CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78446
5.3 MEDIUM

Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-78445
9.8 CRITICAL

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78444
8.1 HIGH

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78442
8.8 HIGH

Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78441
6.5 MEDIUM

Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78439
8.8 HIGH

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77911
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-77909
7.7 HIGH

Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-77908
8.8 HIGH

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77907
8.8 HIGH

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77906
8.8 HIGH

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77905
7.0 HIGH

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77904
7.8 HIGH

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77901
8.8 HIGH

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77899
7.0 HIGH

Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77898
7.5 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77897
7.0 HIGH

Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77896
6.5 MEDIUM

Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77895
7.5 HIGH

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77894
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77893
7.5 HIGH

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77892
6.8 MEDIUM

No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-77891
6.4 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-77890
7.5 HIGH

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77889
7.5 HIGH

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77888
7.5 HIGH

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77887
6.4 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-77886
7.5 HIGH

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77505
8.1 HIGH

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77504
8.8 HIGH

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77503
8.4 HIGH

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77502
7.5 HIGH

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77501
7.5 HIGH

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77500
7.8 HIGH

Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77499
7.5 HIGH

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77498
7.5 HIGH

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77495
8.8 HIGH

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77494
7.5 HIGH

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77493
9.8 CRITICAL

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77492
5.5 MEDIUM

Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-77491
5.5 MEDIUM

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-77489
7.8 HIGH

Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77488
5.5 MEDIUM

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-77487
8.8 HIGH

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-77486
8.8 HIGH

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77485
7.0 HIGH

Use after free in SQL Server allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-77484
8.8 HIGH

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77483
8.8 HIGH

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-77482
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-77481
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.