CVE Vulnerability Database

Search and browse 396,711 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45598HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio...
CVE-2026-45597HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (ui...
CVE-2026-45596HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-45595MEDIUM5.4Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feat...
CVE-2026-45594MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an a...
CVE-2026-45593HIGH7.8Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.
CVE-2026-45592HIGH7.8Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges loc...
CVE-2026-45591HIGH7.5Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-45588HIGH7.9Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-45586HIGH7.8Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an ...
CVE-2026-45583HIGH8.1Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker t...
CVE-2026-45504HIGH8.8Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over...
CVE-2026-45503MEDIUM6.5Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network...
CVE-2026-45502MEDIUM5Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information ov...
CVE-2026-45501MEDIUM6.1Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a...
CVE-2026-45500MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows...
CVE-2026-45491MEDIUM5.5Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tamper...
CVE-2026-45490HIGH7.8Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-45487HIGH7Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attack...
CVE-2026-45486HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45485LOW3.3Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45484HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove...
CVE-2026-45483MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server ...
CVE-2026-45482HIGH8.4Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code ...
CVE-2026-45481MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...