VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-62908High· 7.0
1mo ago

Windows Backup Engine Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-65789High· 8.1
1mo ago

Windows DNS Server Remote Code Execution Vulnerability

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows Server 2016EPSS 0.71%via CVEORG
CVE-2026-65788High· 7.0
1mo ago

Desktop Window Manager Elevation of Privilege Vulnerability

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.26%via CVEORG
CVE-2026-65678High· 7.0
1mo ago

Windows Win32k Elevation of Privilege Vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-68820High· 7.0CISA KEV0dayPoC
1mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ AbyssalMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-65783High· 7.0
1mo ago

Windows Autopilot Elevation of Privilege Vulnerability

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-61357High· 7.8
1mo ago

Application Information Services Elevation of Privilege Vulnerability

Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.33%via CVEORG
CVE-2026-62726High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-62725High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-62708Medium· 6.4
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

▾ SunlitMicrosoft · Windows 11 Version 24H2EPSS 0.34%via CVEORG
CVE-2026-61938High· 7.0
1mo ago

Windows Installer Elevation of Privilege Vulnerability

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-61929High· 7.0
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.26%via CVEORG
CVE-2026-62788High· 7.0
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.26%via CVEORG
CVE-2026-62780High· 7.0
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.20%via CVEORG
CVE-2026-62778High· 8.1
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.54%via CVEORG
CVE-2026-62749High· 7.0
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-62734High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-62888High· 7.8
1mo ago

Windows DWM Core Library Elevation of Privilege Vulnerability

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-65776High· 7.0
1mo ago

Windows Win32k Elevation of Privilege Vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-66802High· 8.1
1mo ago

Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.54%via CVEORG
CVE-2026-65782High· 7.0
1mo ago

Windows Autopilot Elevation of Privilege Vulnerability

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-65781High· 7.0
1mo ago

Windows Autopilot Elevation of Privilege Vulnerability

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-65779High· 7.0
1mo ago

Windows Autopilot Elevation of Privilege Vulnerability

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-65778High· 7.0
1mo ago

Windows Autopilot Elevation of Privilege Vulnerability

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-65775High· 7.8
1mo ago

Windows Win32k Elevation of Privilege Vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-73282Medium· 4.8
1mo ago

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

▾ Sunlitopenbsd · opensshEPSS 0.16%via NVD
CVE-2026-18711High· 7.1
1mo ago

An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries again…

An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries again…

▾ Twilightmongodb · mongodbEPSS 0.46%via NVD
CVE-2026-18706Medium· 6.6
1mo ago

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. …

▾ Sunlitmongodb · mongodbEPSS 0.47%via NVD
CVE-2026-18700Medium· 6.5
1mo ago

An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a coll…

An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a coll…

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18692High· 8.8
1mo ago

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations coul…

▾ Twilightmongodb · mongodbEPSS 0.57%via NVD
CWE-416 vulnerabilities (CVEs) — page 15 · VulnSea