Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-26153

7.8

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

Out-of-bounds
Details

CVE-2026-26152

7.0

Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

Insecure
Details

CVE-2026-26151

7.1

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

Details

CVE-2026-26149

9.0

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to bypass a security feature over a network.

Microsoft
Details

CVE-2026-26143

7.8

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

Microsoft
Details

CVE-2026-25184

7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.

Concurrent
Details

CVE-2026-24907

5.1

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail preview feature. …

October
Details

CVE-2026-24906

5.1

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup …

October
Details

CVE-2026-23670

5.7

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Untrusted
Details

CVE-2026-23666

7.5

Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.

Details
52/3864