CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-69681 | HIGH | 8.0 | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69676 | HIGH | 8.8 | Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-69674 | MEDIUM | 5.5 | Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally. | Sep 8, 2026 | |
| CVE-2026-69672 | MEDIUM | 5.5 | Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69631 | HIGH | 7.5 | Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69627 | MEDIUM | 5.5 | Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69624 | MEDIUM | 6.5 | Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network. | Sep 8, 2026 | |
| CVE-2026-69621 | HIGH | 7.0 | Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69618 | MEDIUM | 5.5 | Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69616 | MEDIUM | 5.5 | Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69609 | MEDIUM | 5.5 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69608 | HIGH | 7.8 | Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69607 | HIGH | 7.5 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-69605 | HIGH | 7.0 | Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69600 | HIGH | 7.0 | Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69594 | HIGH | 7.8 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69593 | HIGH | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69591 | MEDIUM | 5.7 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-69589 | HIGH | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69588 | HIGH | 7.5 | Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69587 | HIGH | 7.5 | Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69585 | HIGH | 7.8 | Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69584 | HIGH | 7.8 | Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69583 | HIGH | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69580 | HIGH | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 |