Vulnerability index

Browse CVEs

872 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.0 CVE-2026-26165 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.5020 / 10.0.22631.6936+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-23657 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-26132 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.7058 / 10.0.19045.7058+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26134 Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. 365 Copilot 16.0.19822.20000+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26107 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20102+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-25189 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8511 / 10.0.19044.7058+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-25178 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-25170 Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.4830 / 10.0.22631.6783+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-25171 Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.4 CVE-2026-25167 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.7979 / 10.0.26100.32463+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-24292 Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8511 / 10.0.19044.7058+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-24295 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorize… Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-24289 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-24285 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. 365 Copilot 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-23669 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-23671 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an auth… Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-23667 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8511 / 10.0.19044.7058+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-21253 Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21251 Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally. Windows Server 2016 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21241 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.4711 / 10.0.22631.6649+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21242 Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6937 / 10.0.19045.6937+ Fix from $1,9502026-02-10 HIGH 7.3 CVE-2026-21235 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21237 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attac… Windows 10 21h2 10.0.19044.6937 / 10.0.19045.6937+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21219 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows Software Development Kit 10.0.26100.7463+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-21221 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a… Windows 11 24h2 10.0.26100.7623 / 10.0.26100.32230+ Fix from $1,9502026-01-13 HIGH 8.4 CVE-2026-20953 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502026-01-13 HIGH 8.4 CVE-2026-20952 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20950 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20083+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20924 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20920 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.4648 / 10.0.22631.6491+ Fix from $1,9502026-01-13