AUGUST 30, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

143,459 records on file
Page 388 of 4,782
CVE ID Score Description
26d ago
7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

26d ago
7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

26d ago
7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

26d ago
7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

26d ago
7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

26d ago
7.1

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

26d ago
7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

26d ago
7.8

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

26d ago
7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

26d ago
7.9

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

26d ago
7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

26d ago
8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

26d ago
8.2

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

26d ago
7

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

26d ago
8.4

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

26d ago
7.3

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

26d ago
8.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

26d ago
8

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

26d ago
7

Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

26d ago
7.8

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

26d ago
8.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

26d ago
7.1

Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.

Exploit 26d ago
7.2

md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the resulting page without sanitization, allowing arbitrary JavaScript execution in the context of the affected domain. This issue has been patched in version 1.10.3.

Exploit 26d ago
7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH's bundled XML parser expands nested <!ENTITY> declarations without a depth or count bound, so a small DTD can describe a body that expands exponentially ("billion laughs"). The PIDF body of a SIP PUBLISH is fed to this parser before any digest check, letting an unauthenticated network attacker force unbounded CPU and memory consumption with a single request. This issue has been patched in version 1.11.0.

26d ago
7.8

Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

26d ago
7.8

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

26d ago
7.9

Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

26d ago
7

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

26d ago
7.1

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

26d ago
8.8

Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.