Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-25169

5.5

Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

Microsoft
Details

CVE-2026-25168

5.5

Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

Microsoft
Details

CVE-2026-25167

7.4

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-25166

7.8

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

Microsoft
Details

CVE-2026-25165

7.8

Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24641

2.7

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may …

Fortinet
Details

CVE-2026-24640

6.6

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may …

Fortinet
Details

CVE-2026-24297

4.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.

Microsoft
Details

CVE-2026-24296

7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24295

7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Microsoft
Details
748/3864