|
161
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-35421
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-35420
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-35419
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
New
|
CWE-367 CWE-416
Time-of-check Time-of-use (TOCTOU) Race Condition Use After Free
|
CVE-2026-35418
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
7.8 |
HIGH
Local
|
-
|
-
|
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
New
|
CWE-843
Type Confusion
|
CVE-2026-35417
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-35416
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-35415
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
7.8 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
New
|
CWE-362
Race Condition
|
CVE-2026-34351
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-34350
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-34347
|
2026-05-13 03:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|