CVE Vulnerability Database

Search and browse 375,909 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-61361HIGH7Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CVE-2026-61360MEDIUM5.5Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-61359HIGH7.8Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-61358HIGH7.8Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) al...
CVE-2026-61357HIGH7.8Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61356HIGH7.8Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate...
CVE-2026-61355HIGH7.8Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61353HIGH7.8Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61352HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all...
CVE-2026-61350MEDIUM4.6Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-61349HIGH7.8Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61348HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-61347MEDIUM5.5Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVE-2026-61346HIGH7Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-61345MEDIUM6.5Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo...
CVE-2026-59138MEDIUM6.5Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo...
CVE-2026-59137MEDIUM5.5Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc...
CVE-2026-59136MEDIUM5.5Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally...
CVE-2026-59135MEDIUM5.5Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CVE-2026-59134HIGH7.5Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-59133HIGH8.8Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker t...
CVE-2026-59132HIGH7.5Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CVE-2026-59131MEDIUM5.6No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
CVE-2026-59130MEDIUM5.6No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
CVE-2026-59128MEDIUM5.5Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally...