Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
4933
Current result set after filter and search.
Exploited Flagged
4189
Rows with a non-empty exploitation signal.
Distinct CWE
162
Unique weakness classes in this view.
Modules
1528
Unique inferred driver or component labels.
Reset
Release Month
May 2026
25 CVE | last update 1 day(s) ago
Release 2026-05-12 Patch Tuesday Count 17
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-34336
Windows DWM Core Library
Exploitation Unlikely
Windows DWM Core Library Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
CVE-2026-35419
Windows DWM Core Library
Exploitation Less Likely
Windows DWM Core Library Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-05-12 No
CVE-2026-35423
Windows 11 Telnet Client
Exploitation Unlikely
Windows 11 Telnet Client Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Microsoft
CVE-2026-40380
Windows Volume Manager Extension Driver
Exploitation Less Likely
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
CVSS vector: AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-33837
Windows TCP/IP Local
Exploitation More Likely
Windows TCP/IP Local Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
CVE-2026-40398
Windows Remote Desktop Services
Exploitation More Likely
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-35420
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
CVE-2026-33841
Windows Kernel
Exploitation More Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Anonymous
Andrew Fasano with NIST Center for AI Standards and Innovation
Minwoo Jeong (P1nkjelly) with KAIST Hacking Lab
r0keb with Calif
Kentaro Kawane with GMO Cybersecurity by Ierae, Inc.
CVE-2026-40403
Windows Graphics Component
Exploitation Less Likely
Windows Graphics Component Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Calif.io and Milad Nasr (Anthropic) with Claude with Calif.io and Anthropic
CVE-2026-35421
Windows GDI
Exploitation Unlikely
Windows GDI Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
pwn2addr
CVE-2026-41096
Windows DNS Client
Exploitation Unlikely
Windows DNS Client Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
WARP team at Microsoft
CVE-2026-40407
Windows Common Log File System Driver
Exploitation Unlikely
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Microsoft
CVE-2026-34343
Windows Application Identity (AppID) Subsystem
Exploitation Less Likely
Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
CVE-2026-34329
Microsoft Message Queuing (MSMQ)
Exploitation Less Likely
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
CVE-2026-40377
Microsoft Cryptographic Services
Exploitation Less Likely
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
CVE-2026-40399
Windows TCP/IP
Exploitation Less Likely
Windows TCP/IP Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
WARP & MORSE teams at Microsoft
CVE-2026-41089
Windows Netlogon
Exploitation Less Likely
Windows Netlogon Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Windows Attack Research & Protection (WARP) with Microsoft
Release 2026-05-10 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-33079
Mistune ReDoS in LINK_TITLE_RE allows
No latest release note
Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
No CVSS vector published
2026-05-10 - -
Release 2026-05-07 Other / OOB Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-32934
CoreDNS DNS-over-QUIC unbounded goroutine growth leads to
No latest release note
CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service
No CVSS vector published
2026-05-07 - -
CVE-2026-42154
Prometheus: remote read endpoint allows
No latest release note
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2026-05-07 - -
CVE-2026-33823
Microsoft Team Events Portal
N/A
Microsoft Team Events Portal Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
2026-05-07 No
Reported By
Adi Ivascu
CVE-2026-24072
Apache HTTP Server: mod_rewrite
No latest release note
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
No CVSS vector published
2026-05-07 - -
CVE-2026-33845
Gnutls: gnutls
No latest release note
Gnutls: gnutls: denial of service via dtls zero-length fragment
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2026-05-07 - -
Release 2026-05-05 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-37457
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a
No latest release note
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2026-05-05 - -
Release 2026-05-03 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-6843
Nano: nano: format string vulnerability leads to
No latest release note
Nano: nano: format string vulnerability leads to denial of service
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2026-05-03 - -
Release Month
April 2026
25 CVE | last update 1 day(s) ago
Release 2026-04-29 Other / OOB Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-33999
Xorg: xwayland: x.org x server
No latest release note
Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2026-04-29 - -
CVE-2026-34003
Xorg: xwayland: x.org x server: information exposure and
No latest release note
Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2026-04-29 - -
Release 2026-04-23 Other / OOB Count 4
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-33819
Microsoft Bing
N/A
Microsoft Bing Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-23 No -
CVE-2026-32172
Microsoft Power Apps
N/A
Microsoft Power Apps Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
2026-04-23 No
Reported By
Hritik Sateesh, Application Security Researcher with Stantec
CVE-2026-24303
Microsoft Partner Center
N/A
Microsoft Partner Center Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
2026-04-23 No
Reported By
Shyam Datti with Microsoft Corporation
CVE-2026-6409
the Protobuf PHP library during the parsing of untrusted input
No latest release note
Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input
No CVSS vector published
2026-04-23 - -
Release 2026-04-18 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-70873
An
No latest release note
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
2026-04-18 - -
Release 2026-04-14 Patch Tuesday Count 18
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-26152
Microsoft Cryptographic Services
Exploitation Less Likely
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Anonymous
CVE-2026-26162
Windows OLE
Exploitation Less Likely
Windows OLE Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Hart Wilson with Microsoft
CVE-2026-20806
Windows COM Server
Exploitation Unlikely
Windows COM Server Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Pwnforr777
CVE-2026-32222
Windows Win32k
Exploitation Less Likely
Windows Win32k Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Anonymous
CVE-2026-32077
Windows UPnP Device Host
Exploitation Less Likely
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
David Zhu with Microsoft
CVE-2026-27920
Windows UPnP Device Host
Exploitation Less Likely
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Anonymous
CVE-2026-27919
Windows UPnP Device Host
Exploitation Less Likely
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Anonymous
CVE-2026-26161
Windows Sensor Data Service
Exploitation Less Likely
Windows Sensor Data Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Andrew Ruddick with Microsoft Red Team
CVE-2026-32183
Windows Snipping Tool
Exploitation Less Likely
Windows Snipping Tool Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Nacl
Zeeshan Shaikh (@bugzzzhunter) working with TrendAI Zero Day Initiative
Julien Brianceau with Microsoft
CVE-2026-26178
Windows Advanced Rasterization Platform
Exploitation Less Likely
Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Dongzhuo Zhao working with ADLab of Venustech
CVE-2026-32212
Universal Plug and Play (upnp.dll)
Exploitation Less Likely
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Anonymous
CVE-2026-32218
Windows Kernel
Exploitation Less Likely
Windows Kernel Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
MasterOogway
CVE-2026-32217
Windows Kernel
Exploitation Less Likely
Windows Kernel Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
MasterOogway
CVE-2026-32215
Windows Kernel
Exploitation Less Likely
Windows Kernel Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
MasterOogway
CVE-2026-32184
Microsoft High Performance Compute (HPC) Pack
Exploitation Less Likely
Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Long Zhang
CVE-2026-32216
Windows Redirected Drive Buffering System
Exploitation Less Likely
Windows Redirected Drive Buffering System Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Erik Egsgard with Field Effect
Xinyu Yu with Tsinghua University
Shuqiao Zhang with Tsinghua University
ziiiro
CVE-2026-32071
Windows Local Security Authority Subsystem Service (LSASS)
Exploitation Less Likely
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Howard McGreehan with MSRC V&M
CVE-2026-32080
Windows WalletService
Exploitation Less Likely
Windows WalletService Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Prev Page 2 / 99 | rows 51-100 of 4933 Next