| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20867 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20866 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20865 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20864 | Hig | 0.51 | 7.8 | 0.01 | Jan 13, 2026 | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20863 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20861 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20860 | Hig | 0.51 | 7.8 | 0.08 | Jan 13, 2026 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20859 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20858 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20857 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20856 | Hig | 0.53 | 8.1 | 0.01 | Jan 13, 2026 | Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-20854 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-20853 | Hig | 0.48 | 7.4 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-20852 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2026-20849 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20848 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20844 | Hig | 0.48 | 7.4 | 0.00 | Jan 13, 2026 | Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-20843 | Hig | 0.51 | 7.8 | 0.03 | Jan 13, 2026 | Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20842 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20840 | Hig | 0.51 | 7.8 | 0.05 | Jan 13, 2026 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | ||
| CVE-2026-20837 | Hig | 0.51 | 7.8 | 0.01 | Jan 13, 2026 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-20836 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20832 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | ||
| CVE-2026-20831 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20830 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20826 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20822 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20820 | Hig | 0.51 | 7.8 | 0.03 | Jan 13, 2026 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20817 | Hig | 0.51 | 7.8 | 0.05 | Jan 13, 2026 | Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20816 | Hig | 0.51 | 7.8 | 0.02 | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20815 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20814 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20811 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20810 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20809 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20808 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20804 | Hig | 0.50 | 7.7 | 0.01 | Jan 13, 2026 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2026-20803 | Hig | 0.47 | 7.2 | 0.01 | Jan 13, 2026 | Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-0386 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2025-37166 | Hig | 0.49 | 7.5 | 0.00 | Jan 13, 2026 | A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this… | ||
| CVE-2025-37165 | Hig | 0.49 | 7.5 | 0.00 | Jan 13, 2026 | A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets. | ||
| CVE-2025-10865 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal resource caused scenario where potential for use after free was… | ||
| CVE-2025-68707 | Hig | 0.57 | 8.8 | 0.00 | Jan 13, 2026 | An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated network-adjacent attackers to perform arbitrary configuration changes without providing credentials, as long as a valid admin session is active. This can result… | ||
| CVE-2025-59922 | Hig | 0.47 | 7.2 | 0.07 | Jan 13, 2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions… | ||
| CVE-2025-58411 | Hig | 0.57 | 8.8 | 0.00 | Jan 13, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused… | ||
| CVE-2025-46685 | Hig | 0.49 | 7.5 | 0.00 | Jan 13, 2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||
| CVE-2025-25652 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directory traversal. | ||
| CVE-2025-25249 | Hig | 0.53 | 8.1 | 0.01 | Jan 13, 2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5… | ||
| CVE-2026-0408 | Hig | 0.52 | 8.0 | 0.00 | Jan 13, 2026 | A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI. | ||
| CVE-2026-0407 | Hig | 0.52 | 8.0 | 0.00 | Jan 13, 2026 | An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel. |
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.08
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- risk 0.53cvss 8.1epss 0.01
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.
- risk 0.48cvss 7.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.49cvss 7.5epss 0.01
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- risk 0.48cvss 7.4epss 0.00
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.05
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.05
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.02
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally.
- risk 0.50cvss 7.7epss 0.01
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- risk 0.47cvss 7.2epss 0.01
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.49cvss 7.5epss 0.00
A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this…
- risk 0.49cvss 7.5epss 0.00
A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets.
- risk 0.51cvss 7.8epss 0.00
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal resource caused scenario where potential for use after free was…
- risk 0.57cvss 8.8epss 0.00
An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated network-adjacent attackers to perform arbitrary configuration changes without providing credentials, as long as a valid admin session is active. This can result…
- risk 0.47cvss 7.2epss 0.07
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions…
- risk 0.57cvss 8.8epss 0.00
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused…
- risk 0.49cvss 7.5epss 0.00
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- risk 0.49cvss 7.5epss 0.01
In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directory traversal.
- risk 0.53cvss 8.1epss 0.01
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5…
- risk 0.52cvss 8.0epss 0.00
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
- risk 0.52cvss 8.0epss 0.00
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.