SEPTEMBER 20, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

169,836 records on file
Page 331 of 5,662
CVE ID Score Description
1mo ago
6.4

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

1mo ago
6.5

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

KEV 1mo ago
5.3

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

1mo ago
6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

1mo ago
6.4

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

1mo ago
5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

1mo ago
6.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

1mo ago
4.7

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.

1mo ago
6.8

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

1mo ago
6.5

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

1mo ago
6.6

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

1mo ago
5.5

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

1mo ago
5.5

Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

1mo ago
5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

1mo ago
5.5

Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.

1mo ago
5.5

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

1mo ago
6.8

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.

1mo ago
6.8

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

1mo ago
5.5

Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.

1mo ago
6.2

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.

1mo ago
6.2

Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.

1mo ago
6.6

Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.

1mo ago
5.5

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

1mo ago
6.5

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

1mo ago
4.6

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

1mo ago
5.5

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

1mo ago
6.1

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

1mo ago
6.8

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

1mo ago
4.7

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

1mo ago
6.5

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.