CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-78448 | HIGH | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-78446 | MEDIUM | 5.3 | Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-78444 | HIGH | 8.1 | Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-78442 | HIGH | 8.8 | Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-78441 | MEDIUM | 6.5 | Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-77911 | MEDIUM | 6.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-77909 | HIGH | 7.7 | Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network. | Sep 8, 2026 | |
| CVE-2026-77907 | HIGH | 8.8 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-77904 | HIGH | 7.8 | Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-77901 | HIGH | 8.8 | Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-77899 | HIGH | 7.0 | Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-77896 | MEDIUM | 6.5 | Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77895 | HIGH | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77894 | HIGH | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. | Sep 8, 2026 | |
| CVE-2026-77893 | HIGH | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77891 | MEDIUM | 6.4 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. | Sep 8, 2026 | |
| CVE-2026-77890 | HIGH | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77889 | HIGH | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77888 | HIGH | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77886 | HIGH | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77504 | HIGH | 8.8 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | Sep 8, 2026 | |
| CVE-2026-77502 | HIGH | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77501 | HIGH | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77499 | HIGH | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 | |
| CVE-2026-77498 | HIGH | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Sep 8, 2026 |