Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 21h2 HIGH 7.8
CVE-2026-20871

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6809 / 10.0.19045.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20869

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authoriz…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 6.5
CVE-2026-20872EPSS 20%

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20861

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20864

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20865

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20866

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 11 23h2 HIGH 7.0
CVE-2026-20863

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4648 / 10.0.22631.6491+
Fix from $1,950 2026-01-13
Windows 10 1809 MEDIUM 5.5
CVE-2026-20862

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information local…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 8.1
CVE-2026-20856

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20857

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20858

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.8
CVE-2026-20859

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20860EPSS 8%

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.5
CVE-2026-20854

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.7
CVE-2026-20852

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20848

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to el…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20849

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.4
CVE-2026-20853

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker …

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 6.5
CVE-2026-20847

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 11 24h2 MEDIUM 6.2
CVE-2026-20851

Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20840

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20843

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.4
CVE-2026-20844

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 21h2 HIGH 7.0
CVE-2026-20842

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6809 / 10.0.19045.6809+
Fix from $1,950 2026-01-13
Windows 11 23h2 MEDIUM 5.5
CVE-2026-20838

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.20348.4648 / 10.0.22631.6491+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20839

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20832

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20837

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20836

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13