Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27197
Total
2065
Critical
8240
High
8439
Medium
CVE ID Severity Score Description Published
CVE-2026-34336 HIGH 7.8 Buffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally. May 12, 2026
CVE-2026-34334 HIGH 7.8 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-34333 HIGH 7.8 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-34332 HIGH 8.0 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. May 12, 2026
CVE-2026-34331 HIGH 7.0 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-34330 HIGH 7.8 Integer overflow or wraparound in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-34329 HIGH 8.8 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. May 12, 2026
CVE-2026-33841 HIGH 7.8 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-33840 HIGH 7.8 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-33839 HIGH 7.0 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-33838 HIGH 7.8 Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-33837 HIGH 7.8 Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-33835 HIGH 7.8 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-33834 HIGH 7.8 Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-33833 HIGH 8.2 Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over … May 12, 2026
CVE-2026-33821 HIGH 7.7 Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. May 12, 2026
CVE-2026-33117 CRITICAL 9.1 Improper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature over a network. May 12, 2026
CVE-2026-33112 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. May 12, 2026
CVE-2026-33110 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. May 12, 2026
CVE-2026-32209 MEDIUM 4.4 Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. May 12, 2026
CVE-2026-32204 HIGH 7.8 External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-32185 MEDIUM 5.5 Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally. May 12, 2026
CVE-2026-32177 HIGH 7.3 Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. May 12, 2026
CVE-2026-32175 MEDIUM 4.3 A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories … May 12, 2026
CVE-2026-32170 MEDIUM 6.7 Double free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges locally. May 12, 2026