Vulnerabilities (CVE)

Total 396665 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-69289 2026-09-09 N/A 7.8 HIGH
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
CVE-2026-69283 2026-09-09 N/A 7.8 HIGH
Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69280 2026-09-09 N/A 7.0 HIGH
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-69279 2026-09-09 N/A 7.0 HIGH
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69275 2026-09-09 N/A 7.0 HIGH
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69274 2026-09-09 N/A 7.1 HIGH
Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.
CVE-2026-68894 2026-09-09 N/A 8.0 HIGH
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
CVE-2026-68880 2026-09-09 N/A 8.0 HIGH
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
CVE-2026-68878 2026-09-09 N/A 8.0 HIGH
Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.
CVE-2026-68876 2026-09-09 N/A 8.0 HIGH
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-68850 2026-09-09 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally.
CVE-2026-68828 2026-09-09 N/A 8.8 HIGH
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-65669 2026-09-09 N/A 9.6 CRITICAL
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62813 2026-09-09 N/A 7.5 HIGH
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
CVE-2026-62810 2026-09-09 N/A 7.8 HIGH
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
CVE-2026-55007 2026-09-09 N/A 8.1 HIGH
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-7861 2026-09-09 N/A 9.8 CRITICAL
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.
CVE-2026-86504 2026-09-09 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
CVE-2026-86502 2026-09-09 N/A 8.4 HIGH
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
CVE-2026-86480 2026-09-09 N/A 9.8 CRITICAL
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges