Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2026-20833
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
Windows Server 2008
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20835
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.
Windows 11 24h2
10.0.25398.2092 / 10.0.26100.7623+
HIGH 7.0
CVE-2026-20826
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allow…
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.0
CVE-2026-20830
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…
Windows Server 2025
10.0.26100.7623+
HIGH 7.0
CVE-2026-20831
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege…
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20827
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to discl…
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20829
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
Windows 10 1809
10.0.17763.8276 / 10.0.19044.6809+
HIGH 7.8
CVE-2026-20820
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.8
CVE-2026-20822
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 6.2
CVE-2026-20821
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information l…
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20823
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20824
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.8
CVE-2026-20817EPSS 5%
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.6809 / 10.0.19045.6809+
HIGH 7.0
CVE-2026-20814
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva…
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.0
CVE-2026-20815
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…
Windows 11 24h2
10.0.26100.7623 / 10.0.26100.32230+
HIGH 7.0
CVE-2026-20816
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 6.2
CVE-2026-20818
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.
Windows Server 2016
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20819
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
Windows 11 23h2
10.0.22631.6491 / 10.0.26100.7623+
HIGH 7.8
CVE-2026-20809
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.8
CVE-2026-20810
Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8276 / 10.0.19044.6809+
HIGH 7.8
CVE-2026-20811
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.20348.4648 / 10.0.22631.6491+
HIGH 7.0
CVE-2026-20808
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attack…
Windows 11 24h2
10.0.25398.2092 / 10.0.26100.7623+
MEDIUM 6.5
CVE-2026-20812
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
MEDIUM 5.5
CVE-2026-20805 KEVEPSS 5%
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.7
CVE-2026-20804
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.5
CVE-2026-0386
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
Windows Server 2008
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.2
CVE-2026-20803
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
Sql Server 2022
16.0.1165.1 / 16.0.4230.2+
CRITICAL 9.6
CVE-2025-64675
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp…
Azure Cosmos Db
Mitigation only
CRITICAL 10.0
CVE-2025-65037
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
Azure Container Apps
Mitigation only
CRITICAL 9.8
CVE-2025-65041
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Partner Center
Mitigation only