SEPTEMBER 21, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,146 records on file
Page 1056 of 4,939
CVE ID Score Description
1mo ago
8.2

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

1mo ago
7

Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

1mo ago
7

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

1mo ago
7

Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

1mo ago
8.1

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.

1mo ago
8.8

Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1mo ago
7.5

Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1mo ago
7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

1mo ago
8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

1mo ago
8.4

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

1mo ago
7.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

1mo ago
7.8

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

1mo ago
7.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

1mo ago
7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

KEV 1mo ago
7.8

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

1mo ago
7.8

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.