CVE Vulnerability Database

Search and browse 398,020 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-33838HIGH7.8Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2026-33837HIGH7.8Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-33835HIGH7.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-33834HIGH7.8Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CVE-2026-33833HIGH8.2Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Lear...
CVE-2026-33821CRITICAL9.9Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privi...
CVE-2026-33117CRITICAL9.1The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path...
CVE-2026-33112HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-33110HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-32209MEDIUM4.4Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature l...
CVE-2026-32204HIGH7.8External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally...
CVE-2026-32185MEDIUM5.5Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofi...
CVE-2026-32177HIGH7.3Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-32175MEDIUM4.3A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully...
CVE-2026-32170MEDIUM6.7Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2026-32161HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Minip...
CVE-2026-31245MEDIUM5.3The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memori...
CVE-2026-31244MEDIUM6.5The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo...
CVE-2026-31243MEDIUM6.5The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functio...
CVE-2026-31242CRITICAL9.1The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via...
CVE-2026-31241MEDIUM6.5The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo...
CVE-2026-31240HIGH7.5The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical ...
CVE-2026-31239CRITICAL9.8The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-train...
CVE-2026-31238CRITICAL9.8The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. Whe...
CVE-2026-31237CRITICAL9.8The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When ...