CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-69403 | MEDIUM | 5.5 | Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69396 | HIGH | 7.1 | Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69395 | MEDIUM | 6.5 | Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-69393 | MEDIUM | 5.7 | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-69391 | HIGH | 7.8 | Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69390 | MEDIUM | 5.5 | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69384 | HIGH | 7.1 | Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally. | Sep 8, 2026 | |
| CVE-2026-69382 | MEDIUM | 5.9 | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-69381 | MEDIUM | 4.6 | Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack. | Sep 8, 2026 | |
| CVE-2026-69378 | HIGH | 7.5 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69376 | MEDIUM | 5.5 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69375 | MEDIUM | 6.5 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | Sep 8, 2026 | |
| CVE-2026-69374 | MEDIUM | 6.5 | Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69372 | MEDIUM | 5.7 | Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69371 | HIGH | 8.0 | Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69369 | MEDIUM | 5.5 | Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69367 | MEDIUM | 5.5 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69359 | HIGH | 7.8 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69356 | CRITICAL | 9.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | Sep 8, 2026 | |
| CVE-2026-69353 | MEDIUM | 5.5 | Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69352 | HIGH | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69351 | MEDIUM | 5.5 | Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69349 | MEDIUM | 5.7 | Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-69348 | HIGH | 7.8 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69345 | MEDIUM | 5.5 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | Sep 8, 2026 |