CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-58613
7.8 HIGH

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58594
8.8 HIGH

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-58544
7.0 HIGH

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58542
7.8 HIGH

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-58541
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58540
7.8 HIGH

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58538
7.8 HIGH

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58537
7.8 HIGH

Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58536
7.8 HIGH

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58534
8.8 HIGH

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58532
7.8 HIGH

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58531
7.5 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-58530
7.8 HIGH

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-58529
7.1 HIGH

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-58527
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-58277
8.8 HIGH

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-57968
7.8 HIGH

Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-57108
7.5 HIGH

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-57102
8.8 HIGH

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Jul 14, 2026
CVE-2026-57101
7.1 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Jul 14, 2026
CVE-2026-57096
7.8 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-57094
8.8 HIGH

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-57093
7.0 HIGH

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-57091
7.8 HIGH

Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-57090
8.8 HIGH

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-57089
7.5 HIGH

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-57088
7.8 HIGH

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-57087
8.8 HIGH

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56650
7.8 HIGH

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56648
7.5 HIGH

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-56647
8.8 HIGH

Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-56644
7.8 HIGH

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56643
7.8 HIGH

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56642
8.8 HIGH

Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56197
8.8 HIGH

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56196
8.8 HIGH

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56194
8.8 HIGH

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-56189
7.8 HIGH

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-56187
7.0 HIGH

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56186
8.1 HIGH

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-56183
7.0 HIGH

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56182
7.8 HIGH

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56181
8.3 HIGH

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

Jul 14, 2026
CVE-2026-56176
7.8 HIGH

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56175
7.8 HIGH

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56173
7.0 HIGH

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-56156
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55949
7.8 HIGH

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55947
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55141
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.