| CVE-2026-61938 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-61929 | 7 | high | microsoft / windows 11 23h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-61927 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-61366 | 7 | high | microsoft / windows 10 1607 | Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-61361 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. | 25d ago |
| CVE-2026-61348 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 25d ago |
| CVE-2026-61346 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-59126 | 7 | high | microsoft / windows 10 21h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Loggi | 25d ago |
| CVE-2026-59125 | 7 | high | microsoft / windows 10 1607 | Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges loca | 25d ago |
| CVE-2026-59122 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 25d ago |
| CVE-2026-50472 | 7 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-58598 | 7 | high | microsoft / windows 10 21h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engi | 51d ago |
| CVE-2026-50526 | 7 | high | microsoft / .net | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform ta | 53d ago |
| CVE-2026-58637 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges lo | 53d ago |
| CVE-2026-58629 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-58619 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-58544 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-57093 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 53d ago |
| CVE-2026-56187 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-56183 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-56173 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50674 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50672 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50669 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 53d ago |
| CVE-2026-50658 | 7 | high | microsoft / defender for endpoint | Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate p | 53d ago |
| CVE-2026-50503 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50491 | 7 | high | microsoft / windows 10 1607 | Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50490 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50459 | 7 | high | microsoft / windows 10 21h2 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50452 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50449 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50410 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50406 | 7 | high | microsoft / windows 10 21h2 | Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50404 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allow | 53d ago |
| CVE-2026-50403 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50397 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50396 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50393 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50392 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50390 | 7 | high | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to e | 53d ago |
| CVE-2026-50372 | 7 | high | microsoft / windows 10 1607 | Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally | 53d ago |
| CVE-2026-50371 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allow | 53d ago |
| CVE-2026-50359 | 7 | high | microsoft / windows 10 1607 | Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50358 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50348 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50345 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50322 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50307 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-58526 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-54996 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print D | 53d ago |
| CVE-2026-54989 | 7 | high | microsoft / windows 10 1607 | Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate | 53d ago |
| CVE-2026-54129 | 7 | high | microsoft / windows 10 1809 | Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-54111 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print D | 53d ago |
| CVE-2026-50384 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Servic | 53d ago |
| CVE-2026-50356 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows A | 53d ago |
| CVE-2026-50325 | 7 | high | microsoft / windows 10 1607 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50323 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50297 | 7 | high | microsoft / windows 10 1607 | Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50296 | 7 | high | microsoft / windows 10 1607 | Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49806 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print D | 53d ago |