|
2111
|
8.7 |
HIGH
Network
|
-
|
-
|
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
|
CWE-20
Improper Input Validation
|
CVE-2026-27928
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2112
|
7.0 |
HIGH
Local
|
-
|
-
|
Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-27929
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2113
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-27930
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2114
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-27931
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2115
|
7.0 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
|
CWE-362
Race Condition
|
CVE-2026-32068
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2116
|
7.8 |
HIGH
Local
|
-
|
-
|
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-32069
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2117
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32070
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2118
|
7.5 |
HIGH
Network
|
-
|
-
|
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-32071
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2119
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
|
CWE-287
Improper Authentication
|
CVE-2026-32072
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2120
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32073
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|