CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-69350
6.7 MEDIUM

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69349
5.7 MEDIUM

Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69348
7.8 HIGH

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69347
7.4 HIGH

Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-69346
8.0 HIGH

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69345
5.5 MEDIUM

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69344
5.5 MEDIUM

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69343
5.5 MEDIUM

Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69342
7.5 HIGH

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69341
7.0 HIGH

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69340
7.1 HIGH

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69339
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69338
7.1 HIGH

Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69337
7.1 HIGH

Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69336
7.1 HIGH

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69335
7.0 HIGH

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69334
8.8 HIGH

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69333
7.0 HIGH

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69332
8.0 HIGH

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69331
7.0 HIGH

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69329
7.5 HIGH

Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69328
7.8 HIGH

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69325
8.1 HIGH

Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-69324
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69323
7.8 HIGH

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69322
8.0 HIGH

Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69321
5.5 MEDIUM

Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-69319
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69318
5.5 MEDIUM

Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69317
5.7 MEDIUM

Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69316
4.7 MEDIUM

Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69315
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69314
7.1 HIGH

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69313
7.1 HIGH

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69312
7.8 HIGH

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69311
7.0 HIGH

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69310
7.0 HIGH

Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69309
7.0 HIGH

Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69308
5.5 MEDIUM

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69307
7.8 HIGH

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69305
7.1 HIGH

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69304
5.9 MEDIUM

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-69303
5.5 MEDIUM

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-69301
8.0 HIGH

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69300
7.0 HIGH

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69299
7.0 HIGH

Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69298
7.8 HIGH

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-69297
6.5 MEDIUM

Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69296
7.1 HIGH

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-69295
7.8 HIGH

Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.