CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-69525
9.8 CRITICAL

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69524
8.1 HIGH

Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69522
8.8 HIGH

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69518
8.8 HIGH

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69517
7.0 HIGH

Use after free in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69516
7.0 HIGH

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69514
7.5 HIGH

Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69513
7.8 HIGH

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69512
8.0 HIGH

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69511
8.8 HIGH

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69510
8.1 HIGH

Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69509
7.8 HIGH

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69508
7.8 HIGH

Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69507
5.7 MEDIUM

Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69505
8.0 HIGH

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69504
5.5 MEDIUM

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69503
8.0 HIGH

Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69501
7.0 HIGH

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69500
7.0 HIGH

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69499
8.8 HIGH

Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69498
7.0 HIGH

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69497
6.5 MEDIUM

Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69496
9.8 CRITICAL

Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69495
8.8 HIGH

Heap-based buffer overflow in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69494
8.8 HIGH

Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69493
9.8 CRITICAL

Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69492
7.0 HIGH

Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69491
9.8 CRITICAL

Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69490
6.8 MEDIUM

Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-69489
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69488
7.0 HIGH

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69485
8.8 HIGH

Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69483
4.7 MEDIUM

Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69482
7.1 HIGH

Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-69481
8.0 HIGH

Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69480
7.8 HIGH

Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69479
8.4 HIGH

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-69478
7.8 HIGH

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69477
7.3 HIGH

Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-69476
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69475
7.8 HIGH

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69474
4.8 MEDIUM

Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69473
7.0 HIGH

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69472
7.0 HIGH

Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69470
7.0 HIGH

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69469
6.6 MEDIUM

Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-69468
7.0 HIGH

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69467
7.8 HIGH

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69466
7.0 HIGH

Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69465
8.8 HIGH

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.