Количество 331 342
Количество 331 342
CVE-2026-20842
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2026-20840
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-20839
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
CVE-2026-20838
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-20837
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-20836
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-20835
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.
CVE-2026-20834
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
CVE-2026-20833
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
CVE-2026-20832
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
CVE-2026-20831
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-20830
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-20829
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
CVE-2026-20828
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-20827
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
CVE-2026-20826
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.
CVE-2026-20825
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-20824
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-20823
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-20822
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-20842 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 25 дней назад | |
CVE-2026-20840 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 25 дней назад | |
CVE-2026-20839 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 25 дней назад | |
CVE-2026-20838 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 25 дней назад | |
CVE-2026-20837 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 25 дней назад | |
CVE-2026-20836 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 25 дней назад | |
CVE-2026-20835 Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 25 дней назад | |
CVE-2026-20834 Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | CVSS3: 4.6 | 0% Низкий | 25 дней назад | |
CVE-2026-20833 Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 25 дней назад | |
CVE-2026-20832 Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | 25 дней назад | |
CVE-2026-20831 Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 25 дней назад | |
CVE-2026-20830 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 25 дней назад | |
CVE-2026-20829 Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 25 дней назад | |
CVE-2026-20828 Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | CVSS3: 4.6 | 0% Низкий | 25 дней назад | |
CVE-2026-20827 Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 25 дней назад | |
CVE-2026-20826 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 25 дней назад | |
CVE-2026-20825 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | CVSS3: 4.4 | 0% Низкий | 25 дней назад | |
CVE-2026-20824 Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. | CVSS3: 5.5 | 0% Низкий | 25 дней назад | |
CVE-2026-20823 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 25 дней назад | |
CVE-2026-20822 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 25 дней назад |
Уязвимостей на страницу