Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26990
Total
2034
Critical
8144
High
8390
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42983 | HIGH | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42981 | HIGH | 8.1 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | Jun 09, 2026 |
| CVE-2026-42980 | HIGH | 7.8 | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42979 | HIGH | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42978 | HIGH | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42977 | HIGH | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42974 | HIGH | 8.1 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | Jun 09, 2026 |
| CVE-2026-42973 | MEDIUM | 5.5 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-42972 | MEDIUM | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-42971 | MEDIUM | 5.5 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-42970 | MEDIUM | 5.5 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-42969 | MEDIUM | 5.5 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-42968 | MEDIUM | 5.5 | Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-42916 | HIGH | 7.8 | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42915 | MEDIUM | 5.7 | Incorrect calculation of buffer size in Windows TCP/IP allows an authorized attacker to deny service over an adjacent network. | Jun 09, 2026 |
| CVE-2026-42914 | MEDIUM | 5.3 | Windows Kerberos Denial of Service Vulnerability | Jun 09, 2026 |
| CVE-2026-42913 | HIGH | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 09, 2026 |
| CVE-2026-42912 | HIGH | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42911 | HIGH | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42910 | HIGH | 7.8 | Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |
| CVE-2026-42909 | HIGH | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Jun 09, 2026 |
| CVE-2026-42908 | HIGH | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | Jun 09, 2026 |
| CVE-2026-42907 | MEDIUM | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-42906 | MEDIUM | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-42905 | HIGH | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Jun 09, 2026 |