CVEs
Sourced from CVEProject/cvelistV5 and the CISA KEV catalog.
351,354 CVEs
CVSS
CVE
Description
KEV added
PoCs
7.8
CVE-2026-20955
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
2026-01-13
—
8.4
CVE-2026-20953
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-01-13
—
7.8
CVE-2026-20951
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
2026-01-13
—
7.8
CVE-2026-20946
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
2026-01-13
—
8.4
CVE-2026-20944
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-01-13
—
7.0
CVE-2026-20943
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-01-13
—
7.8
CVE-2026-20940
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20938
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.5
CVE-2026-20934
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
2026-01-13
—
5.5
CVE-2026-20932
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
2026-01-13
—
5.3
CVE-2026-20927
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
2026-01-13
—
7.5
CVE-2026-20926
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
2026-01-13
—
6.5
CVE-2026-20925
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
2026-01-13
—
7.8
CVE-2026-20924
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20923
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20922
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
2026-01-13
—
7.5
CVE-2026-20921
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
2026-01-13
—
7.8
CVE-2026-20920
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.5
CVE-2026-20919
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
2026-01-13
—
7.8
CVE-2026-20918
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20877
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
2026-01-13
—
6.7
CVE-2026-20876
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.5
CVE-2026-20875
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
2026-01-13
—
7.0
CVE-2026-20869
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20865
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20864
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20860
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20859
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20858
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20857
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
2026-01-13
—
8.1
CVE-2026-20856
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
2026-01-13
—
7.7
CVE-2026-20852
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
2026-01-13
—
6.2
CVE-2026-20851
Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.
2026-01-13
—
6.5
CVE-2026-20847
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
2026-01-13
—
7.4
CVE-2026-20844
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
2026-01-13
—
7.0
CVE-2026-20842
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
2026-01-13
—
7.8
CVE-2026-20840
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
2026-01-13
—
5.5
CVE-2026-20839
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
2026-01-13
—
5.5
CVE-2026-20838
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
2026-01-13
—
7.8
CVE-2026-20837
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
2026-01-13
—
7.0
CVE-2026-20836
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
2026-01-13
—
5.5
CVE-2026-20835
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.
2026-01-13
—
4.6
CVE-2026-20834
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
2026-01-13
—
5.5
CVE-2026-20833
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
2026-01-13
—
7.8
CVE-2026-20832
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
2026-01-13
—
7.8
CVE-2026-20831
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
2026-01-13
—
5.5
CVE-2026-20829
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
2026-01-13
—
4.6
CVE-2026-20828
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
2026-01-13
—
5.5
CVE-2026-20827
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
2026-01-13
—
7.8
CVE-2026-20826
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.
2026-01-13
—