Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Remote Desktop Client HIGH 7.5
CVE-2026-45639

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

Fix: 1.2.7214 / 2.0.1193.0+
Fix from $1,950 2026-06-09
Windows 10 21h2 HIGH 7.0
CVE-2026-45640

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7417 / 10.0.19045.7417+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45605

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45607

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 6.8
CVE-2026-45608

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 11 23h2 MEDIUM 5.5
CVE-2026-45604

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

Fix: 10.0.22631.7219 / 10.0.26100.8655+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-45606

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-45634

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 CRITICAL 9.1
CVE-2026-45602

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $2,300 2026-06-09
Windows 10 1607 HIGH 8.1
CVE-2026-45599

Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 11 24h2 HIGH 7.8
CVE-2026-45600

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges loca…

Fix: 10.0.26100.8655 / 10.0.26100.32995+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-45598

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-45601

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-45603

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45592

Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-45593

Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-45596

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 11 23h2 HIGH 7.0
CVE-2026-45597

Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an autho…

Fix: 10.0.20348.5256 / 10.0.22631.7219+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-45594

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclos…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.4
CVE-2026-45595

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Exchange Server HIGH 8.8
CVE-2026-45504

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Fix: 15.02.2562.043+
Fix from $1,950 2026-06-09
Exchange Server HIGH 8.1
CVE-2026-45583

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Fix: 15.02.2562.043+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-45588

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45586

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevat…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Asp.net Core HIGH 7.5
CVE-2026-45591

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.28 / 9.0.17+
Fix from $1,950 2026-06-09
Exchange Server MEDIUM 6.5
CVE-2026-45503

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Exchange Server MEDIUM 5.0
CVE-2026-45502EPSS 20%

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
.net HIGH 7.8
CVE-2026-45490

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

Fix: 8.0.28 / 9.0.17+
Fix from $1,950 2026-06-09
Exchange Server MEDIUM 6.1
CVE-2026-45501

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Exchange Server MEDIUM 6.1
CVE-2026-45500

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09