CVE Vulnerability Database

Search and browse 389,958 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-55021HIGH8.7Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-55020MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-55019MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-55018HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55017HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55016MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-55010CRITICAL9.8Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a ...
CVE-2026-54131HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-54128HIGH8.4Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
CVE-2026-54126MEDIUM6.5Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-54125HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...
CVE-2026-54124HIGH7.8Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
CVE-2026-54121HIGH8.8Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privile...
CVE-2026-54116MEDIUM6.5Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in...
CVE-2026-54115HIGH7.8Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
CVE-2026-50692HIGH8.8Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-50690MEDIUM5.5Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-50689HIGH7.8Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
CVE-2026-50688HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50687HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50686HIGH8.1Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute ...
CVE-2026-50685HIGH7.5Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-50684MEDIUM4.8Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Serv...
CVE-2026-50683HIGH8Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n...
CVE-2026-50682HIGH7.1Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.