Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-20839 - Windows 10 Version 1607 Plugin
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
CVE-2026-20839
CVE-2026-20838 - Windows 11 version 22H3 Plugin
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-20838
CVE-2026-20835 - Windows 11 Version 24H2 Plugin
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.
CVE-2026-20835
CVE-2026-20833 - Windows Server 2008 R2 Service Pack 1 Plugin
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
CVE-2026-20833
CVE-2026-20834 - Windows 10 Version 1607 Plugin
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
CVE-2026-20834
CVE-2026-20829 - Windows 10 Version 1809 Plugin
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
CVE-2026-20829
CVE-2026-20827 - Windows 10 Version 1607 Plugin
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
CVE-2026-20827
CVE-2026-20828 - Windows 10 Version 1607 Plugin
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-20828
CVE-2026-20821 - Windows 10 Version 1607 Plugin
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.
CVE-2026-20821
CVE-2026-20824 - Windows 10 Version 1607 Plugin
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-20824
CVE-2026-20823 - Windows 10 Version 1607 Plugin
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-20823
CVE-2026-20825 - Windows 10 Version 1809 Plugin
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-20825
CVE-2026-20818 - Windows Server 2016 Plugin
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.
CVE-2026-20818
CVE-2026-20819 - Windows 11 version 22H3 Plugin
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
CVE-2026-20819
CVE-2026-20812 - Windows 10 Version 1607 Plugin
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
CVE-2026-20812
CVE-2026-20805 - Windows 10 Version 1607 Plugin
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
CVE-2026-20805
CVE-2026-0408 - EX2800 Plugin
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
CVE-2026-0408
CVE-2026-0407 - EX2800 Plugin
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.
CVE-2026-0407
CVE-2026-0406 - XR1000v2 Plugin
An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections.
CVE-2026-0406
CVE-2026-0405 - CBR750 Plugin
An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.
CVE-2026-0405
