FR
live
cve

Full archive

Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-54433In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).Roundcube Webmail Critical CVSS 10 14/07 CVE-2026-54572Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.Rclone High CVSS 8.8 14/07 CVE-2026-54684jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlled archive entry contents outside the intended XAPK plugin temporary unpack directory because XApkLoader resolves each entry name directly with tmpDir.resolve(fileName) after a CWD-based ZIP security check. When jadx is launched from a directory that is an ancestor of the config directory, the arbitrary write can plant a JAR in plugins/dropins, and the next jadx run loads the JAR with URLClassLoader and ServiceLoader, executing attacker-controlled plugin code. This issue is fixed in version 1.5.6. High CVSS 7 14/07 CVE-2026-54982Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.Microsoft Windows 10 1607 High CVSS 8.8 14/07 CVE-2026-54983Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 14/07 CVE-2026-54986Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-54987Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-54989Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-54990Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 11 24h2 High CVSS 8.8 14/07 CVE-2026-54991Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 14/07 CVE-2026-54992Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-54993Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1809 High CVSS 7.8 14/07 CVE-2026-54995Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 14/07 CVE-2026-54996Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 14/07 CVE-2026-54999Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.Microsoft Windows 10 1607 High CVSS 8.8 14/07 CVE-2026-55001Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-55002External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.NVD analysis in progress High CVSS 7.8 14/07 CVE-2026-55004Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-55005Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.Microsoft Exchange Server High CVSS 8.8 14/07 CVE-2026-55006Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.Microsoft Exchange Server High CVSS 7.8 14/07 CVE-2026-55008Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.Microsoft Exchange Server Critical CVSS 9.6 14/07 CVE-2026-55009Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.Microsoft Exchange Server High CVSS 7.8 14/07 CVE-2026-55010Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.Microsoft Minecraft Bedrock Dedicated Server Critical CVSS 9.8 14/07 CVE-2026-55011Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.Microsoft Malware Protection Engine High CVSS 7.8 14/07 CVE-2026-55012Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.Microsoft Malware Protection Engine High CVSS 7.8 14/07 CVE-2026-55014Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.Microsoft Remote Help High CVSS 7.8 14/07 CVE-2026-55017Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55018Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55021Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.Microsoft Sharepoint Server High CVSS 8.7 14/07 CVE-2026-55022Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55024Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55025Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55029Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55031Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55032Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55033Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55034Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.Microsoft Sharepoint Server High CVSS 8.7 14/07 CVE-2026-55036Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55037Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55038Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55039Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55040Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.Microsoft Sharepoint Server Critical CVSS 9.1 14/07 CVE-2026-55041Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55043Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55044Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55045Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 8.4 14/07 CVE-2026-55048Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55049Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55052Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.Microsoft Sharepoint Server High CVSS 8.8 14/07 CVE-2026-55053Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55055Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55056Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55058Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55120Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55122Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Microsoft 365 Apps High CVSS 7.1 14/07 CVE-2026-55123Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55125Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55127Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55128Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55129Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55130Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55131Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55132Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55133Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55134Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55136Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55137Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55140Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55141Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55144Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.Microsoft Windows 11 24h2 High CVSS 7.1 14/07 CVE-2026-55145Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.Microsoft Copilot High CVSS 7.1 14/07 CVE-2026-55651Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers, resulting in an Appointments Takeover. Version 1.6.0 fixes the issue. High CVSS 7.1 14/07 CVE-2026-55898Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Microsoft 365 Apps High CVSS 7.1 14/07 CVE-2026-55899Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55944Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.Microsoft Dynamics Nav Critical CVSS 9.8 14/07 CVE-2026-55947Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55948Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55949Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-55954Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback id_token against Apple's JWKS but does not validate any registered claims. The iss, aud, exp, and iat claims are read from the token and passed on to Ueberauth.Strategy.Apple.handle_callback!/1, which derives the logged-in user's uid and email directly from the unvalidated sub claim. An attacker who obtains any Apple-signed ID token bearing the victim's sub (via a captured expired token, or via an ID token issued to a sibling client in the same Apple developer team) can replay it against the vulnerable callback and be authenticated as the victim. The absent exp check makes stolen tokens usable indefinitely, and the absent aud check enables cross-application account takeover across clients that share an Apple developer team. This issue affects ueberauth_apple: from 0.1.0 before 0.6.2. Critical CVSS 9.1 14/07 CVE-2026-56155Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.Microsoft Active Directory Federation Services Critical CVSS 7.8 14/07 CVE-2026-56156Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 14/07 CVE-2026-56159Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 14/07 CVE-2026-56164Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.Microsoft SharePoint Server Critical CVSS 9.8 14/07 CVE-2026-56169Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.Microsoft Windows Admin Center High CVSS 8.8 14/07 CVE-2026-56170Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.Microsoft .net High CVSS 7.5 14/07 CVE-2026-56173Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 14/07 CVE-2026-56175Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-56176Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-56178Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.Microsoft Defender For Endpoint High CVSS 7 14/07 CVE-2026-56181Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.Microsoft Windows 11 24h2 High CVSS 8.3 14/07 CVE-2026-56182Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 14/07 CVE-2026-56183Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 14/07 CVE-2026-56187Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 14/07 CVE-2026-56188Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 14/07 CVE-2026-56189Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 8.4 14/07 CVE-2026-56190Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 14/07 CVE-2026-56194Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.8 14/07 CVE-2026-56196Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.Microsoft Windows Admin Center High CVSS 8.8 14/07 CVE-2026-56197Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.Microsoft Windows Admin Center High CVSS 8.8 14/07 CVE-2026-56451A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application. Critical CVSS 10 14/07
3001–3100 / 5155 CVE

Type at least two characters.

navigate open esc dismiss