SEPTEMBER 13, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

373,161 records on file
Page 842 of 12,439
CVE ID Score Description
1mo ago
5.5

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

1mo ago
8.8

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

1mo ago
7.8

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

1mo ago
6.1

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

1mo ago
7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

1mo ago
9.8

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

1mo ago
7.5

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

1mo ago
8

Use after free in DNS Server allows an authorized attacker to execute code over a network.

1mo ago
6.8

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

1mo ago
4.7

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

1mo ago
7.1

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

1mo ago
8.1

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

1mo ago
7

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

1mo ago
9.6

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

1mo ago
8.8

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

1mo ago
7.5

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

1mo ago
6.5

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

1mo ago
7.5

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

1mo ago
5.5

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

1mo ago
5.3

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

1mo ago
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

1mo ago
9.8

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

1mo ago
7.8

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.