CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2026-32088

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-32086

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    5.5
    Medium

    CVE-2026-32084

    Last Modified: 24 Apr 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-32080

    Last Modified: 24 Apr 2026

    Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    5.5
    Medium

    CVE-2026-32079

    Last Modified: 24 Apr 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-32078

    Last Modified: 24 Apr 2026

    Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-32077

    Last Modified: 26 May 2026

    Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-32076

    Last Modified: 24 Apr 2026

    Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-32074

    Last Modified: 24 Apr 2026

    Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    6.2
    Medium

    CVE-2026-32072

    Last Modified: 24 Apr 2026

    Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-32070

    Last Modified: 24 Apr 2026

    Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-32069

    Last Modified: 24 Apr 2026

    Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-32068

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    5.5
    Medium

    CVE-2026-27930

    Last Modified: 24 Apr 2026

    Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

    Published: 14 Apr 2026
    8.7
    High

    CVE-2026-27928

    Last Modified: 24 Apr 2026

    Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

    Published: 14 Apr 2026
    6.5
    Medium

    CVE-2026-27925

    Last Modified: 24 Apr 2026

    Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27923

    Last Modified: 24 Apr 2026

    Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-27922

    Last Modified: 24 Apr 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27920

    Last Modified: 24 Apr 2026

    Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27916

    Last Modified: 24 Apr 2026

    Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27914

    Last Modified: 24 Apr 2026

    Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.7
    High

    CVE-2026-27913

    Last Modified: 24 Apr 2026

    Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.

    Published: 14 Apr 2026
    8
    High

    CVE-2026-27912

    Last Modified: 24 Apr 2026

    Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27911

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27910

    Last Modified: 24 Apr 2026

    Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27909

    Last Modified: 24 Apr 2026

    Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26184

    Last Modified: 24 Apr 2026

    Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-26182

    Last Modified: 24 Apr 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    8.8
    High

    CVE-2026-26178

    Last Modified: 24 Apr 2026

    Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-26177

    Last Modified: 24 Apr 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26176

    Last Modified: 24 Apr 2026

    Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-26173

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26172

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26170

    Last Modified: 24 Apr 2026

    Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    6.1
    Medium

    CVE-2026-26169

    Last Modified: 24 Apr 2026

    Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26168

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26163

    Last Modified: 24 Apr 2026

    Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26159

    Last Modified: 24 Apr 2026

    Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26156

    Last Modified: 24 Apr 2026

    Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26153

    Last Modified: 24 Apr 2026

    Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-26152

    Last Modified: 24 Apr 2026

    Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26143

    Last Modified: 27 Apr 2026

    Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

    Published: 14 Apr 2026
    7.5
    High

    CVE-2026-23666

    Last Modified: 7 May 2026

    Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-23657

    Last Modified: 29 Apr 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 14 Apr 2026
    5.5
    Medium

    CVE-2026-20806

    Last Modified: 24 Apr 2026

    Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

    Published: 14 Apr 2026
    4.6
    Medium

    CVE-2026-20928

    Last Modified: 24 Apr 2026

    Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Apr 2026
    5.5
    Medium

    CVE-2026-32212

    Last Modified: 24 Apr 2026

    Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

    Published: 14 Apr 2026
    8
    High

    CVE-2026-33826

    Last Modified: 24 Apr 2026

    Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-33825

    Last Modified: 24 Apr 2026

    Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    6.1
    Medium

    CVE-2026-33822

    Last Modified: 29 Apr 2026

    Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 14 Apr 2026