CVE Database

60452+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-69862
5.5 MEDIUM

Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69853
4.7 MEDIUM

Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69839
6.5 MEDIUM

Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69832
5.6 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69808
5.5 MEDIUM

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69803
5.9 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69794
5.5 MEDIUM

Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69792
4.7 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.

Sep 8, 2026
CVE-2026-69781
6.5 MEDIUM

Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.

Sep 8, 2026
CVE-2026-69771
4.7 MEDIUM

Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.

Sep 8, 2026
CVE-2026-69770
5.5 MEDIUM

Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69741
5.5 MEDIUM

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69739
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69734
6.5 MEDIUM

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69723
5.7 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69719
6.5 MEDIUM

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69713
4.4 MEDIUM

Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Sep 8, 2026
CVE-2026-69690
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-69684
5.5 MEDIUM

Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69683
6.5 MEDIUM

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69679
5.7 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

Sep 8, 2026
CVE-2026-69674
5.5 MEDIUM

Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally.

Sep 8, 2026
CVE-2026-69672
5.5 MEDIUM

Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69637
5.7 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

Sep 8, 2026
CVE-2026-69636
6.5 MEDIUM

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a …

Sep 8, 2026
CVE-2026-69627
5.5 MEDIUM

Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69626
6.5 MEDIUM

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69624
6.5 MEDIUM

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

Sep 8, 2026
CVE-2026-69618
5.5 MEDIUM

Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69616
5.5 MEDIUM

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69609
5.5 MEDIUM

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69591
5.7 MEDIUM

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69572
5.7 MEDIUM

Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69569
5.7 MEDIUM

Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69568
5.5 MEDIUM

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69566
6.8 MEDIUM

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-69562
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69559
5.8 MEDIUM

Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69554
5.5 MEDIUM

Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-69552
5.7 MEDIUM

Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69548
4.6 MEDIUM

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-69531
5.5 MEDIUM

Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-69527
5.5 MEDIUM

Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69507
5.7 MEDIUM

Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69504
5.5 MEDIUM

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69497
6.5 MEDIUM

Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69490
6.8 MEDIUM

Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-69483
4.7 MEDIUM

Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69474
4.8 MEDIUM

Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69469
6.6 MEDIUM

Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.