Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 11 23h2 HIGH 8.1
CVE-2026-42974

Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.

Fix: 10.0.20348.5256 / 10.0.22631.7219+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-42977

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-42978

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-42979

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-42980EPSS 7%

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42973

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42970

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42971

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42968

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42969

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42972

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-42916

Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Remote Desktop Client HIGH 7.5
CVE-2026-42913

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …

Fix: 1.2.7214 / 10.0.20348.5256+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-42911

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-42912

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacke…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 21h2 MEDIUM 5.5
CVE-2026-42915

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

Fix: 10.0.19044.7417 / 10.0.19045.7417+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.3
CVE-2026-42914

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-42905

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 11 24h2 HIGH 7.8
CVE-2026-42910

Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8655 / 10.0.26100.32995+
Fix from $1,950 2026-06-09
Remote Desktop Client HIGH 7.5
CVE-2026-42909

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …

Fix: 1.2.7214 / 2.0.1193.0+
Fix from $1,950 2026-06-09
Windows App HIGH 7.5
CVE-2026-42908

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

Fix: 2.0.1193.0 / 10.0.14393.9234+
Fix from $1,950 2026-06-09
Windows 10 1809 MEDIUM 6.5
CVE-2026-42907

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,600 2026-06-09
Windows 10 21h2 MEDIUM 5.5
CVE-2026-42906

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

Fix: 10.0.19044.7417 / 10.0.19045.7417+
Fix from $1,600 2026-06-09
Windows 10 21h2 CRITICAL 9.6
CVE-2026-42904

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

Fix: 10.0.19044.7417 / 10.0.19045.7417+
Fix from $2,300 2026-06-09
Teams HIGH 8.1
CVE-2026-42835

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorize…

Fix: 1.0.76.2026111302+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-42837

Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 11 24h2 HIGH 7.8
CVE-2026-42829

Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.26100.8655 / 10.0.26200.8655+
Fix from $1,950 2026-06-09
Powertoys HIGH 7.8
CVE-2026-42902

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

Fix: 0.99.1+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-42836

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an autho…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 6.5
CVE-2026-42903

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09