CVE Vulnerability Database

Search and browse 389,962 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-50373HIGH7.8Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locall...
CVE-2026-50372HIGH7Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
CVE-2026-50371HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an a...
CVE-2026-50370HIGH8.8Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netwo...
CVE-2026-50369HIGH8.8Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
CVE-2026-50368HIGH7.5Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over...
CVE-2026-50367HIGH7.8Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to e...
CVE-2026-50366MEDIUM6.5Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ...
CVE-2026-50365HIGH8Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent networ...
CVE-2026-50363HIGH7.8Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-50362HIGH7.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code local...
CVE-2026-50361HIGH7.8Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-50360HIGH8.8Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate priv...
CVE-2026-50359HIGH7.8Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
CVE-2026-50358HIGH7.8Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50357HIGH7.8Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-50355HIGH7.5Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over...
CVE-2026-50353HIGH7.8Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-50352MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack...
CVE-2026-50348HIGH8.1Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-50347HIGH7.8Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
CVE-2026-50346HIGH7.8Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50345HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-50344HIGH7.8Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
CVE-2026-50343HIGH7.8Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.