CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-69648
7.0 HIGH

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69645
7.0 HIGH

Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69643
8.0 HIGH

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69641
9.1 CRITICAL

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69638
8.4 HIGH

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-69637
5.7 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

Sep 8, 2026
CVE-2026-69636
6.5 MEDIUM

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a …

Sep 8, 2026
CVE-2026-69632
8.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69631
7.5 HIGH

Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69630
7.0 HIGH

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69629
8.8 HIGH

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69628
8.8 HIGH

Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69627
5.5 MEDIUM

Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69626
6.5 MEDIUM

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69625
8.0 HIGH

Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69624
6.5 MEDIUM

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

Sep 8, 2026
CVE-2026-69623
8.0 HIGH

Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69621
7.0 HIGH

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69620
8.1 HIGH

Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69619
8.0 HIGH

Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69618
5.5 MEDIUM

Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69617
7.0 HIGH

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69616
5.5 MEDIUM

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69615
3.5 LOW

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-69614
8.8 HIGH

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69613
7.0 HIGH

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69612
7.8 HIGH

Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69611
7.0 HIGH

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69610
7.0 HIGH

Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69609
5.5 MEDIUM

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69608
7.8 HIGH

Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69607
7.5 HIGH

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69606
7.0 HIGH

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69605
7.0 HIGH

Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69604
7.8 HIGH

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69603
8.8 HIGH

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-69602
7.1 HIGH

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69601
8.8 HIGH

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69600
7.0 HIGH

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69599
7.5 HIGH

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69598
8.8 HIGH

Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69597
7.1 HIGH

Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69595
9.8 CRITICAL

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69594
7.8 HIGH

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69593
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69592
7.8 HIGH

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69591
5.7 MEDIUM

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69590
9.8 CRITICAL

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Sep 8, 2026
CVE-2026-69589
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69588
7.5 HIGH

Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.