Skip to content
cyberexploits

CVEs

Sourced from CVEProject/cvelistV5 and the CISA KEV catalog.

351,354 CVEs
CVSS
CVE
Description
KEV added
PoCs
6.2
CVE-2026-32072
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
2026-04-14
7.0
CVE-2026-32070
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-32069
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
2026-04-14
7.0
CVE-2026-32068
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
2026-04-14
5.5
CVE-2026-27930
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
2026-04-14
8.7
CVE-2026-27928
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
2026-04-14
6.5
CVE-2026-27925
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
2026-04-14
7.8
CVE-2026-27923
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
2026-04-14
7.0
CVE-2026-27922
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-27920
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-27916
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-27914
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
2026-04-14
7.7
CVE-2026-27913
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
2026-04-14
8.0
CVE-2026-27912
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
2026-04-14
7.8
CVE-2026-27911
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-27910
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-27909
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-26184
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
2026-04-14
7.0
CVE-2026-26182
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
2026-04-14
8.8
CVE-2026-26178
Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.
2026-04-14
7.0
CVE-2026-26177
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-26176
Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally.
2026-04-14
7.0
CVE-2026-26173
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-26172
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-26170
Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
2026-04-14
6.1
CVE-2026-26169
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
2026-04-14
7.8
CVE-2026-26168
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-26163
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-26159
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-26156
Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.
2026-04-14
7.8
CVE-2026-26153
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
2026-04-14
7.0
CVE-2026-26152
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
2026-04-14
7.8
CVE-2026-26143
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
2026-04-14
7.5
CVE-2026-23666
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
2026-04-14
7.8
CVE-2026-23657
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-04-14
5.5
CVE-2026-20806
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
2026-04-14
4.6
CVE-2026-20928
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
2026-04-14
5.5
CVE-2026-32212
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
2026-04-14
8.0
CVE-2026-33826
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
2026-04-14
6.1
CVE-2026-33822
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
2026-04-14
8.8
CVE-2026-33120
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
2026-04-14
7.5
CVE-2026-33116
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
2026-04-14
7.8
CVE-2026-33098
Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.
2026-04-14
7.5
CVE-2026-33096
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
2026-04-14
7.8
CVE-2026-33095
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-04-14
5.9
CVE-2026-32226
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
2026-04-14
7.0
CVE-2026-32224
Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
2026-04-14
6.8
CVE-2026-32223
Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
2026-04-14
7.8
CVE-2026-32222
Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
2026-04-14
8.4
CVE-2026-32221
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
2026-04-14
Page 280 / 7028