SEPTEMBER 19, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

377,750 records on file
Page 259 of 12,592
CVE ID Score Description
5h ago
6.5

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

5h ago
8.8

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

5h ago
6.8

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

5h ago
8.8

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

5h ago
9.6

Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.

5h ago
6.5

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

5h ago
8.8

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

5h ago
7.5

Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

5h ago
7.8

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

5h ago
7.8

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

5h ago
6.5

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.

5h ago
6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

5h ago
7.5

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

5h ago
8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

5h ago
8.8

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

5h ago
7.8

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

5h ago
7

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

5h ago
6.5

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

5h ago
7.8

Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

5h ago
7.8

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

5h ago
7.8

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

5h ago
7.5

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

5h ago
7.5

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

5h ago
7.8

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

5h ago
7.8

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

5h ago
7.8

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

5h ago
8.1

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Exploit 5h ago
5.5

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.

5h ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Exploit 5h ago
3.1

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.