CVE-2026-0390
- EPSS 0.09%
- Veröffentlicht 14.04.2026 16:57:29
- Zuletzt bearbeitet 24.04.2026 20:17:13
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
CVE-2026-32165
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:29
- Zuletzt bearbeitet 20.04.2026 16:42:08
Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
CVE-2026-32160
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:28
- Zuletzt bearbeitet 20.04.2026 18:15:39
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-32158
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:27
- Zuletzt bearbeitet 20.04.2026 18:21:02
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-32159
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:27
- Zuletzt bearbeitet 20.04.2026 18:19:16
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-32157
- EPSS 0.13%
- Veröffentlicht 14.04.2026 16:57:26
- Zuletzt bearbeitet 07.05.2026 19:57:08
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-32154
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:25
- Zuletzt bearbeitet 17.04.2026 15:10:35
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-32156
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:25
- Zuletzt bearbeitet 23.04.2026 14:51:17
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:24
- Zuletzt bearbeitet 20.04.2026 18:27:30
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-32089
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:23
- Zuletzt bearbeitet 21.04.2026 15:04:29
Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.