SEPTEMBER 23, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,560 records on file
Page 1217 of 4,952
CVE ID Score Description
Exploit 1mo ago
7.8

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Exploit 1mo ago
8.8

In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines, potentially resulting in remote code execution.

Exploit 1mo ago
8.8

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.

1mo ago
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

1mo ago
7

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.

1mo ago
8.8

Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.

1mo ago
8.8

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

1mo ago
7.8

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.

1mo ago
8.1

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

1mo ago
7.8

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

1mo ago
7

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.

1mo ago
8.8

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.

1mo ago
7.8

Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.

1mo ago
7.5

Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

1mo ago
7.5

Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.

1mo ago
8.5

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

1mo ago
7.5

Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.

1mo ago
7.8

Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

KEV 1mo ago
8.8

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

1mo ago
7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.