Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows Server 2016 HIGH 7.8
CVE-2026-21251

Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21247

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21248

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 11 24h2 HIGH 7.8
CVE-2026-21245

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.7781 / 10.0.26100.32313+
Fix from $1,950 2026-02-10
Windows Server 2019 HIGH 7.5
CVE-2026-21243

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

Fix: 10.0.17763.8389 / 10.0.20348.4711+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21244

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 11 23h2 HIGH 7.0
CVE-2026-21241

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4711 / 10.0.22631.6649+
Fix from $1,950 2026-02-10
Windows 10 21h2 HIGH 7.0
CVE-2026-21242

Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6937 / 10.0.19045.6937+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21236

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21238

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21239

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21235

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 21h2 HIGH 7.0
CVE-2026-21237

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attac…

Fix: 10.0.19044.6937 / 10.0.19045.6937+
Fix from $1,950 2026-02-10
Windows 10 1809 HIGH 7.0
CVE-2026-21240

Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8389 / 10.0.19044.6937+
Fix from $1,950 2026-02-10
Power Bi Report Server HIGH 8.8
CVE-2026-21229

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

Fix: 15.0.1120.113+
Fix from $1,950 2026-02-10
Azure Local HIGH 8.1
CVE-2026-21228

Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.

Fix: 2510.0.3002+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21231

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 11 23h2 HIGH 7.8
CVE-2026-21232

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.6649 / 10.0.25398.2149+
Fix from $1,950 2026-02-10
Windows 10 1809 HIGH 7.0
CVE-2026-21234

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an a…

Fix: 10.0.17763.8389 / 10.0.19044.6937+
Fix from $1,950 2026-02-10
Windows 10 1607 MEDIUM 5.5
CVE-2026-21222

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,600 2026-02-10
Windows Notepad HIGH 7.8
CVE-2026-20841EPSS 12%

Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute…

Fix: 11.2510+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.5
CVE-2026-20846

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
.net HIGH 7.5
CVE-2026-21218

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

Fix: 8.0.24 / 9.0.13+
Fix from $1,950 2026-02-10
Azure Front Door CRITICAL 9.8
CVE-2026-24300

Azure Front Door Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-02-05
Azure Arc CRITICAL 9.8
CVE-2026-24302

Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-02-05
Azure Functions HIGH 8.2
CVE-2026-21532

Azure Function Information Disclosure Vulnerability

No fix yet
Fix from $1,950 2026-02-05
Edge Chromium MEDIUM 6.5
CVE-2026-0391

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over …

Fix: 143.0.3650.66+
Fix from $1,600 2026-02-05
Maker.js CRITICAL 9.8
CVE-2026-24888

Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject`…

Fix: after 0.19.1
Fix from $2,300 2026-01-28
365 Apps HIGH 7.8
CVE-2026-21509 KEVEPSS 72%

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Mitigation only
Fix from $1,950 2026-01-26
Azure Resource Manager CRITICAL 9.9
CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-01-23