|
2091
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-27908
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2092
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-27909
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2093
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-27910
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2094
|
7.8 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-27911
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2095
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
|
CWE-285
Improper Authorization
|
CVE-2026-27912
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2096
|
7.7 |
HIGH
Local
|
-
|
-
|
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
|
CWE-20
Improper Input Validation
|
CVE-2026-27913
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2097
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
|
CWE-284
Improper Access Control
|
CVE-2026-27914
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2098
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-27915
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2099
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-27916
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2100
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-27917
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|