|
2121
|
7.8 |
HIGH
Local
|
-
|
-
|
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-32074
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2122
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32075
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2123
|
7.8 |
HIGH
Local
|
-
|
-
|
Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-32076
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2124
|
7.8 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-32077
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2125
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32078
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2126
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
|
CWE-200
Information Exposure
|
CVE-2026-32079
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2127
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32080
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2128
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
|
CWE-200
Information Exposure
|
CVE-2026-32081
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2129
|
7.0 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
|
CWE-362
Race Condition
|
CVE-2026-32082
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2130
|
7.0 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
|
CWE-362
Race Condition
|
CVE-2026-32083
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|