Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
26,802 matching · page 383/537Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-20956(opens NVD record) | High | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20955(opens NVD record) | High | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20953(opens NVD record) | High | 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20952(opens NVD record) | High | 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20951(opens NVD record) | High | 7.8 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20950(opens NVD record) | High | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20949(opens NVD record) | High | 7.8 | Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | Jan 13, 2026 |
| CVE-2026-20948(opens NVD record) | High | 7.8 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20947(opens NVD record) | High | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Jan 13, 2026 |
| CVE-2026-20946(opens NVD record) | High | 7.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20944(opens NVD record) | High | 8.4 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20943(opens NVD record) | High | 7.0 | Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20941(opens NVD record) | High | 7.8 | Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20940(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20939(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20938(opens NVD record) | High | 7.8 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20937(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20936(opens NVD record) | Medium | 4.3 | Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. | Jan 13, 2026 |
| CVE-2026-20935(opens NVD record) | Medium | 6.2 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20934(opens NVD record) | High | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | Jan 13, 2026 |
| CVE-2026-20932(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20931(opens NVD record) | High | 8.0 | External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. | Jan 13, 2026 |
| CVE-2026-20929(opens NVD record) | High | 7.5 | Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | Jan 13, 2026 |
| CVE-2026-20927(opens NVD record) | Medium | 5.3 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network. | Jan 13, 2026 |
| CVE-2026-20926(opens NVD record) | High | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | Jan 13, 2026 |
| CVE-2026-20925(opens NVD record) | Medium | 6.5 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | Jan 13, 2026 |
| CVE-2026-20924(opens NVD record) | High | 7.8 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20923(opens NVD record) | High | 7.8 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20922(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | Jan 13, 2026 |
| CVE-2026-20921(opens NVD record) | High | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | Jan 13, 2026 |
| CVE-2026-20920(opens NVD record) | High | 7.8 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20919(opens NVD record) | High | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | Jan 13, 2026 |
| CVE-2026-20918(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20877(opens NVD record) | High | 7.8 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20876(opens NVD record) | Medium | 6.7 | Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20875(opens NVD record) | High | 7.5 | Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | Jan 13, 2026 |
| CVE-2026-20874(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20873(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20872(opens NVD record) | Medium | 6.5 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | Jan 13, 2026 |
| CVE-2026-20871(opens NVD record) | High | 7.8 | Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20870(opens NVD record) | High | 7.8 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20869(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20868(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | Jan 13, 2026 |
| CVE-2026-20867(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20866(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20865(opens NVD record) | High | 7.8 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20864(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20863(opens NVD record) | High | 7.0 | Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |
| CVE-2026-20862(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. | Jan 13, 2026 |
| CVE-2026-20861(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | Jan 13, 2026 |