Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1607 HIGH 7.8
CVE-2026-49793

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49796

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49797

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49789

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49790

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49791

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to e…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49792

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-49787

Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-49788

Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-49181

Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49184

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49783

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.0
CVE-2026-49183

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker…

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.0
CVE-2026-49784

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attac…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-49180

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-49172

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-49178

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49171

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 11 26h1 HIGH 7.8
CVE-2026-49173

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.28000.2269 / 10.0.28000.2525+
Fix from $1,950 2026-07-14
Windows 10 21h2 HIGH 7.8
CVE-2026-49175

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49176

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1809 MEDIUM 6.1
CVE-2026-49174

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,600 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-49164

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows Server 2025 HIGH 8.8
CVE-2026-49169

Use after free in DNS Server allows an authorized attacker to execute code over a network.

Fix: 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.8
CVE-2026-49166

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-49170

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-49167

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.1
CVE-2026-49165

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 6.8
CVE-2026-49168

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Surface Go 2 1901 Firmware HIGH 7.8
CVE-2026-48581

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $1,950 2026-07-14