Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1809 MEDIUM 5.5
CVE-2026-61936

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61932

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 11 23h2 HIGH 7.8
CVE-2026-61934

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.7517 / 10.0.26100.9106+
Fix from $4,900 2026-08-11
Windows 11 24h2 MEDIUM 5.5
CVE-2026-61933

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Fix: 10.0.26100.9106 / 10.0.26100.33222+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61925

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61926

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61930

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 11 24h2 HIGH 7.0
CVE-2026-61927

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.9106 / 10.0.26100.33222+
Fix from $4,900 2026-08-11
Windows 11 23h2 HIGH 7.0
CVE-2026-61929

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.7517 / 10.0.26100.9106+
Fix from $4,900 2026-08-11
Windows 10 1607 MEDIUM 5.5
CVE-2026-61928

Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Windows 10 1809 HIGH 7.8
CVE-2026-61923

Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.5
CVE-2026-61924

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 MEDIUM 6.6
CVE-2026-61920

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute c…

No fix yet
Fix from $4,000 2026-08-11
Windows 10 1607 MEDIUM 6.5
CVE-2026-61921

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61367

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.5
CVE-2026-61918

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 MEDIUM 5.5
CVE-2026-61368

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.0
CVE-2026-61366

Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 8.1
CVE-2026-61363

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61364

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61365

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 11 24h2 HIGH 7.0
CVE-2026-61361

Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.

Fix: 10.0.26100.9106 / 10.0.26100.33222+
Fix from $4,900 2026-08-11
Windows 10 21h2 HIGH 7.8
CVE-2026-61355

Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7663 / 10.0.19045.7663+
Fix from $4,900 2026-08-11
Windows 10 1809 HIGH 7.8
CVE-2026-61356

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Windows 11 24h2 HIGH 7.8
CVE-2026-61357

Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.9106 / 10.0.26100.33222+
Fix from $4,900 2026-08-11
Windows 10 1809 HIGH 7.8
CVE-2026-61358

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker t…

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Windows 11 23h2 HIGH 7.8
CVE-2026-61359

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.5440 / 10.0.22631.7517+
Fix from $4,900 2026-08-11
Windows 10 1607 MEDIUM 5.5
CVE-2026-61360

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 8.1
CVE-2026-61352

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61349

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11