CVE Vulnerability Database
Search and browse 389,967 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45646 | HIGH | 7.5 | 0.8% | Jul 14, 2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove... |
| CVE-2026-45496 | MEDIUM | 5.5 | 0.5% | Jul 14, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthori... |
| CVE-2026-44806 | HIGH | 7.5 | 0.8% | Jul 14, 2026 | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to ... |
| CVE-2026-44800 | HIGH | 7.8 | 0.2% | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification... |
| CVE-2026-42990 | CRITICAL | 9.8 | 0.7% | Jul 14, 2026 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42982 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate p... |
| CVE-2026-42975 | HIGH | 8.8 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adja... |
| CVE-2026-42900 | HIGH | 8.1 | 0.4% | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows ... |
| CVE-2026-41087 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis... |
| CVE-2026-40422 | MEDIUM | 5.5 | 0.3% | Jul 14, 2026 | Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
| CVE-2026-40400 | HIGH | 8 | 0.6% | Jul 14, 2026 | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. |
| CVE-2026-40378 | HIGH | 7.5 | 0.8% | Jul 14, 2026 | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unau... |
| CVE-2026-36214 | MEDIUM | 6.4 | 0.3% | Jul 14, 2026 | osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable... |
| CVE-2026-34349 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in... |
| CVE-2026-34348 | MEDIUM | 6.5 | 0.7% | Jul 14, 2026 | Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over... |
| CVE-2026-34346 | MEDIUM | 5.5 | 0.2% | Jul 14, 2026 | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized at... |
| CVE-2026-34328 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to dis... |
| CVE-2026-33842 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis... |
| CVE-2026-15703 | HIGH | 7.3 | 0.3% | Jul 14, 2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unkn... |
| CVE-2026-15702 | MEDIUM | 6.3 | 0.3% | Jul 14, 2026 | A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file co... |
| CVE-2026-15701 | CRITICAL | 9.8 | 0.8% | Jul 14, 2026 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo... |
| CVE-2026-15700 | MEDIUM | 4.7 | 0.4% | Jul 14, 2026 | A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th... |
| CVE-2026-15429 | HIGH | 8.8 | 0.4% | Jul 14, 2026 | A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling... |
| CVE-2026-15428 | HIGH | 8.8 | 0.9% | Jul 14, 2026 | An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain na... |
| CVE-2026-15427 | HIGH | 8.1 | 0.5% | Jul 14, 2026 | An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf... |
