Live feed

CVE Feed

Last 30 days — 15,665 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-67378
CRITICAL· 9.0

Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.

microsoft
29d ago
CVE-2026-67376
HIGH· 7.5

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

microsoft
29d ago
CVE-2026-67373
HIGH· 8.8

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

microsoft
29d ago
CVE-2026-67370
HIGH· 8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

microsoft
29d ago
CVE-2026-67369
MEDIUM· 6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

microsoft
29d ago
CVE-2026-67368
HIGH· 8.8

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

microsoft
29d ago
CVE-2026-66820
HIGH· 8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

microsoft
29d ago
CVE-2026-66819
HIGH· 8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

microsoft
29d ago
CVE-2026-66818
HIGH· 8.8

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

microsoft
29d ago
CVE-2026-66816
MEDIUM· 6.5

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

microsoft
29d ago
CVE-2026-66814
HIGH· 8.8

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

microsoft
29d ago
CVE-2026-65812
MEDIUM· 6.8

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

microsoft
29d ago
CVE-2026-65772
HIGH· 8.8

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

microsoft
29d ago
CVE-2026-65669
CRITICAL· 9.6

Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.

microsoft
29d ago
CVE-2026-64918
MEDIUM· 6.5

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

microsoft
29d ago
CVE-2026-62895
HIGH· 8.8

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

29d ago
CVE-2026-62813
HIGH· 7.5

Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

microsoft
29d ago
CVE-2026-62810
HIGH· 7.8

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-62804
HIGH· 7.8

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

microsoft
29d ago
CVE-2026-62801
MEDIUM· 6.5

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.

microsoft
29d ago
CVE-2026-62762
MEDIUM· 6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

microsoft
29d ago
CVE-2026-62759
HIGH· 7.5

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

microsoft
29d ago
CVE-2026-62744
HIGH· 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

microsoft
29d ago
CVE-2026-62706
HIGH· 8.8

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

microsoft
29d ago
CVE-2026-62697
HIGH· 7.8

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-62694
HIGH· 7.0

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-58649
MEDIUM· 6.5

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

microsoftapple+1
29d ago
CVE-2026-58611
HIGH· 7.8

Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-58600
HIGH· 7.8

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-58599
HIGH· 7.8

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

microsoft
29d ago
CVE-2026-57099
HIGH· 7.5

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

microsoft
29d ago
CVE-2026-57098
HIGH· 7.5

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

microsoft
29d ago
CVE-2026-56198
HIGH· 7.8

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-56177
HIGH· 7.8

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-56172
HIGH· 7.8

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-55007
HIGH· 8.1

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

microsoft
29d ago
CVE-2026-54611
MEDIUM· 5.5

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.

29d ago
CVE-2026-50349
HIGH· 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft
29d ago
CVE-2026-48707
LOW· 3.1

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.

29d ago
CVE-2026-47297
HIGH· 8.1

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

microsoft
29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000