CVE Database

45611+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-49784
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49783
7.8 HIGH

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Jul 14, 2026
CVE-2026-49184
8.4 HIGH

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-49183
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49181
7.5 HIGH

Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-49178
8.8 HIGH

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49176
7.8 HIGH

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49175
7.8 HIGH

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49173
7.8 HIGH

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49171
7.5 HIGH

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49170
7.8 HIGH

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49169
8.0 HIGH

Use after free in DNS Server allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49166
7.8 HIGH

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49165
7.1 HIGH

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-49164
8.1 HIGH

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49162
7.0 HIGH

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-48581
7.8 HIGH

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-48572
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-48571
7.0 HIGH

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-48564
8.8 HIGH

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-47632
8.8 HIGH

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Jul 14, 2026
CVE-2026-47296
7.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-45646
7.5 HIGH

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-44800
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-42982
7.8 HIGH

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-42975
8.0 HIGH

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

Jul 14, 2026
CVE-2026-42900
8.1 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-40400
8.0 HIGH

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-40378
7.5 HIGH

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-15703
7.3 HIGH

A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation …

Jul 14, 2026
CVE-2026-62643
7.2 HIGH

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information …

Jul 14, 2026
CVE-2026-60081
7.5 HIGH

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an …

Jul 14, 2026
CVE-2026-59841
7.5 HIGH

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert …

Jul 14, 2026
CVE-2026-59836
7.5 HIGH

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure …

Jul 14, 2026
CVE-2026-59835
8.6 HIGH

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access …

Jul 14, 2026
CVE-2026-59205
7.5 HIGH

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output …

Jul 14, 2026
CVE-2026-59204
7.5 HIGH

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per …

Jul 14, 2026
CVE-2026-59199
7.5 HIGH

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near …

Jul 14, 2026
CVE-2026-55651
7.1 HIGH

Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to …

Jul 14, 2026
CVE-2026-15392
7.7 HIGH

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the …

Jul 14, 2026
CVE-2026-12707
7.5 HIGH

Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the …

Jul 14, 2026
CVE-2026-12523
7.5 HIGH

Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines …

Jul 14, 2026
CVE-2025-53379
7.5 HIGH

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via …

Jul 14, 2026
CVE-2026-60114
7.5 HIGH

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to …

Jul 14, 2026
CVE-2026-58477
8.2 HIGH

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter …

Jul 14, 2026
CVE-2026-58476
8.1 HIGH

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a …

Jul 14, 2026
CVE-2026-51105
7.5 HIGH

Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler.

Jul 14, 2026
CVE-2026-15736
8.3 HIGH

Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through …

Jul 14, 2026
CVE-2026-15696
8.8 HIGH

A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the …

Jul 14, 2026
CVE-2026-15695
8.8 HIGH

A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.