CVE Database

60452+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-69457
5.5 MEDIUM

Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69453
5.5 MEDIUM

Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-69449
6.7 MEDIUM

Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-69425
4.7 MEDIUM

Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-69416
5.7 MEDIUM

Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

Sep 8, 2026
CVE-2026-69415
6.8 MEDIUM

Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69409
6.5 MEDIUM

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69406
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69405
5.7 MEDIUM

Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

Sep 8, 2026
CVE-2026-69403
5.5 MEDIUM

Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69395
6.5 MEDIUM

Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69393
5.7 MEDIUM

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69390
5.5 MEDIUM

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69382
5.9 MEDIUM

Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69381
4.6 MEDIUM

Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-69376
5.5 MEDIUM

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69375
6.5 MEDIUM

Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Sep 8, 2026
CVE-2026-69374
6.5 MEDIUM

Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69373
6.7 MEDIUM

Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69372
5.7 MEDIUM

Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69369
5.5 MEDIUM

Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69367
5.5 MEDIUM

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69361
6.5 MEDIUM

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-69353
5.5 MEDIUM

Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69351
5.5 MEDIUM

Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information …

Sep 8, 2026
CVE-2026-69350
6.7 MEDIUM

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69349
5.7 MEDIUM

Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69345
5.5 MEDIUM

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69344
5.5 MEDIUM

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69343
5.5 MEDIUM

Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69339
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69321
5.5 MEDIUM

Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-69318
5.5 MEDIUM

Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69317
5.7 MEDIUM

Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69316
4.7 MEDIUM

Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69315
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69308
5.5 MEDIUM

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69304
5.9 MEDIUM

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69303
5.5 MEDIUM

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69297
6.5 MEDIUM

Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69294
5.5 MEDIUM

Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69288
5.5 MEDIUM

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69286
5.5 MEDIUM

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69267
6.5 MEDIUM

Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68898
6.5 MEDIUM

Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-68895
5.5 MEDIUM

Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68891
4.7 MEDIUM

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68886
5.5 MEDIUM

Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68881
5.5 MEDIUM

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68874
5.7 MEDIUM

Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.