|
901
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
|
CWE-416
Use After Free
|
CVE-2026-27925
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
902
|
7.0 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-27926
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
903
|
7.8 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-27927
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
904
|
8.7 |
HIGH
Network
|
-
|
-
|
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
|
CWE-20
Improper Input Validation
|
CVE-2026-27928
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
905
|
7.0 |
HIGH
Local
|
-
|
-
|
Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-27929
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
906
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-27930
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
907
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-27931
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
908
|
7.0 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
|
CWE-362
Race Condition
|
CVE-2026-32068
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
909
|
7.8 |
HIGH
Local
|
-
|
-
|
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-32069
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
910
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32070
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|