CVE Vulnerability Database

Search and browse 398,020 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-35438HIGH8.3Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-35436HIGH8.8Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-35433HIGH7.3Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-35429MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-35424HIGH7.5Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorize...
CVE-2026-35423MEDIUM5.4Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-35422MEDIUM6.5Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a sec...
CVE-2026-35421HIGH7.8Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
CVE-2026-35420HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-35419MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-35418HIGH7Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-35417HIGH7.8Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2026-35416HIGH7Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an...
CVE-2026-35415HIGH7.8Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges ...
CVE-2026-34687HIGH7.8Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu...
CVE-2026-34676HIGH7.8Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result...
CVE-2026-34675HIGH7.8Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result...
CVE-2026-34663MEDIUM5.5Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis...
CVE-2026-34662MEDIUM5.5Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result...
CVE-2026-34661HIGH7.8Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in ...
CVE-2026-34644HIGH7.8After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that cou...
CVE-2026-34643HIGH7.8After Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-34642HIGH7.8After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could re...
CVE-2026-34640HIGH7.8Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that c...
CVE-2026-34639HIGH7.8Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result...