Vulnerability index

Browse CVEs

872 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Windows 10 1809 HIGH 7.0
CVE-2026-42984

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-42978

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-42979

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Remote Desktop Client HIGH 7.5
CVE-2026-42913

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …

Fix: 1.2.7214 / 10.0.20348.5256+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-42911

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-42905

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Remote Desktop Client HIGH 7.5
CVE-2026-42909

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …

Fix: 1.2.7214 / 2.0.1193.0+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-42836

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an autho…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-34335

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-42825

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows Server 2012 HIGH 7.8
CVE-2026-41095

Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40419

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 8.1
CVE-2026-40415

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40418

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Windows 11 23h2 CRITICAL 9.3
CVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.20348.5074 / 10.0.22631.7079+
Fix from $2,300 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-40408

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.5
CVE-2026-40406

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-40410

Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-40382

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40366

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40358

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40361

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40359

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20128+
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.0
CVE-2026-35418

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-35416

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34345

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34347

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.0
CVE-2026-34340

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows Server 2025 HIGH 8.0
CVE-2026-34332

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

Fix: 10.0.26100.32772+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34333

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12