Common Vulnerabilities and Exposures (CVE)

CVE-2026-20810

Feb 26, 2026 15:04:39 UTC

Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-20408

Feb 26, 2026 15:04:39 UTC

In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVE-2026-20811

Feb 26, 2026 15:04:39 UTC

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20409

Feb 26, 2026 15:04:39 UTC

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitati...

CVE-2026-20814

Feb 26, 2026 15:04:38 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-20410

Feb 26, 2026 15:04:38 UTC

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitati...

CVE-2026-20815

Feb 26, 2026 15:04:38 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

CVE-2026-20411

Feb 26, 2026 15:04:38 UTC

In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Pat...

CVE-2026-20816

Feb 26, 2026 15:04:38 UTC

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-20412

Feb 26, 2026 15:04:38 UTC

In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploit...

CVE-2026-20817

Feb 26, 2026 15:04:38 UTC

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-20413

Feb 26, 2026 15:04:37 UTC

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitati...

CVE-2026-20820

Feb 26, 2026 15:04:37 UTC

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-20414

Feb 26, 2026 15:04:37 UTC

In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. ...

CVE-2026-20822

Feb 26, 2026 15:04:37 UTC

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.