CVE Vulnerability Database

Search and browse 389,959 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-50398HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50397HIGH7Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50396HIGH7.8Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-50394MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in...
CVE-2026-50393HIGH7.8Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-50392HIGH7Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-50391HIGH7.8Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
CVE-2026-50390HIGH7.8Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate...
CVE-2026-50389MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-50388HIGH7.8Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50387HIGH7.8Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-50386HIGH7.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50385HIGH8.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-50383MEDIUM5.5Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-50382HIGH8.8Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
CVE-2026-50380CRITICAL9.6Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2026-50379HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50378HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows ...
CVE-2026-50377HIGH7.8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50376MEDIUM6.5Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50375HIGH7.8Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-50374MEDIUM6.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a phys...
CVE-2026-50373HIGH7.8Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locall...
CVE-2026-50372HIGH7Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
CVE-2026-50371HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an a...