Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-24294

7.8

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24293

7.8

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24292

7.8

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24291

7.8

Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24290

7.8

Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24289

7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24288

6.8

Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.

Microsoft
Details

CVE-2026-24287

7.8

External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24285

7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-24283

8.8

Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.

Microsoft
Details
749/3864