CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-68785
4.9 MEDIUM

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-68784
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68781
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68780
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68779
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68778
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68777
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-68776
6.5 MEDIUM

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67648
6.5 MEDIUM

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67645
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67641
6.5 MEDIUM

Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-67633
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-67630
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67629
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67624
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67393
6.5 MEDIUM

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67390
6.5 MEDIUM

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67389
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67386
6.5 MEDIUM

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67383
6.5 MEDIUM

Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-67369
6.5 MEDIUM

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-66816
6.5 MEDIUM

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-65812
6.8 MEDIUM

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-64918
6.5 MEDIUM

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-62801
6.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a …

Sep 8, 2026
CVE-2026-62762
6.5 MEDIUM

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-58649
6.5 MEDIUM

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-54611
5.5 MEDIUM

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated …

Sep 8, 2026
CVE-2026-86668
4.3 MEDIUM

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation …

Sep 8, 2026
CVE-2026-86667
4.7 MEDIUM

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of …

Sep 8, 2026
CVE-2026-84391
6.5 MEDIUM

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

Sep 8, 2026
CVE-2026-84386
5.1 MEDIUM

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector …

Sep 8, 2026
CVE-2026-84385
5.4 MEDIUM

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 …

Sep 8, 2026
CVE-2026-82076
6.5 MEDIUM

An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal …

Sep 8, 2026
CVE-2026-82074
6.5 MEDIUM

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that …

Sep 8, 2026
CVE-2026-82073
6.5 MEDIUM

A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data …

Sep 8, 2026
CVE-2026-82070
6.5 MEDIUM

A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. …

Sep 8, 2026
CVE-2026-82068
6.5 MEDIUM

A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable …

Sep 8, 2026
CVE-2026-82066
4.3 MEDIUM

A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can …

Sep 8, 2026
CVE-2026-82065
6.5 MEDIUM

A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of …

Sep 8, 2026
CVE-2026-82063
5.3 MEDIUM

A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing …

Sep 8, 2026
CVE-2026-82062
5.5 MEDIUM

A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the applyOps command by …

Sep 8, 2026
CVE-2026-82060
5.4 MEDIUM

In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key …

Sep 8, 2026
CVE-2026-82059
5.3 MEDIUM

An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By …

Sep 8, 2026
CVE-2026-82058
6.5 MEDIUM

A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON …

Sep 8, 2026
CVE-2026-82057
6.5 MEDIUM

A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By specifying a custom WiredTiger …

Sep 8, 2026
CVE-2026-82056
5.3 MEDIUM

A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index …

Sep 8, 2026
CVE-2026-82055
6.5 MEDIUM

A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially …

Sep 8, 2026
CVE-2026-82054
6.5 MEDIUM

A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema …

Sep 8, 2026
CVE-2026-82052
6.5 MEDIUM

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.