CVE Vulnerability Database

Search and browse 389,967 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45646HIGH7.5Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove...
CVE-2026-45496MEDIUM5.5Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthori...
CVE-2026-44806HIGH7.5Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to ...
CVE-2026-44800HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-42990CRITICAL9.8Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
CVE-2026-42982HIGH7.8Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate p...
CVE-2026-42975HIGH8.8Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adja...
CVE-2026-42900HIGH8.1Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows ...
CVE-2026-41087MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-40422MEDIUM5.5Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-40400HIGH8Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
CVE-2026-40378HIGH7.5Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unau...
CVE-2026-36214MEDIUM6.4osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable...
CVE-2026-34349MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in...
CVE-2026-34348MEDIUM6.5Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over...
CVE-2026-34346MEDIUM5.5Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized at...
CVE-2026-34328MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to dis...
CVE-2026-33842MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-15703HIGH7.3A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unkn...
CVE-2026-15702MEDIUM6.3A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file co...
CVE-2026-15701CRITICAL9.8A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo...
CVE-2026-15700MEDIUM4.7A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th...
CVE-2026-15429HIGH8.8A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling...
CVE-2026-15428HIGH8.8An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain na...
CVE-2026-15427HIGH8.1An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf...