SEPTEMBER 21, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,146 records on file
Page 424 of 4,939
CVE ID Score Description
1mo ago
7.8

Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

1mo ago
7.8

Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

1mo ago
7.8

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

1mo ago
8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

1mo ago
8.1

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

1mo ago
7.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

1mo ago
8.4

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

1mo ago
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

1mo ago
7

Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

1mo ago
7.5

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

1mo ago
8.8

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

1mo ago
7.2

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

1mo ago
7

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

1mo ago
7.4

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

1mo ago
8.4

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

1mo ago
7.5

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

1mo ago
8.8

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

1mo ago
8.8

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

1mo ago
7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

1mo ago
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

1mo ago
7

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.