CVE Search

IDDescriptionSeverityUpdated
CVE-2026-72938Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
medium
CVE-2026-71336Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.
high
CVE-2026-72943Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
high
CVE-2026-72957Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.
high
CVE-2026-72937Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
medium
CVE-2026-72931Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.
medium
CVE-2026-72989Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
high
CVE-2026-72962Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
high
CVE-2026-73028Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
high
CVE-2026-73010Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
critical
CVE-2026-73005Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
high
CVE-2026-77504Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
high
CVE-2026-77886Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
high
CVE-2026-73018Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
high
CVE-2026-73026Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
high
CVE-2026-73029Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
medium
CVE-2026-77911Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
medium
CVE-2026-77491Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-78463Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
high
CVE-2026-77487Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
high
CVE-2026-78516Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.
medium
CVE-2026-80074Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
high
CVE-2026-78507Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
high
CVE-2026-80079Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
medium
CVE-2026-81396Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
CVE-2026-80089Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
medium
CVE-2026-81399Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-81354Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
high
CVE-2026-78520Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
medium
CVE-2026-78450Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
high
CVE-2026-83954Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
high
CVE-2026-83948Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.
high
CVE-2026-83987Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
high
CVE-2026-83970Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
high
CVE-2026-83996Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
high
CVE-2026-83988Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
high
CVE-2026-83971Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
high
CVE-2026-81401Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-83974Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
high
CVE-2026-81954Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
CVE-2026-85877Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
high
CVE-2026-83968Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
high
CVE-2026-83998Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
high
CVE-2026-83949Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-81953Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
CVE-2026-81387Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-81381Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
high
CVE-2026-81394Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-81393Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
medium
CVE-2026-78503Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
medium