CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-80081
8.8 HIGH

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-80080
8.8 HIGH

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-80079
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80078
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80077
8.8 HIGH

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-80076
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80075
7.8 HIGH

Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-80074
8.8 HIGH

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-80073
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-79904
5.0 MEDIUM

Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature …

Sep 8, 2026
CVE-2026-78526
8.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78525
8.8 HIGH

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78524
8.8 HIGH

Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78523
5.9 MEDIUM

Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-78522
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78521
8.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78520
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78519
8.8 HIGH

Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78518
8.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78517
8.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78516
4.3 MEDIUM

Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-78515
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78514
8.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78513
5.5 MEDIUM

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-78512
8.8 HIGH

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78511
8.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78510
9.8 CRITICAL

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78509
9.8 CRITICAL

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78508
4.6 MEDIUM

Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-78507
8.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78506
5.5 MEDIUM

Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-78505
8.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78504
8.8 HIGH

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78503
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78502
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78464
7.0 HIGH

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-78463
8.8 HIGH

Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78462
8.8 HIGH

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-78461
7.4 HIGH

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over …

Sep 8, 2026
CVE-2026-78457
7.0 HIGH

Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-78456
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78455
4.3 MEDIUM

Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-78454
5.5 MEDIUM

Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-78453
6.5 MEDIUM

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78452
4.6 MEDIUM

Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-78451
6.8 MEDIUM

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-78450
8.1 HIGH

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78449
8.1 HIGH

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78448
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-78447
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.