-2026-56184
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50690
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50681
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attac… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50483
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacke… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50475
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50473
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50455
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose informati… |
MEDIUM 5.5 | — | Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50456
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50442
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50434
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50437
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50430
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50431
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability |
MEDIUM 5.5 | — | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability | |
|
CVE-2026-50409
Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to d… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50401
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information loca… |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50394
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose i… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50389
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50377
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50352
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attac… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50339
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50341
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50334
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to dis… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. | |
|
CVE-2026-49177
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. | |
|
CVE-2026-58614
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-54997
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50381
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorize… |
MEDIUM 5.5 | — | Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information local… | |
|
CVE-2026-50350
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an author… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information lo… | |
|
CVE-2026-50316
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose informatio… |
MEDIUM 5.5 | — | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50300
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50303
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypa… |
MEDIUM 5.5 | — | Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-50295
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature local… |
MEDIUM 5.5 | — | Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-49801
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | |
|
CVE-2026-49180
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authoriz… |
MEDIUM 5.5 | — | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca… | |
|
CVE-2026-40422
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-41087
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-33842
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-34328
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. | |
|
CVE-2026-34346
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized a… |
MEDIUM 5.5 | — | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | |
|
CVE-2026-34349
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose i… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | |
|
CVE-2026-48566
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | |
|
CVE-2026-45604
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat… |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. | |
|
CVE-2026-45606
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. | |
|
CVE-2026-45634
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. | |
|
CVE-2026-45594
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat… | |
|
CVE-2026-44805
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. |
MEDIUM 5.5 | — | Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. | |
|
CVE-2026-42973
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-42968
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. | |
|
CVE-2026-42969
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information local… |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-42970
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-42971
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker … |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | |
|
CVE-2026-42972
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. | |
|
CVE-2026-42915
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. |
MEDIUM 5.5 | — | Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. | |
|
CVE-2026-42906
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose i… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. | |
|
CVE-2026-34339
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
HIGH 5.5 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | |
|
CVE-2026-35419
Windows DWM Core Library Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows DWM Core Library Information Disclosure Vulnerability | |
|
CVE-2026-20806
Windows COM Server Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows COM Server Information Disclosure Vulnerability | |
|
CVE-2026-27930
Windows GDI Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows GDI Information Disclosure Vulnerability | |
|
CVE-2026-27931
Windows GDI Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows GDI Information Disclosure Vulnerability | |
|
CVE-2026-32079
Web Account Manager Information Disclosure Vulnerability |
HIGH 5.5 | — | Web Account Manager Information Disclosure Vulnerability | |
|
CVE-2026-32081
Package Catalog Information Disclosure Vulnerability |
HIGH 5.5 | — | Package Catalog Information Disclosure Vulnerability | |
|
CVE-2026-32084
Windows Print Spooler Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Print Spooler Information Disclosure Vulnerability | |
|
CVE-2026-32085
Remote Procedure Call Information Disclosure Vulnerability |
HIGH 5.5 | — | Remote Procedure Call Information Disclosure Vulnerability | |
|
CVE-2026-32181
Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
HIGH 5.5 | — | Connected User Experiences and Telemetry Service Denial of Service Vulnerability | |
|
CVE-2026-32212
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
HIGH 5.5 | — | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | |
|
CVE-2026-32214
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
HIGH 5.5 | — | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | |
|
CVE-2026-32215
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2026-32217
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2026-32218
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2026-25180
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
HIGH 5.5 | — | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. | |
|
CVE-2026-25186
Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability | |
|
CVE-2026-21222
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2026-20939
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20932
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20937
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20862
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20838
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclos… |
MEDIUM 5.5 | — | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20839
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose informat… |
MEDIUM 5.5 | — | Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20835
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose informati… |
MEDIUM 5.5 | — | Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20827
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows a… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose inform… | |
|
CVE-2026-20829
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20823
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20824
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature … |
MEDIUM 5.5 | — | Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. | |
|
CVE-2026-20833
Windows Kerberos Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kerberos Information Disclosure Vulnerability | |
|
CVE-2025-62468
Windows Defender Firewall Service Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Defender Firewall Service Information Disclosure Vulnerability | |
|
CVE-2025-59509
Windows Speech Recognition Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Speech Recognition Information Disclosure Vulnerability | |
|
CVE-2025-59510
Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability |
HIGH 5.5 | — | Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability | |
|
CVE-2025-59513
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability | |
|
CVE-2025-60706
Windows Hyper-V Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Hyper-V Information Disclosure Vulnerability | |
|
CVE-2025-62208
Windows License Manager Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows License Manager Information Disclosure Vulnerability | |
|
CVE-2025-62209
Windows License Manager Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows License Manager Information Disclosure Vulnerability | |
|
CVE-2025-47979
Microsoft Failover Cluster Information Disclosure Vulnerability |
HIGH 5.5 | — | Microsoft Failover Cluster Information Disclosure Vulnerability | |
|
CVE-2025-55325
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-55336
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | |
|
CVE-2025-55676
Windows USB Video Class System Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows USB Video Class System Driver Information Disclosure Vulnerability | |
|
CVE-2025-55683
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2025-55695
Windows WLAN AutoConfig Service Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows WLAN AutoConfig Service Information Disclosure Vulnerability | |
|
CVE-2025-55699
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2025-59184
Storage Spaces Direct Information Disclosure Vulnerability |
HIGH 5.5 | — | Storage Spaces Direct Information Disclosure Vulnerability | |
|
CVE-2025-59186
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2025-59188
Microsoft Failover Cluster Information Disclosure Vulnerability |
HIGH 5.5 | — | Microsoft Failover Cluster Information Disclosure Vulnerability | |
|
CVE-2025-59190
Windows Search Service Denial of Service Vulnerability |
HIGH 5.5 | — | Windows Search Service Denial of Service Vulnerability | |
|
CVE-2025-59197
Windows ETL Channel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows ETL Channel Information Disclosure Vulnerability | |
|
CVE-2025-59203
Windows State Repository API Server File Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows State Repository API Server File Information Disclosure Vulnerability | |
|
CVE-2025-59204
Windows Management Services Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Management Services Information Disclosure Vulnerability | |
|
CVE-2025-59209
Windows Push Notification Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Push Notification Information Disclosure Vulnerability | |
|
CVE-2025-59211
Windows Push Notification Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Push Notification Information Disclosure Vulnerability | |
|
CVE-2025-59253
Windows Search Service Denial of Service Vulnerability |
HIGH 5.5 | — | Windows Search Service Denial of Service Vulnerability | |
|
CVE-2025-59260
Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability | |
|
CVE-2025-53799
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information loca… |
CRITICAL 5.5 | — | Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | |
|
CVE-2025-53803
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2025-53804
Windows Kernel-Mode Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel-Mode Driver Information Disclosure Vulnerability | |
|
CVE-2025-53136
NT OS Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | NT OS Kernel Information Disclosure Vulnerability | |
|
CVE-2025-53156
Windows Storage Port Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Port Driver Information Disclosure Vulnerability | |
|
CVE-2025-26636
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2025-48808
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2025-48809
Windows Secure Kernel Mode Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Secure Kernel Mode Information Disclosure Vulnerability | |
|
CVE-2025-48810
Windows Secure Kernel Mode Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Secure Kernel Mode Information Disclosure Vulnerability | |
|
CVE-2025-49658
Windows Transport Driver Interface (TDI) Translation Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Transport Driver Interface (TDI) Translation Driver Information Disclosure Vulnerability | |
|
CVE-2025-49664
Windows User-Mode Driver Framework Host Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows User-Mode Driver Framework Host Information Disclosure Vulnerability | |
|
CVE-2025-49684
Windows Storage Port Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Port Driver Information Disclosure Vulnerability | |
|
CVE-2025-24065
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-24068
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-24069
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-32719
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-32720
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-32722
Windows Storage Port Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Port Driver Information Disclosure Vulnerability | |
|
CVE-2025-33052
Windows DWM Core Library Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows DWM Core Library Information Disclosure Vulnerability | |
|
CVE-2025-33055
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-33058
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-33059
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-33060
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-33061
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-33062
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-33063
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-33065
Windows Storage Management Provider Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Storage Management Provider Information Disclosure Vulnerability | |
|
CVE-2025-29829
Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability | |
|
CVE-2025-29837
Windows Installer Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Installer Information Disclosure Vulnerability | |
|
CVE-2025-27736
Windows Power Dependency Coordinator Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Power Dependency Coordinator Information Disclosure Vulnerability | |
|
CVE-2025-27742
NTFS Information Disclosure Vulnerability |
HIGH 5.5 | — | NTFS Information Disclosure Vulnerability | |
|
CVE-2025-24992
Windows NTFS Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows NTFS Information Disclosure Vulnerability | |
|
CVE-2025-21257
Windows WLAN AutoConfig Service Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows WLAN AutoConfig Service Information Disclosure Vulnerability | |
|
CVE-2025-21274
Windows Event Tracing Denial of Service Vulnerability |
HIGH 5.5 | — | Windows Event Tracing Denial of Service Vulnerability | |
|
CVE-2025-21280
Windows Virtual Trusted Platform Module Denial of Service Vulnerability |
HIGH 5.5 | — | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | |
|
CVE-2025-21284
Windows Virtual Trusted Platform Module Denial of Service Vulnerability |
HIGH 5.5 | — | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | |
|
CVE-2025-21316
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2025-21317
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2025-21318
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2025-21319
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2025-21320
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2025-21321
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2025-21323
Windows Kernel Memory Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows Kernel Memory Information Disclosure Vulnerability | |
|
CVE-2025-21340
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
HIGH 5.5 | — | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | |
|
CVE-2025-21374
Windows CSC Service Information Disclosure Vulnerability |
HIGH 5.5 | — | Windows CSC Service Information Disclosure Vulnerability | |
|
CVE-2021-45985
Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-read |
HIGH 5.5 | — | Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-read | |
|
CVE-2020-35538
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH 5.5 | — | Microsoft Security Update Guide entry — NVD enrichira. | |
|
CVE-2026-45595
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security fea… |
MEDIUM 5.4 | — | Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. | |
|
CVE-2026-35423
Windows 11 Telnet Client Information Disclosure Vulnerability |
HIGH 5.4 | — | Windows 11 Telnet Client Information Disclosure Vulnerability | |
|
CVE-2025-47160
Windows Shortcut Files Security Feature Bypass Vulnerability |
HIGH 5.4 | — | Windows Shortcut Files Security Feature Bypass Vulnerability | |
|
CVE-2025-29956
Windows SMB Information Disclosure Vulnerability |
HIGH 5.4 | — | Windows SMB Information Disclosure Vulnerability | |
|
CVE-2026-50432
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. |
MEDIUM 5.3 | — | Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. | |
|
CVE-2026-50415
Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose… |
MEDIUM 5.3 | — | Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-44806
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to… |
MEDIUM 5.3 | — | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-45655
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a p… |
MEDIUM 5.3 | — | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | |
|
CVE-2026-42914
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. |
MEDIUM 5.3 | — | Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. | |
|
CVE-2023-20585
AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability |
HIGH 5.3 | — | AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability | |
|
CVE-2026-25185
Windows Shell Link Processing Spoofing Vulnerability |
HIGH 5.3 | — | Windows Shell Link Processing Spoofing Vulnerability | |
|
CVE-2026-20927
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allow… |
MEDIUM 5.3 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service… | |
|
CVE-2025-62567
Windows Hyper-V Denial of Service Vulnerability |
HIGH 5.3 | — | Windows Hyper-V Denial of Service Vulnerability | |
|
CVE-2025-55229
Windows Certificate Spoofing Vulnerability |
HIGH 5.3 | — | Windows Certificate Spoofing Vulnerability | |
|
CVE-2026-50418
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. |
MEDIUM 5.1 | — | Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. | |
|
CVE-2025-55679
Windows Kernel Information Disclosure Vulnerability |
HIGH 5.1 | — | Windows Kernel Information Disclosure Vulnerability | |
|
CVE-2025-33069
Windows App Control for Business Security Feature Bypass Vulnerability |
HIGH 5.1 | — | Windows App Control for Business Security Feature Bypass Vulnerability | |
|
CVE-2025-26644
Windows Hello Spoofing Vulnerability |
HIGH 5.1 | — | Windows Hello Spoofing Vulnerability | |
|
CVE-2025-59198
Windows Search Service Denial of Service Vulnerability |
HIGH 5.0 | — | Windows Search Service Denial of Service Vulnerability | |
|
CVE-2026-50684
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Ser… |
MEDIUM 4.8 | — | Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attac… | |
|
CVE-2025-21179
DHCP Client Service Denial of Service Vulnerability |
HIGH 4.8 | — | DHCP Client Service Denial of Service Vulnerability | |
|
CVE-2026-50310
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information… |
MEDIUM 4.7 | — | Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50312
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
MEDIUM 4.7 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-49167
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
MEDIUM 4.7 | — | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2025-58719
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
HIGH 4.7 | — | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | |
|
CVE-2026-49794
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informa… |
MEDIUM 4.6 | — | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | |
|
CVE-2026-20928
Windows Recovery Environment Security Feature Bypass Vulnerability |
HIGH 4.6 | — | Windows Recovery Environment Security Feature Bypass Vulnerability | |
|
CVE-2026-26175
Windows Boot Manager Security Feature Bypass Vulnerability |
HIGH 4.6 | — | Windows Boot Manager Security Feature Bypass Vulnerability | |
|
CVE-2026-20834
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. |
MEDIUM 4.6 | — | Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | |
|
CVE-2026-20828
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information… |
MEDIUM 4.6 | — | Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | |
|
CVE-2025-21213
Secure Boot Security Feature Bypass Vulnerability |
HIGH 4.6 | — | Secure Boot Security Feature Bypass Vulnerability | |
|
CVE-2025-21215
Secure Boot Security Feature Bypass Vulnerability |
HIGH 4.6 | — | Secure Boot Security Feature Bypass Vulnerability | |
|
CVE-2024-49087
Windows Mobile Broadband Driver Information Disclosure Vulnerability |
HIGH 4.6 | — | Windows Mobile Broadband Driver Information Disclosure Vulnerability | |
|
CVE-2026-50485
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. |
MEDIUM 4.5 | — | Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | |
|
CVE-2026-32209
Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability |
HIGH 4.4 | — | Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability | |
|
CVE-2026-32220
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass … |
MEDIUM 4.4 | — | Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-20962
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose… |
MEDIUM 4.4 | — | Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. | |
|
CVE-2026-20825
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. |
MEDIUM 4.4 | — | Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | |
|
CVE-2025-47969
Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability |
HIGH 4.4 | — | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | |
|
CVE-2025-24997
DirectX Graphics Kernel File Denial of Service Vulnerability |
HIGH 4.4 | — | DirectX Graphics Kernel File Denial of Service Vulnerability | |
|
CVE-2026-33829
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to … |
MEDIUM 4.3 | — | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. | |
|
CVE-2026-20936
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. |
MEDIUM 4.3 | — | Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. | |
|
CVE-2025-54107
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2025-54917
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2025-21247
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2025-24055
Windows USB Video Class System Driver Information Disclosure Vulnerability |
HIGH 4.3 | — | Windows USB Video Class System Driver Information Disclosure Vulnerability | |
|
CVE-2025-21189
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2025-21219
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2025-21268
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2025-21269
Windows HTML Platforms Security Feature Bypass Vulnerability |
HIGH 4.3 | — | Windows HTML Platforms Security Feature Bypass Vulnerability | |
|
CVE-2025-21328
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2025-21329
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2025-21332
MapUrlToZone Security Feature Bypass Vulnerability |
HIGH 4.3 | — | MapUrlToZone Security Feature Bypass Vulnerability | |
|
CVE-2024-49098
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
HIGH 4.3 | — | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | |
|
CVE-2024-49099
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
HIGH 4.3 | — | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | |
|
CVE-2024-49103
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
HIGH 4.3 | — | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | |
|
CVE-2026-50302
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security … |
MEDIUM 4.2 | — | Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network. | |
|
CVE-2025-21210
Windows BitLocker Information Disclosure Vulnerability |
HIGH 4.2 | — | Windows BitLocker Information Disclosure Vulnerability | |
|
CVE-2025-21214
Windows BitLocker Information Disclosure Vulnerability |
HIGH 4.2 | — | Windows BitLocker Information Disclosure Vulnerability | |
|
CVE-2025-29839
Windows Multiple UNC Provider Driver Information Disclosure Vulnerability |
HIGH 4.0 | — | Windows Multiple UNC Provider Driver Information Disclosure Vulnerability | |
|
CVE-2026-45642
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an author… |
LOW 3.9 | — | Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a… | |
|
CVE-2025-49760
Windows Storage Spoofing Vulnerability |
MEDIUM 3.5 | — | Windows Storage Spoofing Vulnerability | |
|
CVE-2026-50419
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose … |
LOW 3.3 | — | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | |
|
CVE-2026-50416
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose … |
LOW 3.3 | — | Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | |
|
CVE-2026-21249
Windows NTLM Spoofing Vulnerability |
HIGH 3.3 | — | Windows NTLM Spoofing Vulnerability | |
|
CVE-2025-59284
Windows NTLM Spoofing Vulnerability |
HIGH 3.3 | — | Windows NTLM Spoofing Vulnerability | |
|
CVE-2025-21337
Windows NTFS Elevation of Privilege Vulnerability |
HIGH 3.3 | — | Windows NTFS Elevation of Privilege Vulnerability | |
|
CVE-2025-59280
Windows SMB Client Tampering Vulnerability |
HIGH 3.1 | — | Windows SMB Client Tampering Vulnerability | |
|
CVE-2025-59294
Windows Taskbar Live Preview Information Disclosure Vulnerability |
HIGH 2.1 | — | Windows Taskbar Live Preview Information Disclosure Vulnerability | |
|
CVE-2024-9157
Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability |
HIGH | — | Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability |