SEPTEMBER 19, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,088 records on file
Page 861 of 4,937
CVE ID Score Description
1mo ago
7.8

Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

1mo ago
7.3

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

1mo ago
7.3

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

1mo ago
7.8

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

1mo ago
7.3

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

1mo ago
7.5

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

1mo ago
7

Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

1mo ago
7.3

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

1mo ago
8

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

1mo ago
8.1

Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.

1mo ago
7.5

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

1mo ago
7.5

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

1mo ago
7.8

Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.

1mo ago
8.8

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

Exploit 1mo ago
7.8

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit this logic flaw by supplying crafted, URL encoded traversal sequences that bypass directory restrictions and allow access to files outside the intended web root. Successful exploitation may allow authenticated attackers to get disclosure of sensitive system files and credentials, while unauthenticated attackers may gain access to non-sensitive static assets.

1mo ago
7.9

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

1mo ago
8.6

Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.

1mo ago
7.9

Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

1mo ago
8.2

Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.