CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 7.8 | Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.4 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
| 1mo ago | 7 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.7 | Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally. |
| 1mo ago | 7.8 | Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally. |
| 1mo ago | 7 | Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.4 | Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7 | Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.5 | Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. |
| 1mo ago | 7 | Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally. |