CVE Vulnerability Database

Search and browse 375,909 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-62688HIGH7.8Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-61939HIGH7Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
CVE-2026-61938HIGH7Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-61937HIGH7.8Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-61936MEDIUM5.5Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature lo...
CVE-2026-61934HIGH7.8Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-61933MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-61932HIGH7.8Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker ...
CVE-2026-61930HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-61929HIGH7Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-61928MEDIUM5.5Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
CVE-2026-61927HIGH7Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-61926HIGH7.8Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-61925HIGH7.8Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-61924MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61923HIGH7.8Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges lo...
CVE-2026-61921MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61920MEDIUM6.6Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut...
CVE-2026-61918MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61368MEDIUM5Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-61367HIGH7.8Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate...
CVE-2026-61366HIGH7Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
CVE-2026-61365HIGH7.8Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate...
CVE-2026-61364HIGH7.8Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate...
CVE-2026-61363HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.