Newest CVEs

IDDescriptionSeverityUpdated
CVE-2026-55038Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
2026-07-16
CVE-2026-55037Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
2026-07-16
CVE-2026-55036Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
2026-07-16
CVE-2026-55035Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
low
2026-07-16
CVE-2026-55034Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high
2026-07-15
CVE-2026-55033Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
2026-07-16
CVE-2026-55032Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
2026-07-16
CVE-2026-55031Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
2026-07-15
CVE-2026-55030Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium
2026-07-15
CVE-2026-55029Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
2026-07-15
CVE-2026-55028Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium
2026-07-16
CVE-2026-55027Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium
2026-07-16
CVE-2026-55026Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium
2026-07-16
CVE-2026-55025Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
2026-07-15
CVE-2026-55024Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
2026-07-15
CVE-2026-55023Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium
2026-07-16
CVE-2026-55022Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
high
2026-07-16
CVE-2026-55021Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high
2026-07-15
CVE-2026-55020Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium
2026-07-16
CVE-2026-55019Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium
2026-07-15
CVE-2026-55018Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high
2026-07-16
CVE-2026-55017Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high
2026-07-16
CVE-2026-55016Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium
2026-07-15
CVE-2026-55010Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
critical
2026-07-22
CVE-2026-54131Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
2026-07-15
CVE-2026-54128Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
high
2026-07-22
CVE-2026-54126Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
medium
2026-07-22
CVE-2026-54125Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
high
2026-07-21
CVE-2026-54124Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
high
2026-07-22
CVE-2026-54121Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
high
2026-07-21
CVE-2026-54116Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
medium
2026-07-22
CVE-2026-54115Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
high
2026-07-21
CVE-2026-50692Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
high
2026-07-22
CVE-2026-50690Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
medium
2026-07-22
CVE-2026-50689Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
high
2026-07-22
CVE-2026-50688Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
high
2026-07-16
CVE-2026-50687Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
high
2026-07-22
CVE-2026-50686Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
high
2026-07-23
CVE-2026-50685Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
high
2026-07-21
CVE-2026-50684Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
medium
2026-07-21
CVE-2026-50683Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
high
2026-07-21
CVE-2026-50682Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
high
2026-07-22
CVE-2026-50681Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
medium
2026-07-22
CVE-2026-50680Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
high
2026-07-22
CVE-2026-50679Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
high
2026-07-22
CVE-2026-50677Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
high
2026-07-22
CVE-2026-50676Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
high
2026-07-22
CVE-2026-50674Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
high
2026-07-22
CVE-2026-50673Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
high
2026-07-16
CVE-2026-50672Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
high
2026-07-22