Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
26,352 matching · page 375/528Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-20844(opens NVD record) | High | 7.4 | Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20843(opens NVD record) | High | 7.8 | Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20842(opens NVD record) | High | 7.0 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20840(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20839(opens NVD record) | Medium | 5.5 | Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20838(opens NVD record) | Medium | 5.5 | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20837(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20836(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20835(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20834(opens NVD record) | Medium | 4.6 | Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | Jan 13, 2026 |
| CVE-2026-20833(opens NVD record) | Medium | 5.5 | Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20832(opens NVD record) | High | 7.8 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | Jan 13, 2026 |
| CVE-2026-20831(opens NVD record) | High | 7.8 | Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20830(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20829(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20828(opens NVD record) | Medium | 4.6 | Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | Jan 13, 2026 |
| CVE-2026-20827(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20826(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20825(opens NVD record) | Medium | 4.4 | Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20824(opens NVD record) | Medium | 5.5 | Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. | Jan 13, 2026 |
| CVE-2026-20823(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20822(opens NVD record) | High | 7.8 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20821(opens NVD record) | Medium | 6.2 | Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20820(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20819(opens NVD record) | Medium | 5.5 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20818(opens NVD record) | Medium | 6.2 | Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20817(opens NVD record) | High | 7.8 | Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20816(opens NVD record) | High | 7.8 | Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20815(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20814(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20812(opens NVD record) | Medium | 6.5 | Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. | Jan 13, 2026 |
| CVE-2026-20811(opens NVD record) | High | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20810(opens NVD record) | High | 7.8 | Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20809(opens NVD record) | High | 7.8 | Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20808(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20805(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20804(opens NVD record) | High | 7.7 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. | Jan 13, 2026 |
| CVE-2026-20803(opens NVD record) | High | 7.2 | Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. | Jan 13, 2026 |
| CVE-2026-0386(opens NVD record) | High | 7.5 | Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. | Jan 13, 2026 |
| CVE-2025-67685(opens NVD record) | Low | 3.8 | A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests. | Jan 13, 2026 |
| CVE-2025-65784(opens NVD record) | Medium | 6.5 | Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request. | Jan 13, 2026 |
| CVE-2025-64155(opens NVD record) | Critical | 9.8 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests. | Jan 13, 2026 |
| CVE-2025-59922(opens NVD record) | High | 7.2 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. | Jan 13, 2026 |
| CVE-2025-58693(opens NVD record) | Medium | 6.5 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests. | Jan 13, 2026 |
| CVE-2025-46685(opens NVD record) | High | 7.5 | Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | Jan 13, 2026 |
| CVE-2025-46684(opens NVD record) | Medium | 6.6 | Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering. | Jan 13, 2026 |
| CVE-2025-25249(opens NVD record) | High | 8.1 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets | Jan 13, 2026 |
| CVE-2025-71098(opens NVD record) | Medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved: ip6_gre: make ip6gre_header() robust Over the years, syzbot found many ways to crash the kernel in ip6gre_header() [1]. This involves team or bonding drivers ability to dynamically change their dev->needed_headroom and/or dev->hard_header_len In this particular crash mld_newpack() allocated an skb with a too small reserve/headroom, and by the time mld_sendpack() was called, syzbot managed to attach an ip6gre device. [1] skbuff: skb_under_panic: text:ffffffff8a1d69a8 len:136 put:40 head:ffff888059bc7000 data:ffff888059bc6fe8 tail:0x70 end:0x6c0 dev:team0 ------------[ cut here ]------------ kernel BUG at net/core/skbuff.c:213 ! <TASK> skb_under_panic net/core/skbuff.c:223 [inline] skb_push+0xc3/0xe0 net/core/skbuff.c:2641 ip6gre_header+0xc8/0x790 net/ipv6/ip6_gre.c:1371 dev_hard_header include/linux/netdevice.h:3436 [inline] neigh_connected_output+0x286/0x460 net/core/neighbour.c:1618 neigh_output include/net/neighbour.h:556 [inline] ip6_finish_output2+0xfb3/0x1480 net/ipv6/ip6_output.c:136 __ip6_finish_output net/ipv6/ip6_output.c:-1 [inline] ip6_finish_output+0x234/0x7d0 net/ipv6/ip6_output.c:220 NF_HOOK_COND include/linux/netfilter.h:307 [inline] ip6_output+0x340/0x550 net/ipv6/ip6_output.c:247 NF_HOOK+0x9e/0x380 include/linux/netfilter.h:318 mld_sendpack+0x8d4/0xe60 net/ipv6/mcast.c:1855 mld_send_cr net/ipv6/mcast.c:2154 [inline] mld_ifc_work+0x83e/0xd60 net/ipv6/mcast.c:2693 | Jan 13, 2026 |
| CVE-2025-71097(opens NVD record) | Medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix reference count leak when using error routes with nexthop objects When a nexthop object is deleted, it is marked as dead and then fib_table_flush() is called to flush all the routes that are using the dead nexthop. The current logic in fib_table_flush() is to only flush error routes (e.g., blackhole) when it is called as part of network namespace dismantle (i.e., with flush_all=true). Therefore, error routes are not flushed when their nexthop object is deleted: # ip link add name dummy1 up type dummy # ip nexthop add id 1 dev dummy1 # ip route add 198.51.100.1/32 nhid 1 # ip route add blackhole 198.51.100.2/32 nhid 1 # ip nexthop del id 1 # ip route show blackhole 198.51.100.2 nhid 1 dev dummy1 As such, they keep holding a reference on the nexthop object which in turn holds a reference on the nexthop device, resulting in a reference count leak: # ip link del dev dummy1 [ 70.516258] unregister_netdevice: waiting for dummy1 to become free. Usage count = 2 Fix by flushing error routes when their nexthop is marked as dead. IPv6 does not suffer from this problem. | Jan 13, 2026 |
| CVE-2025-71095(opens NVD record) | Medium | 5.5 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix the crash issue for zero copy XDP_TX action There is a crash issue when running zero copy XDP_TX action, the crash log is shown below. [ 216.122464] Unable to handle kernel paging request at virtual address fffeffff80000000 [ 216.187524] Internal error: Oops: 0000000096000144 [#1] SMP [ 216.301694] Call trace: [ 216.304130] dcache_clean_poc+0x20/0x38 (P) [ 216.308308] __dma_sync_single_for_device+0x1bc/0x1e0 [ 216.313351] stmmac_xdp_xmit_xdpf+0x354/0x400 [ 216.317701] __stmmac_xdp_run_prog+0x164/0x368 [ 216.322139] stmmac_napi_poll_rxtx+0xba8/0xf00 [ 216.326576] __napi_poll+0x40/0x218 [ 216.408054] Kernel panic - not syncing: Oops: Fatal exception in interrupt For XDP_TX action, the xdp_buff is converted to xdp_frame by xdp_convert_buff_to_frame(). The memory type of the resulting xdp_frame depends on the memory type of the xdp_buff. For page pool based xdp_buff it produces xdp_frame with memory type MEM_TYPE_PAGE_POOL. For zero copy XSK pool based xdp_buff it produces xdp_frame with memory type MEM_TYPE_PAGE_ORDER0. However, stmmac_xdp_xmit_back() does not check the memory type and always uses the page pool type, this leads to invalid mappings and causes the crash. Therefore, check the xdp_buff memory type in stmmac_xdp_xmit_back() to fix this issue. | Jan 13, 2026 |