SEPTEMBER 26, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

380,739 records on file
Page 1385 of 12,692
CVE ID Score Description
1mo ago
7.8

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

1mo ago
3.9

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

1mo ago
8.4

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

1mo ago
7

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

1mo ago
7.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

1mo ago
7.8

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

1mo ago
8.1

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

1mo ago
5.5

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

1mo ago
6.8

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

1mo ago
8.4

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

1mo ago
5.5

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

1mo ago
7.8

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

1mo ago
5.5

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
9.1

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

1mo ago
8.1

Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
5.4

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

1mo ago
5.5

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

1mo ago
7.8

Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.

1mo ago
7.5

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

1mo ago
7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

1mo ago
7.8

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.