SEPTEMBER 17, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

147,530 records on file
Page 100 of 4,918
CVE ID Score Description
5h ago
8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

5h ago
8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

5h ago
8.8

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

5h ago
8.8

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

5h ago
8.8

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

5h ago
8.8

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

5h ago
7.5

Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

5h ago
7.8

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

5h ago
7.8

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

5h ago
7.5

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

5h ago
8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

5h ago
8.8

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

5h ago
7.8

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

5h ago
7

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

5h ago
7.8

Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

5h ago
7.8

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

5h ago
7.8

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

5h ago
7.5

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

5h ago
7.5

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

5h ago
7.8

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

5h ago
7.8

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

5h ago
7.8

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

5h ago
8.1

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

5h ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

5h ago
8.1

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Exploit 5h ago
7.6

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the requested resource was registered, not that it matched the original grant. An OAuth client approved for one workflow could substitute a different workflow URL in the resource parameter and obtain a valid token for an unapproved workflow accessible to the consenting user. This issue is fixed in versions 2.37.7 and 2.38.1.

5h ago
8.1

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>

5h ago
7.2

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

5h ago
7.5

An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to expend CPU resources without any rate limiting, degrading or denying service to legitimate clients. No authentication, elevated privileges, or user interaction is required. Only availability is affected; data confidentiality and integrity are not impacted.

Exploit 5h ago
8.1

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary code execution.