CVE Vulnerability Database

Search and browse 389,967 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-49181CRITICAL9.8Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over...
CVE-2026-49180MEDIUM5.5Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize...
CVE-2026-49178HIGH8.8Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a netw...
CVE-2026-49176HIGH7.8Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
CVE-2026-49175HIGH7.8Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-49174MEDIUM6.1Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering...
CVE-2026-49173HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49172CRITICAL9.8Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
CVE-2026-49171HIGH7.8Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
CVE-2026-49170HIGH7.8Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privi...
CVE-2026-49169HIGH8.8Use after free in DNS Server allows an authorized attacker to execute code over a network.
CVE-2026-49168MEDIUM6.8Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges wi...
CVE-2026-49167HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49166HIGH7.8Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-49165HIGH7.1Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information local...
CVE-2026-49164CRITICAL9.8Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a ne...
CVE-2026-49162HIGH7Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-48581HIGH7.8Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges loca...
CVE-2026-48572HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer all...
CVE-2026-48571HIGH7Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-48564HIGH8.8Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-48561CRITICAL9.6Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all...
CVE-2026-47632HIGH8.8Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges o...
CVE-2026-47296HIGH7.5Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2026-47282MEDIUM6.5Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos...