CVE Database

60452+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-68873
5.5 MEDIUM

Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68852
5.5 MEDIUM

Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68851
5.5 MEDIUM

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68849
4.7 MEDIUM

Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68843
5.5 MEDIUM

Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68842
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68833
6.8 MEDIUM

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-68831
5.5 MEDIUM

Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68830
5.5 MEDIUM

Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-68785
4.9 MEDIUM

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-68784
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68781
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68780
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68779
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68778
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68777
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68776
6.5 MEDIUM

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67648
6.5 MEDIUM

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67645
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67641
6.5 MEDIUM

Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-67633
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-67630
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67629
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67624
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67393
6.5 MEDIUM

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67390
6.5 MEDIUM

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67389
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67386
6.5 MEDIUM

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67383
6.5 MEDIUM

Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67369
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-66816
6.5 MEDIUM

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-65812
6.8 MEDIUM

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-64918
6.5 MEDIUM

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-62801
6.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a …

Sep 8, 2026
CVE-2026-62762
6.5 MEDIUM

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-58649
6.5 MEDIUM

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-54611
5.5 MEDIUM

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated …

Sep 8, 2026
CVE-2026-86668
4.3 MEDIUM

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation …

Sep 8, 2026
CVE-2026-86667
4.7 MEDIUM

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of …

Sep 8, 2026
CVE-2026-84391
6.5 MEDIUM

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

Sep 8, 2026
CVE-2026-84386
5.1 MEDIUM

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector …

Sep 8, 2026
CVE-2026-84385
5.4 MEDIUM

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 …

Sep 8, 2026
CVE-2026-82076
6.5 MEDIUM

An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal …

Sep 8, 2026
CVE-2026-82074
6.5 MEDIUM

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that …

Sep 8, 2026
CVE-2026-82073
6.5 MEDIUM

A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data …

Sep 8, 2026
CVE-2026-82070
6.5 MEDIUM

A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. …

Sep 8, 2026
CVE-2026-82068
6.5 MEDIUM

A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable …

Sep 8, 2026
CVE-2026-82066
4.3 MEDIUM

A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can …

Sep 8, 2026
CVE-2026-82065
6.5 MEDIUM

A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of …

Sep 8, 2026
CVE-2026-82063
5.3 MEDIUM

A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.