CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-20871

    Last Modified: 16 Apr 2026

    Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20870

    Last Modified: 18 Apr 2026

    Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    8.8
    High

    CVE-2026-20868

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20867

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20866

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7
    High

    CVE-2026-20863

    Last Modified: 16 Apr 2026

    Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-20862

    Last Modified: 16 Apr 2026

    Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20861

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7
    High

    CVE-2026-21219

    Last Modified: 16 Apr 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20854

    Last Modified: 16 Apr 2026

    Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

    Published: 13 Jan 2026
    7.4
    High

    CVE-2026-20853

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20849

    Last Modified: 16 Apr 2026

    Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20848

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20843

    Last Modified: 16 Apr 2026

    Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    8.8
    High

    CVE-2026-20947

    Last Modified: 16 Apr 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-21224

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7
    High

    CVE-2026-21221

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7
    High

    CVE-2026-20830

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    9.8
    Critical

    CVE-2026-20963

    Last Modified: 2 Apr 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    Published: 13 Jan 2026
    4.6
    Medium

    CVE-2026-20959

    Last Modified: 16 Apr 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20956

    Last Modified: 16 Apr 2026

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20955

    Last Modified: 16 Apr 2026

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    8.4
    High

    CVE-2026-20953

    Last Modified: 16 Apr 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20951

    Last Modified: 16 Apr 2026

    Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20946

    Last Modified: 16 Apr 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    8.4
    High

    CVE-2026-20944

    Last Modified: 16 Apr 2026

    Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    7
    High

    CVE-2026-20943

    Last Modified: 16 Apr 2026

    Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20940

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20938

    Last Modified: 30 Jul 2026

    Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20934

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

    Published: 13 Jan 2026
    5.5
    Medium

    CVE-2026-20932

    Last Modified: 16 Apr 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 13 Jan 2026
    5.3
    Medium

    CVE-2026-20927

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20926

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

    Published: 13 Jan 2026
    6.5
    Medium

    CVE-2026-20925

    Last Modified: 16 Apr 2026

    External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20924

    Last Modified: 16 Apr 2026

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20923

    Last Modified: 16 Apr 2026

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20922

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20921

    Last Modified: 26 May 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20920

    Last Modified: 18 Apr 2026

    Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20919

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20918

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20877

    Last Modified: 18 Apr 2026

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    6.7
    Medium

    CVE-2026-20876

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.5
    High

    CVE-2026-20875

    Last Modified: 16 Apr 2026

    Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

    Published: 13 Jan 2026
    7
    High

    CVE-2026-20869

    Last Modified: 16 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20865

    Last Modified: 16 Apr 2026

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20864

    Last Modified: 26 May 2026

    Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20860

    Last Modified: 16 Apr 2026

    Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20859

    Last Modified: 18 Apr 2026

    Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026
    7.8
    High

    CVE-2026-20858

    Last Modified: 16 Apr 2026

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 13 Jan 2026