CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-56187
7.0 HIGH

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56186
8.1 HIGH

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-56184
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-56183
7.0 HIGH

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56182
7.8 HIGH

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56181
8.3 HIGH

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

Jul 14, 2026
CVE-2026-56178
5.5 MEDIUM

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56176
7.8 HIGH

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56175
7.8 HIGH

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56173
7.0 HIGH

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56168
6.5 MEDIUM

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-56159
9.8 CRITICAL

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56157
5.4 MEDIUM

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-56156
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55949
7.8 HIGH

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55947
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55944
9.8 CRITICAL

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-55898
6.1 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55145
6.3 MEDIUM

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

Jul 14, 2026
CVE-2026-55142
5.5 MEDIUM

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55141
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55140
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55139
5.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55138
5.5 MEDIUM

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55137
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55136
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55135
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-55134
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55133
7.8 HIGH

Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55132
7.8 HIGH

Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55131
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55130
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55129
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55128
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55127
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55126
7.3 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-55125
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55124
5.5 MEDIUM

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55123
7.8 HIGH

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55122
7.1 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55121
5.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55120
7.8 HIGH

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55058
7.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55057
5.5 MEDIUM

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55056
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55055
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55054
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-55053
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55052
8.8 HIGH

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-55051
6.5 MEDIUM

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.