Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

365 Apps HIGH 8.4
CVE-2026-20944

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20940

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.8
CVE-2026-20941

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges …

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13
Office HIGH 7.0
CVE-2026-20943

Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19127.20442 / 16.0.19426.20170+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20939

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 8.0
CVE-2026-20931

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 11 23h2 HIGH 7.8
CVE-2026-20938

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.6491 / 10.0.26100.7623+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20934

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to el…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 11 23h2 MEDIUM 6.2
CVE-2026-20935

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.

Fix: 10.0.22631.6491 / 10.0.26100.7623+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20932

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20937

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20924

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20926

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to el…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20929

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 6.5
CVE-2026-20925EPSS 18%

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.3
CVE-2026-20927

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to de…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 11 23h2 HIGH 7.8
CVE-2026-20920

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4648 / 10.0.22631.6491+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20922

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20923

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20919

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to el…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20921

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to el…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20873

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20874

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20877

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20918

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20875

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 11 23h2 MEDIUM 6.7
CVE-2026-20876

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.6491 / 10.0.25398.2092+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 8.8
CVE-2026-20868

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20867

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.8
CVE-2026-20870

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13