CVE Database

134505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-49184
8.4 HIGH

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-49183
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49181
7.5 HIGH

Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-49180
5.5 MEDIUM

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-49178
8.8 HIGH

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49176
7.8 HIGH

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49175
7.8 HIGH

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49174
6.1 MEDIUM

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Jul 14, 2026
CVE-2026-49173
7.8 HIGH

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49172
9.8 CRITICAL

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49171
7.5 HIGH

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49170
7.8 HIGH

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49169
8.0 HIGH

Use after free in DNS Server allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49168
6.8 MEDIUM

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

Jul 14, 2026
CVE-2026-49167
4.7 MEDIUM

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49166
7.8 HIGH

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49165
7.1 HIGH

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-49164
8.1 HIGH

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49162
7.0 HIGH

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-48581
7.8 HIGH

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-48572
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-48571
7.0 HIGH

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-48564
8.8 HIGH

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-48561
9.6 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-47632
8.8 HIGH

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Jul 14, 2026
CVE-2026-47296
7.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-47282
6.5 MEDIUM

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-45646
7.5 HIGH

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-45496
5.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Jul 14, 2026
CVE-2026-44806
5.3 MEDIUM

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-44800
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-42990
9.8 CRITICAL

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-42982
7.8 HIGH

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-42975
8.0 HIGH

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

Jul 14, 2026
CVE-2026-42900
8.1 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-41087
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-40422
5.5 MEDIUM

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-40400
8.0 HIGH

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-40378
7.5 HIGH

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-36214
5.4 MEDIUM

osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip …

Jul 14, 2026
CVE-2026-34349
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-34348
6.5 MEDIUM

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-34346
5.5 MEDIUM

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-34328
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-33842
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-15703
7.3 HIGH

A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation …

Jul 14, 2026
CVE-2026-15702
6.3 MEDIUM

A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Such manipulation leads to improperly …

Jul 14, 2026
CVE-2026-15701
9.8 CRITICAL

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. …

Jul 14, 2026
CVE-2026-15700
4.7 MEDIUM

A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album …

Jul 14, 2026
CVE-2026-15429

A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.