⌂

🐞 CVE Tracking and Search

Search and filter Common Vulnerabilities and Exposures

← Dashboard CVE Search Exploitation Radar Breaches Trends Industries Vendors MITRE ATT&CK MITRE ATLAS Threat Actors Attack-Tools Alerts Investigations
🔎 Search & Filters
Search: Time Range:
Sources:
📚 Intelligence Coverage the corpus behind every search on this page
380,160+
CVEs Tracked
380,160
Exploit Intel
362,085
EPSS Scored
5,299
CISA KEV
2,704
Metasploit Modules
30,390
ExploitDB Entries
61
MITRE ATT&CK Maps
🚨 Exploitation Status within the current filter · click a card to jump to it
0
Actively Exploited
2
CISA KEV
21
PoC Available
0
Zero-Days
8
Recent Discoveries
1
Most Mentioned
📊 CVE Severity Distribution last 30 days
🐞 Results 1,399 CVEs in the last 30 days · showing 951-1000
CVE-2026-69804 HIGH CVSS: 7.5 EPSS: 0.5% CWE-367
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69804 Microsoft Office SharePoint Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-69805 HIGH CVSS: 7.5 EPSS: 0.6% CWE-73 CWE-200 CWE-522 T1005 T1083 T1552
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69805 .NET Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-69809 HIGH CVSS: 7.5 EPSS: 1.2% CWE-401 T1499
Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69809 Windows Active Directory Domain Services Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-69852 HIGH CVSS: 7.5 EPSS: 0.7% CWE-122 T1203
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69852 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-69881 HIGH CVSS: 7.5 EPSS: 1.2% CWE-476 T1499
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69881 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-69890 HIGH CVSS: 7.5 EPSS: 0.3% CWE-416 T1203
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69890 Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-70065 HIGH CVSS: 7.5 EPSS: 1.2% CWE-401 T1499
Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70065 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-70570 HIGH CVSS: 7.5 EPSS: 0.7% CWE-416 T1203
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70570 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-70579 HIGH CVSS: 7.5 EPSS: 1.0% CWE-125 T1005
Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70579 Windows Mobile Broadband Information Disclosure Vulnerability
MSRC Security Update Guide
CVE-2026-70587 HIGH CVSS: 7.5 EPSS: 1.0% CWE-170
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-70587 Windows Remote Desktop Protocol Information Disclosure Vulnerability
MSRC Security Update Guide
CVE-2026-71330 HIGH CVSS: 7.5 EPSS: 1.0% CWE-497
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-71330 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
MSRC Security Update Guide
CVE-2026-72928 HIGH CVSS: 7.5 EPSS: 0.7% CWE-416 T1203
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72928 Windows DNS Server Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-72932 HIGH CVSS: 7.5 EPSS: 1.0% CWE-126
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72932 Windows Message Queuing Queue Manager Information Disclosure Vulnerability
MSRC Security Update Guide
CVE-2026-72943 HIGH CVSS: 7.5 EPSS: 0.7% CWE-416 T1203
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72943 Windows Deployment Services Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-72949 HIGH CVSS: 7.5 EPSS: 1.2% CWE-476 T1499
Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72949 Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-72954 HIGH CVSS: 7.5 EPSS: 0.7% CWE-416 T1203
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72954 Windows Deployment Services Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-72989 HIGH CVSS: 7.5 EPSS: 1.0% CWE-908 T1005
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-72989 Windows Failover Cluster Information Disclosure Vulnerability
MSRC Security Update Guide
CVE-2026-73017 HIGH CVSS: 7.5 EPSS: 0.3% CWE-122 T1203
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-73017 Graphics Kernel Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-77494 HIGH CVSS: 7.5 EPSS: 1.2% CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77494 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77498 HIGH CVSS: 7.5 EPSS: 1.2% CWE-125 T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77498 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77499 HIGH CVSS: 7.5 EPSS: 1.2% CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77499 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77501 HIGH CVSS: 7.5 EPSS: 1.2% CWE-125 T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77501 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77502 HIGH CVSS: 7.5 EPSS: 1.2% CWE-125 T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77502 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77886 HIGH CVSS: 7.5 EPSS: 1.2% CWE-125 T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77886 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77888 HIGH CVSS: 7.5 EPSS: 1.2% CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77888 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77889 HIGH CVSS: 7.5 EPSS: 1.2% CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77889 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77890 HIGH CVSS: 7.5 EPSS: 1.2% CWE-843
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77890 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77893 HIGH CVSS: 7.5 EPSS: 1.2% CWE-125 T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77893 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77895 HIGH CVSS: 7.5 EPSS: 1.2% CWE-125 T1005
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77895 Windows DHCP Server Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-77898 HIGH CVSS: 7.5 EPSS: 0.6% CWE-122 T1203
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-77898 Microsoft Office Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-81355 HIGH CVSS: 7.5 EPSS: 0.2% CWE-122 T1203
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-83989 HIGH CVSS: 7.5 EPSS: 1.2% CWE-125 T1005
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-83989 Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-84001 HIGH CVSS: 7.5 EPSS: 1.2% CWE-125 T1005
Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-84001 Windows Key Distribution Center Denial of Service Vulnerability
MSRC Security Update Guide
CVE-2026-69347 HIGH CVSS: 7.4 EPSS: 0.3% CWE-122 T1203
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69347 Windows Fast FAT Driver Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-78461 HIGH CVSS: 7.4 EPSS: 1.0% CWE-22 T1083
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-78461 Visual Studio Code Security Feature Bypass Vulnerability
MSRC Security Update Guide
CVE-2026-81383 HIGH CVSS: 7.4 EPSS: 0.9% CWE-706
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81383 Visual Studio Code Information Disclosure Vulnerability
MSRC Security Update Guide
CVE-2026-84003 HIGH CVSS: 7.4 EPSS: 0.6% CWE-294
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-84003 Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability
MSRC Security Update Guide
CVE-2026-69402 HIGH CVSS: 7.3 EPSS: 0.4% CWE-79 T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69402 Microsoft Office SharePoint Spoofing Vulnerability
MSRC Security Update Guide
CVE-2026-69417 HIGH CVSS: 7.3 EPSS: 0.4% CWE-79 T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69417 Microsoft Office SharePoint Spoofing Vulnerability
MSRC Security Update Guide
CVE-2026-69477 HIGH CVSS: 7.3 EPSS: 0.4% CWE-122 T1203
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69477 Microsoft Office Access Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-81349 HIGH CVSS: 7.2 EPSS: 1.0% CWE-78 T1059
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-81349 Azure HDInsight Ambari Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-66305 HIGH CVSS: 7.1 EPSS: 0.5% CWE-603
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66305 Skype for Business Spoofing Vulnerability
MSRC Security Update Guide
CVE-2026-68835 HIGH CVSS: 7.1 EPSS: 0.6% CWE-416 T1203
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68835 Windows Print Spooler Components Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-68846 HIGH CVSS: 7.1 EPSS: 0.6% CWE-416 T1203
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68846 Windows Kernel Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-68889 HIGH CVSS: 7.1 EPSS: 0.6% CWE-122 CWE-190 T1203
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68889 Microsoft Standard XPS Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-68893 HIGH CVSS: 7.1 EPSS: 0.6% CWE-416 T1203
Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68893 Remote Desktop Licensing Service Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-69272 HIGH CVSS: 7.1 EPSS: 0.6% CWE-122 T1203
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69272 Microsoft Standard XPS Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-69274 HIGH CVSS: 7.1 EPSS: 0.6% CWE-416 T1203
Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69274 Windows Win32k Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-69296 HIGH CVSS: 7.1 EPSS: 0.6% CWE-416 T1203
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69296 Windows Device Association Service Elevation of Privilege Vulnerability
MSRC Security Update Guide
CVE-2026-69305 HIGH CVSS: 7.1 EPSS: 0.6% CWE-416 T1203
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69305 Microsoft Windows Search Component Elevation of Privilege Vulnerability
MSRC Security Update Guide