CVE Vulnerability Database

Search and browse 389,958 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-50681MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack...
CVE-2026-50680HIGH7.8Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2026-50679HIGH7.8Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges loc...
CVE-2026-50677HIGH7.8Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2026-50676HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a...
CVE-2026-50674HIGH7.8Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50673HIGH7.8Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50672HIGH7Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50670HIGH7.8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50669HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service...
CVE-2026-50668MEDIUM6.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-50667HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an au...
CVE-2026-50666HIGH8.8Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a ne...
CVE-2026-50665LOW3.3Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-50661MEDIUM4.6Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph...
CVE-2026-50658HIGH7Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privile...
CVE-2026-50657MEDIUM5.5Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to...
CVE-2026-50655HIGH7.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-50647HIGH7.5Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho...
CVE-2026-50518CRITICAL9.8Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50510HIGH7.8Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute...
CVE-2026-50509HIGH7.8Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate...
CVE-2026-50505HIGH8.8Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
CVE-2026-50504HIGH7.5Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-50503HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an...