|
911
|
7.5 |
HIGH
Network
|
-
|
-
|
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-32071
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
|
CWE-287
Improper Authentication
|
CVE-2026-32072
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32073
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
7.8 |
HIGH
Local
|
-
|
-
|
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-32074
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32075
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
7.8 |
HIGH
Local
|
-
|
-
|
Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-32076
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
7.8 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-32077
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32078
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
|
CWE-200
Information Exposure
|
CVE-2026-32079
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32080
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|