CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2026-69287

    Last Modified: 10 Sept 2026

    Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-68896

    Last Modified: 10 Sept 2026

    Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-72967

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-72966

    Last Modified: 10 Sept 2026

    Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-72964

    Last Modified: 10 Sept 2026

    Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.

    Published: 8 Sept 2026
    8.2
    High

    CVE-2026-72961

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-72960

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-72954

    Last Modified: 10 Sept 2026

    Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-72959

    Last Modified: 10 Sept 2026

    Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-72950

    Last Modified: 10 Sept 2026

    Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-72957

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-72942

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-72941

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-72953

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-72952

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-72932

    Last Modified: 10 Sept 2026

    Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-72933

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-72936

    Last Modified: 10 Sept 2026

    Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    4.7
    Medium

    CVE-2026-72931

    Last Modified: 10 Sept 2026

    Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-72928

    Last Modified: 10 Sept 2026

    Use after free in Windows DNS allows an authorized attacker to execute code over a network.

    Published: 8 Sept 2026
    6.7
    Medium

    CVE-2026-72927

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-71352

    Last Modified: 10 Sept 2026

    Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-71342

    Last Modified: 10 Sept 2026

    Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    6.8
    Medium

    CVE-2026-71349

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70583

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-70579

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-70578

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-70577

    Last Modified: 11 Sept 2026

    Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70581

    Last Modified: 11 Sept 2026

    Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    5.3
    Medium

    CVE-2026-70575

    Last Modified: 10 Sept 2026

    Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70572

    Last Modified: 11 Sept 2026

    Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-70573

    Last Modified: 11 Sept 2026

    Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70569

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-70568

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-70567

    Last Modified: 10 Sept 2026

    Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-70574

    Last Modified: 10 Sept 2026

    Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-70565

    Last Modified: 10 Sept 2026

    Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-47297

    Last Modified: 9 Sept 2026

    Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-64918

    Last Modified: 9 Sept 2026

    Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58599

    Last Modified: 9 Sept 2026

    Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-69784

    Last Modified: 10 Sept 2026

    Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.2
    High

    CVE-2026-69820

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-69864

    Last Modified: 10 Sept 2026

    Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-69725

    Last Modified: 10 Sept 2026

    Double free in Windows Hello allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.2
    High

    CVE-2026-69874

    Last Modified: 10 Sept 2026

    Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-69858

    Last Modified: 9 Sept 2026

    Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-69710

    Last Modified: 10 Sept 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-69813

    Last Modified: 10 Sept 2026

    Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-69799

    Last Modified: 10 Sept 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.

    Published: 8 Sept 2026
    8.1
    High

    CVE-2026-69786

    Last Modified: 10 Sept 2026

    Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to execute code over a network.

    Published: 8 Sept 2026
    Items Per Page