CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-42911
7.0 HIGH

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-42910
7.8 HIGH

Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-42909
7.5 HIGH

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-42908
7.5 HIGH

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

Jun 9, 2026
CVE-2026-42905
7.8 HIGH

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-42902
7.8 HIGH

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-42837
7.8 HIGH

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-42836
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-42835
8.1 HIGH

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information …

Jun 9, 2026
CVE-2026-42829
7.8 HIGH

Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-42828
7.8 HIGH

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-42765
7.5 HIGH

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the …

Jun 9, 2026
CVE-2026-42764
7.5 HIGH

Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation …

Jun 9, 2026
CVE-2026-42570
7.5 HIGH

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, …

Jun 9, 2026
CVE-2026-42567
7.5 HIGH

Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time …

Jun 9, 2026
CVE-2026-41108
7.0 HIGH

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-41098
8.4 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-41092
7.8 HIGH

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-40409
7.8 HIGH

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Jun 9, 2026
CVE-2026-40404
7.8 HIGH

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Jun 9, 2026
CVE-2026-40376
7.5 HIGH

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Jun 9, 2026
CVE-2026-40371
8.8 HIGH

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

Jun 9, 2026
CVE-2026-34335
7.0 HIGH

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-34183
7.5 HIGH

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A …

Jun 9, 2026
CVE-2026-34181
7.4 HIGH

Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing …

Jun 9, 2026
CVE-2026-34180
7.5 HIGH

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read …

Jun 9, 2026
CVE-2026-33828
7.8 HIGH

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-32193
8.8 HIGH

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

Jun 9, 2026
CVE-2026-24181
7.3 HIGH

NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead …

Jun 9, 2026
CVE-2026-24180
7.3 HIGH

NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead …

Jun 9, 2026
CVE-2026-22926
7.8 HIGH

Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.

Jun 9, 2026
CVE-2026-49948
8.1 HIGH

Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global …

Jun 9, 2026
CVE-2026-24065
8.1 HIGH

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients …

Jun 9, 2026
CVE-2026-24064
7.8 HIGH

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed …

Jun 9, 2026
CVE-2026-10727
7.2 HIGH

An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root

Jun 9, 2026
CVE-2026-52907
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change these comparisons from > vs >= …

Jun 9, 2026
CVE-2026-52906
7.7 HIGH

In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of replaced Since commit 1f3e4142c0eb ("9p: convert …

Jun 9, 2026
CVE-2026-46332
8.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive buffering cc1352_bootloader_rx() appends each serdev chunk into the fixed rx_buffer …

Jun 9, 2026
CVE-2026-46330
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40. As reported by Al Viro, …

Jun 9, 2026
CVE-2026-46328
7.3 HIGH

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cpu timers requires an additional step beyond …

Jun 9, 2026
CVE-2026-46327
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The function dm_blk_report_zones tests if the device is suspended …

Jun 9, 2026
CVE-2026-46326
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct initialisation Make sure that the spi_transfer struct is zeroed …

Jun 9, 2026
CVE-2026-46324
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink hooks nft_netdev_unregister_hooks and __nft_unregister_flowtable_net_hooks need to use list_del_rcu(), this …

Jun 9, 2026
CVE-2026-46323
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and …

Jun 9, 2026
CVE-2026-46322
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one() When build_skb() fails in tun_xdp_one(), the function …

Jun 9, 2026
CVE-2026-46321
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter …

Jun 9, 2026
CVE-2026-46320
7.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp() tap_get_user_xdp() rejects a frame shorter than ETH_HLEN …

Jun 9, 2026
CVE-2026-46319
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after ct_ft When looking up a flow table …

Jun 9, 2026
CVE-2026-46317
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_lock kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the …

Jun 9, 2026
CVE-2017-20250
7.5 HIGH

Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send …

Jun 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.