CVE Vulnerability Database

Search and browse 375,909 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-59127HIGH7.8Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-59126HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Ser...
CVE-2026-59125HIGH7Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-59124CRITICAL9.8Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to ...
CVE-2026-59122HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service...
CVE-2026-59119HIGH7.3Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2026-59113HIGH8.8Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-58651HIGH7.8Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-58650HIGH7.8Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a secur...
CVE-2026-58641HIGH7.8Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-58639MEDIUM6.5Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over...
CVE-2026-58612HIGH7.4Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information ...
CVE-2026-57105MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-57104HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an...
CVE-2026-56179HIGH8.3Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing...
CVE-2026-56174HIGH7.8Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-54984HIGH7.8Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
CVE-2026-54981HIGH7.8Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized...
CVE-2026-54123MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attac...
CVE-2026-54113HIGH7.5Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o...
CVE-2026-50516CRITICAL9.4Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el...
CVE-2026-50472HIGH7Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CVE-2026-49179HIGH8.8Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows a...
CVE-2026-48483MEDIUM5.4TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp...
CVE-2026-48446MEDIUM5.5CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...