CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48273
9.9 CRITICAL

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the …

Sep 8, 2026
CVE-2026-19232
9.9 CRITICAL

Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially …

Sep 8, 2026
CVE-2026-82004
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result …

Sep 8, 2026
CVE-2026-76201
9.3 CRITICAL

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form …

Sep 8, 2026
CVE-2026-76200
9.3 CRITICAL

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form …

Sep 8, 2026
CVE-2026-66302
9.8 CRITICAL

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-58822
9.8 CRITICAL

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no …

Sep 8, 2026
CVE-2026-49921
9.8 CRITICAL

In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no …

Sep 8, 2026
CVE-2026-28606
9.8 CRITICAL

In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote …

Sep 8, 2026
CVE-2026-83941
9.9 CRITICAL

Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-81376
9.6 CRITICAL

Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-78510
9.8 CRITICAL

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78509
9.8 CRITICAL

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78445
9.8 CRITICAL

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77493
9.8 CRITICAL

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73025
9.8 CRITICAL

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-73010
9.8 CRITICAL

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73009
9.8 CRITICAL

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-72983
9.8 CRITICAL

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-72982
9.8 CRITICAL

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-72979
9.8 CRITICAL

Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-70296
9.8 CRITICAL

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69910
9.8 CRITICAL

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69854
9.0 CRITICAL

Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69845
9.8 CRITICAL

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69829
9.8 CRITICAL

Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69824
9.8 CRITICAL

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69819
9.8 CRITICAL

Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69769
9.8 CRITICAL

Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69768
9.8 CRITICAL

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69730
9.8 CRITICAL

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69715
9.8 CRITICAL

Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69641
9.1 CRITICAL

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69595
9.8 CRITICAL

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69590
9.8 CRITICAL

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Sep 8, 2026
CVE-2026-69586
9.8 CRITICAL

Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69579
9.8 CRITICAL

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69525
9.8 CRITICAL

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69496
9.8 CRITICAL

Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69493
9.8 CRITICAL

Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69491
9.8 CRITICAL

Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69463
9.8 CRITICAL

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69431
9.8 CRITICAL

Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69408
9.8 CRITICAL

Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69356
9.3 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-69276
9.8 CRITICAL

Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-68839
9.8 CRITICAL

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-65669
9.6 CRITICAL

Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a …

Sep 8, 2026
CVE-2026-82533
9.6 CRITICAL

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host …

Sep 8, 2026
CVE-2026-79570
9.8 CRITICAL

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.