Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-32073

7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Details

CVE-2026-32072

6.2

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

Details

CVE-2026-32071

7.5

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Null
Details

CVE-2026-32070

7.0

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Details

CVE-2026-32069

7.8

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Double
Details

CVE-2026-32068

7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

Concurrent
Details

CVE-2026-27931

5.5

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Out-of-bounds
Details

CVE-2026-27930

5.5

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Out-of-bounds
Details

CVE-2026-27929

7.0

Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.

Time-of-check
Details

CVE-2026-27928

8.7

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

Details
46/3864