U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NVD Dashboard

CVEs Received and Processed

CVEs Received and Processed

Please Wait

CVE Status Count

Please Wait

CVSS Score Spread

Please Wait

CVSS V3 Score Distribution

Severity Number of Vulns

CVSS V2 Score Distribution

Severity Number of Vulns


For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-70337 - Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
    Published: August 11, 2026; 1:19:11 PM -0400

  • CVE-2026-70329 - Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
    Published: August 11, 2026; 1:19:10 PM -0400

  • CVE-2026-65657 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:53 PM -0400

  • CVE-2026-64911 - Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:52 PM -0400

  • CVE-2026-63518 - Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:47 PM -0400

  • CVE-2026-63513 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:46 PM -0400

  • CVE-2026-13380 - VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the app... read CVE-2026-13380
    Published: July 20, 2026; 5:16:46 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-13381 - VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files b... read CVE-2026-13381
    Published: July 20, 2026; 5:16:46 PM -0400

    V3.1: 8.1 HIGH

  • CVE-2026-62910 - Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
    Published: August 11, 2026; 1:18:44 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-62890 - Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:40 PM -0400

  • CVE-2026-62823 - Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
    Published: August 11, 2026; 1:18:36 PM -0400

  • CVE-2026-62915 - Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
    Published: August 11, 2026; 1:18:45 PM -0400

  • CVE-2026-62898 - Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
    Published: August 11, 2026; 1:18:43 PM -0400

  • CVE-2026-64920 - Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:53 PM -0400

  • CVE-2026-64905 - Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:51 PM -0400

  • CVE-2026-64914 - Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:52 PM -0400

  • CVE-2026-64919 - Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:53 PM -0400

  • CVE-2026-64907 - Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:51 PM -0400

  • CVE-2026-64912 - Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:52 PM -0400

  • CVE-2026-64904 - Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
    Published: August 11, 2026; 1:18:51 PM -0400