SEPTEMBER 26, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

380,870 records on file
Page 1389 of 12,696
CVE ID Score Description
1mo ago
9.8

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

1mo ago
7.8

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

1mo ago
5.3

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

1mo ago
7.9

Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

1mo ago
7

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

1mo ago
4.3

User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.

1mo ago
7.1

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

1mo ago
8.8

Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

1mo ago
5.5

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

1mo ago
8

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.

1mo ago
7.8

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

1mo ago
3.9

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

1mo ago
8.4

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

1mo ago
7

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

1mo ago
7.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

1mo ago
7.8

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

1mo ago
8.1

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

1mo ago
5.5

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

1mo ago
6.8

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

1mo ago
8.4

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

1mo ago
5.5

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

1mo ago
7.8

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

1mo ago
5.5

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
9.1

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.