CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-68804HIGH | Microsoft Excel Remote Code Execution VulnerabilityNumeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65798MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. CWE-197Aug 11, 2026 | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65797MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-63525HIGH | Microsoft Office Word Remote Code Execution VulnerabilityNumeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. CWE-197Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.385% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62883MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62881MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62769MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62698HIGH | Microsoft Digest Authentication Elevation of Privilege VulnerabilityNumeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. CWE-197Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.369% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62739HIGH | Windows HTTP.sys Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | CVSS7.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56650HIGH | Windows Network File System Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. | CVSS7.8v3.1 | EPSS0.311% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55142MEDIUM | Microsoft Word Information Disclosure VulnerabilityNumeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. CWE-197Jul 14, 2026 | CVSS5.5v3.1 | EPSS0.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50357HIGH | Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityNumeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. CWE-197Jul 14, 2026 | CVSS7.8v3.1 | EPSS0.311% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50332HIGH | Windows Kernel Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS7.8v3.1 | EPSS0.347% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49792HIGH | Windows Resilient File System (ReFS) Remote Code Execution VulnerabilityNumeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. CWE-197Jul 14, 2026 | CVSS7.8v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6679HIGH | DTLS 1.3 ACK serialization heap buffer overflow via integer truncationA heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and then overrun. This affects builds using DTLS 1.3 and wolfSSL version 5.9.0 and earlier. A fix was added to the 5.9.1 release. | CVSS8.8v4.0 | EPSS0.576% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6039MEDIUM | Heap buffer overflow in DXF polyline importLibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was sized, while the full count was used to fill it, so a polyline whose point count exceeded the 16-bit range was written past the end of the buffer. In fixed versions such oversized polylines are rejected. | CVSS5.4v4.0 | EPSS0.157% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44823HIGH | Microsoft Excel Remote Code Execution VulnerabilityInteger underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.372% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40404HIGH | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityWindows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | CVSS7.8v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40409HIGH | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityWindows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability CWE-197Jun 9, 2026 | CVSS7.8v3.1 | EPSS0.298% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42944HIGH | Heap overflow with multiple NSID, COOKIE, PADDING EDNS optionsNLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. … | CVSS8.7v4.0 | EPSS0.842% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40380MEDIUM | Windows Volume Manager Extension Driver Remote Code Execution VulnerabilityHeap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack. | CVSS6.2v3.1 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:uriparser Pointer Difference Truncation to IntegerIn uriparser before 1.0.2, there is pointer difference truncation to int in various places. CWE-197May 8, 2026 | CVSS2.9v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-42371MEDIUM | Generated title:uriparser Numeric Truncation Vulnerabilityuriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes. CWE-197Apr 27, 2026 | CVSS5.1v3.1 | EPSS0.172% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32240MEDIUM | Cap'n Proto: Integer overflow in KJ-HTTP chunk sizeCap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0. | CVSS6.3v4.0 | EPSS0.207% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10543MEDIUM | Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytesIn Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an MQTT topic may leak into the message body in a PUBLISH packet). The issue arises because the length of the data passed in was converted from an int64/int32 (depending upon CPU) to an int16 without checks for overflows. The… | CVSS6.3v4.0 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |