Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-61936 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-61932 Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61934 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.22631.7517 / 10.0.26100.9106+ Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-61933 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26100.33222+ Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-61925 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61926 Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61930 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-61927 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26100.33222+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-61929 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.22631.7517 / 10.0.26100.9106+ Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-61928 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-61923 Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-61924 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 MEDIUM 6.6 CVE-2026-61920 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute c… Windows 10 1607 No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-61921 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-61367 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-61918 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-61368 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,0002026-08-11 HIGH 7.0 CVE-2026-61366 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-61363 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61364 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61365 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-61361 Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26100.33222+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61355 Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.7663 / 10.0.19045.7663+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61356 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61357 Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26100.33222+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61358 Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker t… Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61359 Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.5440 / 10.0.22631.7517+ Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-61360 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,0002026-08-11 HIGH 8.1 CVE-2026-61352 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker … Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61349 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11