CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-69489 | HIGH | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69483 | MEDIUM | 4.7 | Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69476 | HIGH | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69474 | MEDIUM | 4.8 | Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-69473 | HIGH | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69472 | HIGH | 7.0 | Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69470 | HIGH | 7.0 | Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69460 | HIGH | 7.1 | Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69457 | MEDIUM | 5.5 | Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69456 | HIGH | 7.8 | Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69450 | HIGH | 7.8 | Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69443 | HIGH | 7.5 | Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-69438 | HIGH | 8.1 | Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-69432 | HIGH | 7.8 | Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69431 | CRITICAL | 9.8 | Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-69430 | HIGH | 7.0 | Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69428 | HIGH | 7.5 | Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69426 | HIGH | 7.8 | Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally. | Sep 8, 2026 | |
| CVE-2026-69425 | MEDIUM | 4.7 | Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally. | Sep 8, 2026 | |
| CVE-2026-69420 | HIGH | 7.8 | Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69416 | MEDIUM | 5.7 | Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | Sep 8, 2026 | |
| CVE-2026-69413 | HIGH | 7.0 | Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69407 | HIGH | 7.8 | Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69406 | MEDIUM | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69404 | HIGH | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 |