CVE-2026-32214
- EPSS 0.04%
- Published 14.04.2026 16:58:47
- Last modified 20.04.2026 14:43:36
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
CVE-2026-33829
- EPSS 0.06%
- Published 14.04.2026 16:58:46
- Last modified 17.04.2026 18:15:00
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33824
- EPSS 0.07%
- Published 14.04.2026 16:58:45
- Last modified 17.04.2026 19:21:23
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-33827
- EPSS 0.06%
- Published 14.04.2026 16:58:44
- Last modified 17.04.2026 19:18:33
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- EPSS 0.04%
- Published 14.04.2026 16:58:42
- Last modified 17.04.2026 18:20:32
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- EPSS 0.04%
- Published 14.04.2026 16:58:40
- Last modified 17.04.2026 19:23:15
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-33101
- EPSS 0.04%
- Published 14.04.2026 16:58:40
- Last modified 17.04.2026 19:22:06
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CVE-2026-32225
- EPSS 0.08%
- Published 14.04.2026 16:58:38
- Last modified 17.04.2026 19:33:37
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-32164
- EPSS 0.04%
- Published 14.04.2026 16:58:30
- Last modified 20.04.2026 16:43:28
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
CVE-2026-32162
- EPSS 0.03%
- Published 14.04.2026 16:58:29
- Last modified 20.04.2026 16:48:17
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.