CVE Vulnerability Database

Search and browse 389,954 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-57084MEDIUM5.5Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
CVE-2026-57083MEDIUM5.5Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informatio...
CVE-2026-56650HIGH7.8Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
CVE-2026-56649HIGH8.1Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File Syst...
CVE-2026-56648HIGH7.5Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevat...
CVE-2026-56647HIGH8.8Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate ...
CVE-2026-56644HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56643HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56642HIGH8.8Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a netw...
CVE-2026-56197HIGH8.8Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an au...
CVE-2026-56196HIGH8.8Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-56195MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56194HIGH8.8Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a net...
CVE-2026-56192MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-56190CRITICAL9.8Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
CVE-2026-56189HIGH8.4Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally...
CVE-2026-56188HIGH8.1Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network dr...
CVE-2026-56187HIGH7.8Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56186MEDIUM6.5Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
CVE-2026-56184MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose i...
CVE-2026-56183HIGH7Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-56182HIGH7.8Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-56181HIGH8.3Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing...
CVE-2026-56178HIGH7Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el...
CVE-2026-56176HIGH7.8Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.