CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-69344 | MEDIUM | 5.5 | Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69343 | MEDIUM | 5.5 | Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69339 | MEDIUM | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69338 | HIGH | 7.1 | Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69333 | HIGH | 7.0 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69329 | HIGH | 7.5 | Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69325 | HIGH | 8.1 | Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-69322 | HIGH | 8.0 | Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69319 | HIGH | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69318 | MEDIUM | 5.5 | Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69317 | MEDIUM | 5.7 | Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-69316 | MEDIUM | 4.7 | Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69315 | MEDIUM | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69314 | HIGH | 7.1 | Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69313 | HIGH | 7.1 | Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69308 | MEDIUM | 5.5 | Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69305 | HIGH | 7.1 | Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69304 | MEDIUM | 5.9 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-69303 | MEDIUM | 5.5 | Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69299 | HIGH | 7.0 | Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69296 | HIGH | 7.1 | Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network. | Sep 8, 2026 | |
| CVE-2026-69294 | MEDIUM | 5.5 | Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | Sep 8, 2026 | |
| CVE-2026-69292 | HIGH | 7.0 | Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-69291 | HIGH | 8.8 | Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-69288 | MEDIUM | 5.5 | Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | Sep 8, 2026 |