Vulnerability index

Browse CVEs

118 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Windows 10 1809 HIGH 7.8
CVE-2026-35417

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34344

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-26162

Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-20806

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,600 2026-04-14
365 Apps HIGH 7.8
CVE-2026-26110

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19822.20000+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-21519 KEV

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-20860EPSS 8%

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 11 23h2 HIGH 7.8
CVE-2026-20811

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4648 / 10.0.22631.6491+
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2025-62554

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-59231

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20059+
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59233

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20059+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-55236

Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.

Fix: 10.0.17763.7792 / 10.0.19044.6332+
Fix from $1,950 2025-09-09
Windows 10 1507 MEDIUM 6.7
CVE-2025-54915

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows 10 1507 MEDIUM 6.7
CVE-2025-54109

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows 10 1507 MEDIUM 6.7
CVE-2025-54104

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows 10 1507 MEDIUM 6.7
CVE-2025-54094

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows 10 1507 MEDIUM 6.7
CVE-2025-53810

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows 10 1507 MEDIUM 6.7
CVE-2025-53808

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
365 Apps HIGH 7.8
CVE-2025-53739

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 7.8
CVE-2025-53726

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges local…

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 7.8
CVE-2025-53724

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges local…

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 7.8
CVE-2025-53725

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges local…

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 8.8
CVE-2025-53143EPSS 6%

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 8.8
CVE-2025-53144EPSS 6%

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 8.8
CVE-2025-53145EPSS 6%

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Windows 11 22h2 HIGH 7.8
CVE-2025-50176

Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally.

Fix: 10.0.20348.3989 / 10.0.22621.5768+
Fix from $1,950 2025-08-12
Windows 11 22h2 HIGH 7.8
CVE-2025-50168

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5768 / 10.0.22631.5768+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 7.8
CVE-2025-50155

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges local…

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-49702

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-48815

Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08