Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows Server 2008 MEDIUM 5.5
CVE-2026-20833

Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 11 24h2 MEDIUM 5.5
CVE-2026-20835

Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

Fix: 10.0.25398.2092 / 10.0.26100.7623+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20826

Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allow…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows Server 2025 HIGH 7.0
CVE-2026-20830

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…

Fix: 10.0.26100.7623+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20831

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20827

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to discl…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1809 MEDIUM 5.5
CVE-2026-20829

Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20820

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20822

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 6.2
CVE-2026-20821

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information l…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20823

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20824

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 21h2 HIGH 7.8
CVE-2026-20817EPSS 5%

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6809 / 10.0.19045.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20814

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.0
CVE-2026-20815

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20816

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows Server 2016 MEDIUM 6.2
CVE-2026-20818

Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 11 23h2 MEDIUM 5.5
CVE-2026-20819

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

Fix: 10.0.22631.6491 / 10.0.26100.7623+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20809

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20810

Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 11 23h2 HIGH 7.8
CVE-2026-20811

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4648 / 10.0.22631.6491+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.0
CVE-2026-20808

Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attack…

Fix: 10.0.25398.2092 / 10.0.26100.7623+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 6.5
CVE-2026-20812

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20805 KEVEPSS 5%

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 7.7
CVE-2026-20804

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows Server 2008 HIGH 7.5
CVE-2026-0386

Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Sql Server 2022 HIGH 7.2
CVE-2026-20803

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.1165.1 / 16.0.4230.2+
Fix from $1,950 2026-01-13
Azure Cosmos Db CRITICAL 9.6
CVE-2025-64675

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp…

Mitigation only
Fix from $2,300 2025-12-19
Azure Container Apps CRITICAL 10.0
CVE-2025-65037

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-12-18
Partner Center CRITICAL 9.8
CVE-2025-65041

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-12-18