CVE Vulnerability Database

Search and browse 398,020 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40399HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an ...
CVE-2026-40398HIGH7.8Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
CVE-2026-40397HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2026-40382HIGH7.8Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-40381HIGH7.8Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-40380MEDIUM6.2Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physi...
CVE-2026-40379HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform ...
CVE-2026-40377HIGH7.8Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally...
CVE-2026-40374MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose i...
CVE-2026-40370HIGH8.8External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-40369HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-40368HIGH8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-40367HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40366HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40365HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-40364HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t...
CVE-2026-40363HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40362HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40361HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40360HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-40359HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40358HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40357HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-35440MEDIUM5.5Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose...
CVE-2026-35439HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...