CVE Search

IDDescriptionSeverityUpdated
CVE-2026-45602No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
critical
CVE-2026-45471Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
CVE-2026-45607Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
high
CVE-2026-45458Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2026-45475Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2026-45654Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
high
CVE-2026-45479Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium
CVE-2026-45588Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
high
CVE-2026-47641Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium
CVE-2026-47634Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium
CVE-2026-6338A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic.
high
CVE-2026-26164Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
high
CVE-2026-35430Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.
high
CVE-2026-40411Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
high
CVE-2026-23663Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
high
CVE-2026-40412Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
critical
CVE-2026-45494Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2026-42822Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
critical
CVE-2026-36828A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter.
high
CVE-2026-57084Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-56189Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
high
CVE-2026-55140Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2026-56187Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
high
CVE-2026-56157Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium
CVE-2026-55136Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
CVE-2026-55125Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2026-55056Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2026-55047Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-55127Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
CVE-2026-55048Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
CVE-2026-55043Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
high
CVE-2026-55041Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
CVE-2026-55034Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high
CVE-2026-55051Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
medium
CVE-2026-54125Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
high
CVE-2026-55018Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2026-50687Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
high
CVE-2026-55033Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
CVE-2026-54115Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
high
CVE-2026-50686Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
high
CVE-2026-55027Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-50306Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
high
CVE-2026-50301Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2026-50309Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
high
CVE-2026-50310Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
medium
CVE-2026-50330Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
critical
CVE-2026-47290Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2026-50358Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
high
CVE-2026-50363Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
high
CVE-2026-50498Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
high