close
U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-46731 - Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevat... read CVE-2026-46731
    Published: August 12, 2026; 4:17:44 PM -0400

  • CVE-2026-59914 - Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevat... read CVE-2026-59914
    Published: August 12, 2026; 4:17:46 PM -0400

  • CVE-2026-59916 - Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privil... read CVE-2026-59916
    Published: August 12, 2026; 4:17:46 PM -0400

  • CVE-2026-59917 - Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privil... read CVE-2026-59917
    Published: August 12, 2026; 4:17:46 PM -0400

  • CVE-2026-71331 - Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
    Published: August 11, 2026; 1:19:13 PM -0400

  • CVE-2026-66802 - Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
    Published: August 11, 2026; 1:19:01 PM -0400

  • CVE-2026-59127 - Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:06 PM -0400

  • CVE-2026-61925 - Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:15 PM -0400

  • CVE-2026-61938 - Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:17 PM -0400

  • CVE-2026-62768 - Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:29 PM -0400

  • CVE-2026-48487 - Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without checking it ag... read CVE-2026-48487
    Published: July 17, 2026; 3:17:15 PM -0400

    V3.1: 5.3 MEDIUM

  • CVE-2026-62807 - Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:34 PM -0400

  • CVE-2026-48045 - Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained every truncated TC-bit incoming query, each up to _MAX_MSG_ABSOLUTE = 8966 bytes, in self._deferred[addr] ... read CVE-2026-48045
    Published: July 17, 2026; 3:17:15 PM -0400

  • CVE-2026-62812 - Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:35 PM -0400

  • CVE-2026-47184 - Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, _expire_heap, and service_cache without a cap, allowing unauthenticated hos... read CVE-2026-47184
    Published: July 17, 2026; 3:17:15 PM -0400

  • CVE-2026-47183 - Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four QuietLogger exception-dedup methods stored an unbounded _seen_logs dictionary keyed by attacker-influenced... read CVE-2026-47183
    Published: July 17, 2026; 3:17:15 PM -0400

  • CVE-2026-47180 - Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression pointer, and a single mDNS packet carrying chained pointers can trigger a Re... read CVE-2026-47180
    Published: July 17, 2026; 3:17:15 PM -0400

  • CVE-2026-65774 - Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
    Published: August 11, 2026; 1:18:56 PM -0400

  • CVE-2026-65806 - Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
    Published: August 11, 2026; 1:19:00 PM -0400

  • CVE-2026-70340 - Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
    Published: August 11, 2026; 1:19:11 PM -0400

    V3.1: 8.8 HIGH

Created September 20, 2022 , Updated August 27, 2024