CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-68824
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-68787
7.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-68786
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-68775
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67643
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67642
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67639
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67638
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67636
8.5 HIGH

Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67631
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67388
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67385
8.8 HIGH

Use after free in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67384
8.8 HIGH

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67381
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-67380
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67379
8.5 HIGH

Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67378
8.5 HIGH

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67376
7.5 HIGH

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-67373
8.8 HIGH

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-67370
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-67368
8.8 HIGH

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-66820
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-66819
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-66818
8.8 HIGH

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-66814
8.8 HIGH

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-65772
8.8 HIGH

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-62895
8.8 HIGH

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-62813
7.5 HIGH

Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-62810
7.8 HIGH

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-62804
7.8 HIGH

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-62759
7.5 HIGH

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

Sep 8, 2026
CVE-2026-62744
8.8 HIGH

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-62706
8.8 HIGH

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-62697
7.8 HIGH

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-62694
7.0 HIGH

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-58611
7.8 HIGH

Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-58600
7.8 HIGH

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-58599
7.8 HIGH

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-57099
7.5 HIGH

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-57098
7.5 HIGH

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-56198
7.8 HIGH

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-56177
7.8 HIGH

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-56172
7.8 HIGH

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-55007
8.1 HIGH

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-50349
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-47297
8.1 HIGH

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-86073
7.6 HIGH

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to …

Sep 8, 2026
CVE-2026-84393
8.1 HIGH

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure …

Sep 8, 2026
CVE-2026-84387
7.2 HIGH

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 …

Sep 8, 2026
CVE-2026-82075
7.5 HIGH

An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.