U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NVD Dashboard

CVEs Received and Processed

CVEs Received and Processed

Please Wait

CVE Status Count

Please Wait

CVSS Score Spread

Please Wait

CVSS V3 Score Distribution

Severity Number of Vulns

CVSS V2 Score Distribution

Severity Number of Vulns


For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-59124 - Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
    Published: August 11, 2026; 1:18:06 PM -0400

  • CVE-2026-58076 - Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. A... read CVE-2026-58076
    Published: August 12, 2026; 12:17:08 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-54183 - Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Va... read CVE-2026-54183
    Published: August 12, 2026; 12:17:04 PM -0400

  • CVE-2026-62816 - Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
    Published: August 11, 2026; 1:18:35 PM -0400

  • CVE-2026-62818 - Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
    Published: August 11, 2026; 1:18:35 PM -0400

  • CVE-2026-65787 - Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:58 PM -0400

  • CVE-2026-27790 - Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior... read CVE-2026-27790
    Published: July 07, 2026; 1:16:50 AM -0400

  • CVE-2025-47147 - Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited d... read CVE-2025-47147
    Published: March 02, 2026; 10:15:54 PM -0500

  • CVE-2026-27844 - Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of servi... read CVE-2026-27844
    Published: July 07, 2026; 1:16:50 AM -0400

  • CVE-2026-65786 - Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:58 PM -0400

  • CVE-2026-62815 - Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
    Published: August 11, 2026; 1:18:35 PM -0400

  • CVE-2026-65788 - Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:58 PM -0400

  • CVE-2026-58651 - Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:05 PM -0400

  • CVE-2026-65662 - Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
    Published: August 11, 2026; 1:18:54 PM -0400

  • CVE-2026-65671 - Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:55 PM -0400

  • CVE-2026-65790 - Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:58 PM -0400

  • CVE-2026-65814 - Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:19:00 PM -0400

  • CVE-2026-66799 - Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:19:01 PM -0400

  • CVE-2026-70307 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:19:08 PM -0400

  • CVE-2026-62819 - Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
    Published: August 11, 2026; 1:18:35 PM -0400