Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
Showing 6,421 - 6,440 of 13,907 CVEs
CVE-2026-33103 MEDIUM - 5.5

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-32226 MEDIUM - 5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-32223 MEDIUM - 6.8

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Vendor: microsoft
Product: windows_11_24h2
Published: Apr 14, 2026
Source: NVD
CVE-2026-32220 MEDIUM - 4.4

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_11_24h2
Published: Apr 14, 2026
Source: NVD
CVE-2026-32218 MEDIUM - 5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_21h2
Published: Apr 14, 2026
Source: NVD
CVE-2026-32217 MEDIUM - 5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32216 MEDIUM - 5.5

Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.

Vendor: microsoft
Product: windows_11_26h1
Published: Apr 14, 2026
Source: NVD
CVE-2026-32215 MEDIUM - 5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1809
Published: Apr 14, 2026
Source: NVD
CVE-2026-32214 MEDIUM - 5.5

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32212 MEDIUM - 5.5

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32202 MEDIUM - 4.3

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32201 MEDIUM - 6.5

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: sharepoint_server
Published: Apr 14, 2026
Source: NVD
CVE-2026-32196 MEDIUM - 6.1

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-32181 MEDIUM - 5.5

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

Vendor: microsoft
Product: windows_10_21h2
Published: Apr 14, 2026
Source: NVD
CVE-2026-32176 MEDIUM - 6.7

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-32167 MEDIUM - 6.7

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-32151 MEDIUM - 6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32088 MEDIUM - 6.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack.

Vendor: microsoft
Product: windows_10_1809
Published: Apr 14, 2026
Source: NVD
CVE-2026-32085 MEDIUM - 5.5

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32084 MEDIUM - 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD