CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-77480
8.8 HIGH

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-76196
7.4 HIGH

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to …

Sep 8, 2026
CVE-2026-76191
8.2 HIGH

Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of …

Sep 8, 2026
CVE-2026-73029
6.5 MEDIUM

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-73028
8.8 HIGH

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-73026
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73025
9.8 CRITICAL

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-73024
7.8 HIGH

Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73023
8.8 HIGH

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73022
7.0 HIGH

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73021
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73020
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73019
4.3 MEDIUM

Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-73018
8.8 HIGH

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73017
7.5 HIGH

Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-73016
8.8 HIGH

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73015
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73014
7.8 HIGH

Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73013
8.8 HIGH

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73012
8.8 HIGH

Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-73011
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73010
9.8 CRITICAL

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73009
9.8 CRITICAL

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73008
5.5 MEDIUM

Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-73007
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73006
8.8 HIGH

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-73005
7.0 HIGH

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73004
5.5 MEDIUM

Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-73003
7.0 HIGH

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73002
7.8 HIGH

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73001
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-73000
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72999
6.8 MEDIUM

Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-72997
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72996
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72995
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72994
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72993
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72992
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72991
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72990
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72989
7.5 HIGH

Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-72988
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-72987
8.1 HIGH

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-72986
8.8 HIGH

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-72985
6.8 MEDIUM

Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-72983
9.8 CRITICAL

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-72982
9.8 CRITICAL

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-72981
8.1 HIGH

Use after free in IP Helper allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-72980
4.4 MEDIUM

Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.