CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-71351
7.0 HIGH

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71350
6.8 MEDIUM

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-71349
6.8 MEDIUM

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-71348
6.8 MEDIUM

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-71345
7.8 HIGH

Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-71343
7.8 HIGH

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-71342
7.0 HIGH

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71341
5.5 MEDIUM

Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-71340
7.0 HIGH

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71339
6.7 MEDIUM

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71338
6.4 MEDIUM

Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71337
7.8 HIGH

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71336
8.8 HIGH

Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-71334
7.8 HIGH

Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71333
7.0 HIGH

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71332
7.0 HIGH

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-71330
7.5 HIGH

Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information …

Sep 8, 2026
CVE-2026-71329
6.8 MEDIUM

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

Sep 8, 2026
CVE-2026-71328
8.8 HIGH

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-70587
7.5 HIGH

Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-70586
8.8 HIGH

Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-70585
7.0 HIGH

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-70584
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70583
7.8 HIGH

Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70582
6.4 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70581
7.8 HIGH

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70579
7.5 HIGH

Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-70578
7.0 HIGH

Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70577
7.0 HIGH

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70575
5.3 MEDIUM

Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-70574
7.8 HIGH

Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70573
7.0 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70572
7.8 HIGH

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70570
7.5 HIGH

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Sep 8, 2026
CVE-2026-70569
7.8 HIGH

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70568
7.0 HIGH

Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70567
7.0 HIGH

Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70565
7.0 HIGH

Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70564
7.8 HIGH

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70563
8.1 HIGH

Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-70562
7.0 HIGH

Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70351
8.8 HIGH

Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-70342
8.1 HIGH

Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-70334
7.8 HIGH

Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Sep 8, 2026
CVE-2026-70296
9.8 CRITICAL

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-70290
5.5 MEDIUM

Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-70289
7.8 HIGH

Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70283
7.0 HIGH

Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-70203
8.8 HIGH

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-70145
5.5 MEDIUM

Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.