Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-21251 Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally. Windows Server 2016 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.3 CVE-2026-21247 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.3 CVE-2026-21248 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21245 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.7781 / 10.0.26100.32313+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-21243 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. Windows Server 2019 10.0.17763.8389 / 10.0.20348.4711+ Fix from $1,9502026-02-10 HIGH 7.3 CVE-2026-21244 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21241 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.4711 / 10.0.22631.6649+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21242 Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6937 / 10.0.19045.6937+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21236 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21238 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21239 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.3 CVE-2026-21235 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21237 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attac… Windows 10 21h2 10.0.19044.6937 / 10.0.19045.6937+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21240 Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8389 / 10.0.19044.6937+ Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-21229 Improper input validation in Power BI allows an authorized attacker to execute code over a network. Power Bi Report Server 15.0.1120.113+ Fix from $1,9502026-02-10 HIGH 8.1 CVE-2026-21228 Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. Azure Local 2510.0.3002+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21231 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21232 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.22631.6649 / 10.0.25398.2149+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21234 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an a… Windows 10 1809 10.0.17763.8389 / 10.0.19044.6937+ Fix from $1,9502026-02-10 MEDIUM 5.5 CVE-2026-21222 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,6002026-02-10 HIGH 7.8 CVE-2026-20841EPSS 12% Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute… Windows Notepad 11.2510+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-20846 Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-21218 Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. .net 8.0.24 / 9.0.13+ Fix from $1,9502026-02-10 CRITICAL 9.8 CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability Azure Front Door No fix yet Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-24302 Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Azure Arc Mitigation only Fix from $2,3002026-02-05 HIGH 8.2 CVE-2026-21532 Azure Function Information Disclosure Vulnerability Azure Functions No fix yet Fix from $1,9502026-02-05 MEDIUM 6.5 CVE-2026-0391 User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over … Edge Chromium 143.0.3650.66+ Fix from $1,6002026-02-05 CRITICAL 9.8 CVE-2026-24888 Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject`… Maker.js after 0.19.1 Fix from $2,3002026-01-28 HIGH 7.8 CVE-2026-21509 KEVEPSS 72% Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. 365 Apps Mitigation only Fix from $1,9502026-01-26 CRITICAL 9.9 CVE-2026-24304 Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. Azure Resource Manager Mitigation only Fix from $2,3002026-01-23