CVE List – Find High-Risk & Exploited Vulnerabilities

Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.

Assigner (CNA / source):[email protected] Remove this filter

Showing 81100 of 13286 results
«« First « Prev Page 5 / 665 Next »
CVE Description Max CVSS EPSS % Published Updated
CVE-2026-45595 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. 5.4 0.32% 2026-06-09 2026-06-11
CVE-2026-45594 Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. 5.5 0.33% 2026-06-09 2026-06-11
CVE-2026-45593 Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. 7.8 0.23% 2026-06-09 2026-06-11
CVE-2026-45592 Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. 7.8 0.23% 2026-06-09 2026-06-11
CVE-2026-45591 Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. 7.5 0.77% 2026-06-09 2026-06-09
CVE-2026-45588 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 7.9 0.24% 2026-06-09 2026-06-11
CVE-2026-45586 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally. 7.8 2.15% 2026-06-09 2026-06-11
CVE-2026-45583 Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. 7.5 0.44% 2026-06-09 2026-06-09
CVE-2026-45504 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 8.8 0.40% 2026-06-09 2026-06-15
CVE-2026-45503 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. 8.1 0.38% 2026-06-09 2026-06-15
CVE-2026-45502 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. 5.0 0.43% 2026-06-09 2026-06-15
CVE-2026-45501 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 6.5 0.30% 2026-06-09 2026-06-15
CVE-2026-45500 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 6.1 0.38% 2026-06-09 2026-06-09
CVE-2026-45491 Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. 6.2 0.30% 2026-06-09 2026-06-09
CVE-2026-45490 Improper authorization in .NET allows an authorized attacker to elevate privileges locally. 7.8 0.22% 2026-06-09 2026-06-09
CVE-2026-45487 Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. 7.8 0.15% 2026-06-09 2026-06-11
CVE-2026-45486 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 7.8 0.32% 2026-06-09 2026-06-11
CVE-2026-45485 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 3.3 0.31% 2026-06-09 2026-06-11
CVE-2026-45484 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 8.8 1.49% 2026-06-09 2026-06-12
CVE-2026-45483 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network. 4.6 0.27% 2026-06-09 2026-06-09
«« First « Prev Page 5 / 665 Next »
cvelogic Threat Intelligence