Vulnerability index

Browse CVEs

872 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Windows 11 23h2 HIGH 7.0
CVE-2026-26165

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.5020 / 10.0.22631.6936+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-23657

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
Windows 10 21h2 HIGH 7.8
CVE-2026-26132

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7058 / 10.0.19045.7058+
Fix from $1,950 2026-03-10
365 Copilot HIGH 7.8
CVE-2026-26134

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

Fix: 16.0.19822.20000+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26107

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20102+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.8
CVE-2026-25189

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-25178

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 11 23h2 HIGH 7.0
CVE-2026-25170

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4830 / 10.0.22631.6783+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-25171

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 11 24h2 HIGH 7.4
CVE-2026-25167

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.26100.7979 / 10.0.26100.32463+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.8
CVE-2026-24292

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-24295

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorize…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-24289

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
365 Copilot HIGH 7.0
CVE-2026-24285

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 8.8
CVE-2026-23669

Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-23671

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an auth…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.0
CVE-2026-23667

Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-21253

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows Server 2016 HIGH 7.8
CVE-2026-21251

Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 11 23h2 HIGH 7.0
CVE-2026-21241

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4711 / 10.0.22631.6649+
Fix from $1,950 2026-02-10
Windows 10 21h2 HIGH 7.0
CVE-2026-21242

Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6937 / 10.0.19045.6937+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21235

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 21h2 HIGH 7.0
CVE-2026-21237

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attac…

Fix: 10.0.19044.6937 / 10.0.19045.6937+
Fix from $1,950 2026-02-10
Windows Software Development Kit HIGH 7.0
CVE-2026-21219

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.26100.7463+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.0
CVE-2026-21221

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13
365 Apps HIGH 8.4
CVE-2026-20953

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-01-13
365 Apps HIGH 8.4
CVE-2026-20952

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20950

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20083+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20924

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 11 23h2 HIGH 7.8
CVE-2026-20920

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4648 / 10.0.22631.6491+
Fix from $1,950 2026-01-13