SEPTEMBER 21, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,198 records on file
Page 1060 of 4,940
CVE ID Score Description
1mo ago
7.8

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

1mo ago
8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

1mo ago
8.8

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.

1mo ago
7.7

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.

1mo ago
7.8

Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

1mo ago
7.4

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

1mo ago
7.8

Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

1mo ago
7.4

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

1mo ago
7

Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

1mo ago
7

Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

1mo ago
7.8

Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

1mo ago
7.4

Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

1mo ago
7.5

Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.