CVE Database

60452+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-77896
6.5 MEDIUM

Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77892
6.8 MEDIUM

No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-77891
6.4 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-77887
6.4 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-77492
5.5 MEDIUM

Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-77491
5.5 MEDIUM

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-77488
5.5 MEDIUM

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-73029
6.5 MEDIUM

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-73019
4.3 MEDIUM

Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-73008
5.5 MEDIUM

Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-73004
5.5 MEDIUM

Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-72999
6.8 MEDIUM

Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-72985
6.8 MEDIUM

Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-72980
4.4 MEDIUM

Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.

Sep 8, 2026
CVE-2026-72978
5.9 MEDIUM

Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-72977
6.5 MEDIUM

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-72976
5.0 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-72975
6.5 MEDIUM

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-72974
6.5 MEDIUM

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-72966
5.5 MEDIUM

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-72964
5.5 MEDIUM

Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-72956
6.5 MEDIUM

Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-72948
6.7 MEDIUM

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72947
6.4 MEDIUM

Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72945
5.5 MEDIUM

Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-72942
6.5 MEDIUM

Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-72939
6.5 MEDIUM

Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-72938
6.5 MEDIUM

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-72937
5.5 MEDIUM

Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-72935
6.7 MEDIUM

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72931
4.7 MEDIUM

Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.

Sep 8, 2026
CVE-2026-72927
6.7 MEDIUM

Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71350
6.8 MEDIUM

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-71349
6.8 MEDIUM

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-71348
6.8 MEDIUM

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-71341
5.5 MEDIUM

Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-71339
6.7 MEDIUM

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71338
6.4 MEDIUM

Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71329
6.8 MEDIUM

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-70582
6.4 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70575
5.3 MEDIUM

Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-70290
5.5 MEDIUM

Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-70145
5.5 MEDIUM

Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-70124
5.9 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-70091
5.9 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-70019
6.5 MEDIUM

Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69930
5.9 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69929
5.9 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69895
4.7 MEDIUM

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69878
6.4 MEDIUM

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.