SEPTEMBER 25, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

170,521 records on file
Page 635 of 5,685
CVE ID Score Description
Exploit 1mo ago
5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.

Exploit 1mo ago
5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page.

1mo ago
6.1

Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.

1mo ago
6.1

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.

Exploit 1mo ago
4.3

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

1mo ago
6.1

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

1mo ago
5.5

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

1mo ago
5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

1mo ago
6.8

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

1mo ago
4.4

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

1mo ago
5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

1mo ago
5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

1mo ago
5.5

Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.

1mo ago
5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

1mo ago
5.5

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

1mo ago
5.5

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

KEV 1mo ago
4.3

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

KEV 1mo ago
6.5

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

1mo ago
6.1

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

1mo ago
5.5

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

1mo ago
6.7

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

1mo ago
6.7

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

1mo ago
6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

1mo ago
6.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack.

1mo ago
5.5

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.

1mo ago
5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

1mo ago
5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

1mo ago
5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

1mo ago
6.2

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

1mo ago
5.5

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.