CVE Vulnerability Database

Search and browse 375,898 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-62909HIGH7.8Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62908HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all...
CVE-2026-62902MEDIUM6.5Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information...
CVE-2026-62901HIGH7.5Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62900MEDIUM5.9Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose...
CVE-2026-62899MEDIUM5.9Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker...
CVE-2026-62898HIGH7.5Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62897HIGH7Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62894HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-62893CRITICAL9.8Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-62892HIGH7Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges loca...
CVE-2026-62890HIGH7.8Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
CVE-2026-62889HIGH8.1Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a ne...
CVE-2026-62888HIGH7.8Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-62887MEDIUM5.5Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62886HIGH7.8Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62885HIGH7.8Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62883MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62882MEDIUM4.3Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove...
CVE-2026-62881MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62880HIGH7.8Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-62878CRITICAL9.8Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-62877HIGH7.8Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62876HIGH7.8Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62872HIGH8.8Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.