U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-62913 - Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
    Published: August 11, 2026; 1:18:45 PM -0400

  • CVE-2026-62893 - Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
    Published: August 11, 2026; 1:18:43 PM -0400

  • CVE-2026-62814 - Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
    Published: August 11, 2026; 1:18:35 PM -0400

  • CVE-2026-62803 - Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:34 PM -0400

  • CVE-2026-62745 - Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
    Published: August 11, 2026; 1:18:26 PM -0400

  • CVE-2026-62742 - Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
    Published: August 11, 2026; 1:18:26 PM -0400

  • CVE-2026-62720 - Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
    Published: August 11, 2026; 1:18:22 PM -0400

  • CVE-2026-62718 - Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
    Published: August 11, 2026; 1:18:22 PM -0400

  • CVE-2026-62716 - Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
    Published: August 11, 2026; 1:18:21 PM -0400

  • CVE-2026-62715 - Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
    Published: August 11, 2026; 1:18:21 PM -0400

  • CVE-2026-62714 - Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
    Published: August 11, 2026; 1:18:21 PM -0400

  • CVE-2026-70315 - Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
    Published: August 11, 2026; 1:19:08 PM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-62908 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:44 PM -0400

  • CVE-2026-70314 - Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
    Published: August 11, 2026; 1:19:08 PM -0400

  • CVE-2026-48434 - CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denia... read CVE-2026-48434
    Published: August 11, 2026; 1:18:00 PM -0400

  • CVE-2026-48435 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser... read CVE-2026-48435
    Published: August 11, 2026; 1:18:00 PM -0400

  • CVE-2026-48436 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit... read CVE-2026-48436
    Published: August 11, 2026; 1:18:00 PM -0400

  • CVE-2026-48437 - CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. E... read CVE-2026-48437
    Published: August 11, 2026; 1:18:00 PM -0400

  • CVE-2026-48438 - CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition.... read CVE-2026-48438
    Published: August 11, 2026; 1:18:01 PM -0400

  • CVE-2026-48439 - CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denia... read CVE-2026-48439
    Published: August 11, 2026; 1:18:01 PM -0400

Created September 20, 2022 , Updated August 27, 2024