SEPTEMBER 15, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

374,063 records on file
Page 868 of 12,469
CVE ID Score Description
1mo ago
7

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

1mo ago
6.5

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

1mo ago
6.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

1mo ago
6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

1mo ago
8.8

Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

1mo ago
7.8

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

1mo ago
6.4

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

1mo ago
7.1

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

1mo ago
6.5

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

1mo ago
7.5

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

1mo ago
8.1

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

KEV 1mo ago
5.3

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

KEV 1mo ago
7.8

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

1mo ago
7.1

Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

1mo ago
7.8

Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

1mo ago
9.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1mo ago
7.8

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

1mo ago
7.8

Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

1mo ago
6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

1mo ago
8.8

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

1mo ago
7.8

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

1mo ago
6.4

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

1mo ago
8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.

1mo ago
5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.