VYPR

CVEs

117,520 total · page 490 of 2,351

  • CVE-2026-20867HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20866HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20865HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20864HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20863HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20861HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20860HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.08

    Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20859HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20858HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20857HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20856HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-20854HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

  • CVE-2026-20853HigJan 13, 2026
    risk 0.48cvss 7.4epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-20852HigJan 13, 2026
    risk 0.50cvss 7.7epss 0.01

    Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

  • CVE-2026-20849HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20848HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20844HigJan 13, 2026
    risk 0.48cvss 7.4epss 0.00

    Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-20843HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20842HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20840HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.05

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

  • CVE-2026-20837HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

  • CVE-2026-20836HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20832HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

  • CVE-2026-20831HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20830HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20826HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20822HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20820HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.03

    Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20817HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.05

    Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20816HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.02

    Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20815HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20814HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20811HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20810HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20809HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20808HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20804HigJan 13, 2026
    risk 0.50cvss 7.7epss 0.01

    Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

  • CVE-2026-20803HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-0386HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2025-37166HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this…

  • CVE-2025-37165HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets.

  • CVE-2025-10865HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal resource caused scenario where potential for use after free was…

  • CVE-2025-68707HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated network-adjacent attackers to perform arbitrary configuration changes without providing credentials, as long as a valid admin session is active. This can result…

  • CVE-2025-59922HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.07

    An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions…

  • CVE-2025-58411HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused…

  • CVE-2025-46685HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-25652HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directory traversal.

  • CVE-2025-25249HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.01

    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5…

  • CVE-2026-0408HigJan 13, 2026
    risk 0.52cvss 8.0epss 0.00

    A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.

  • CVE-2026-0407HigJan 13, 2026
    risk 0.52cvss 8.0epss 0.00

    An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.