Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-20871 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6809 / 10.0.19045.6809+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20869 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authoriz… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2026-20872EPSS 20% External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 HIGH 7.8 CVE-2026-20861 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac… Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20864 Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20865 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20866 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac… Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20863 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.4648 / 10.0.22631.6491+ Fix from $1,9502026-01-13 MEDIUM 5.5 CVE-2026-20862 Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information local… Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,6002026-01-13 HIGH 8.1 CVE-2026-20856 Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20857 Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20858 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20859 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.7623 / 10.0.26100.32230+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20860EPSS 8% Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-20854 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. Windows 11 24h2 10.0.26100.7623 / 10.0.26100.32230+ Fix from $1,9502026-01-13 HIGH 7.7 CVE-2026-20852 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-20848 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to el… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-20849 Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.4 CVE-2026-20853 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker … Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2026-20847 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 6.2 CVE-2026-20851 Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally. Windows 11 24h2 10.0.26100.7623 / 10.0.26100.32230+ Fix from $1,6002026-01-13 HIGH 7.8 CVE-2026-20840 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20843 Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.4 CVE-2026-20844 Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20842 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6809 / 10.0.19045.6809+ Fix from $1,9502026-01-13 MEDIUM 5.5 CVE-2026-20838 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. Windows 11 23h2 10.0.20348.4648 / 10.0.22631.6491+ Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2026-20839 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 HIGH 7.8 CVE-2026-20832 Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20837 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20836 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13