CVE Vulnerability Database

Search and browse 389,954 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-58533HIGH7.5Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-58532HIGH7.8Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-58531HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an aut...
CVE-2026-58530HIGH7.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code local...
CVE-2026-58529HIGH7.1Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information...
CVE-2026-58528MEDIUM4.6Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat...
CVE-2026-58527HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-58277HIGH8.8Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network...
CVE-2026-57982MEDIUM6.5Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
CVE-2026-57973MEDIUM4.7Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perfor...
CVE-2026-57968HIGH7.8Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CVE-2026-57108HIGH7.5Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny servi...
CVE-2026-57102HIGH8.8Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass...
CVE-2026-57101MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una...
CVE-2026-57096HIGH7.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate ...
CVE-2026-57095HIGH7.8Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate ...
CVE-2026-57094HIGH8.8Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a ...
CVE-2026-57093HIGH7.8Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-57092CRITICAL9.9Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
CVE-2026-57091HIGH7.8Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.
CVE-2026-57090CRITICAL9.8Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a ...
CVE-2026-57089CRITICAL9.8Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute co...
CVE-2026-57088HIGH7.8Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally...
CVE-2026-57087HIGH7.8Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a ...
CVE-2026-57085LOW3.3Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.