CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-62738MEDIUM | Windows Management Instrumentation Information Disclosure VulnerabilityOut-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.397% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-71331HIGH | Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityInteger overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. | CVSS8.1v3.1 | EPSS0.454% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66802HIGH | Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. | CVSS8.1v3.1 | EPSS0.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65796MEDIUM | Windows iSCSI Target Service Denial of Service VulnerabilityHeap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. CWE-122Aug 11, 2026 | CVSS5.9v3.1 | EPSS0.645% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65798MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. CWE-197Aug 11, 2026 | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65799MEDIUM | Windows DNS Elevation of Privilege VulnerabilityInteger overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65797MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65794MEDIUM | Windows SMB Client Information Disclosure VulnerabilityBuffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. CWE-126Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.666% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65795MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNo cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. Aug 11, 2026 | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65791CRITICAL | Windows iSCSI Target Service Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CWE-122Aug 11, 2026 | CVSS9.8v3.1 | EPSS0.601% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65790HIGH | Windows Message Queuing Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65775HIGH | Windows Win32k Elevation of Privilege VulnerabilityUse after free in Windows Win32K allows an authorized attacker to elevate privileges locally. CWE-416Aug 11, 2026 | CVSS7.8v3.1 | EPSS2.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65774HIGH | Windows Installer Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65773HIGH | Windows Kernel Elevation of Privilege VulnerabilityImproper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. CWE-284Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65679HIGH | Windows iSCSI Target Service Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CWE-122Aug 11, 2026 | CVSS8.1v3.1 | EPSS0.557% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65681HIGH | Windows iSCSI Target Service Denial of Service VulnerabilityNull pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. CWE-476Aug 11, 2026 | CVSS7.5v3.1 | EPSS0.872% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62887MEDIUM | Windows NTFS Information Disclosure VulnerabilityOut-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.306% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62885HIGH | Windows Win32k Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62883MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62881MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62880HIGH | Windows NTFS Elevation of Privilege VulnerabilityOut-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. CWE-125Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62822HIGH | Windows GDI+ Remote Code Execution VulnerabilityInteger overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | CVSS8.8v3.1 | EPSS0.633% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62823HIGH | Windows DHCP Server Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. CWE-122Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.555% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62814MEDIUM | Windows DHCP Server Information Disclosure VulnerabilityInteger underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS6.5v3.1 | EPSS0.549% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62807HIGH | Windows DHCP Server Elevation of Privilege VulnerabilityImproper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. CWE-59Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |