FR
live
cve

Full archive

Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-62886Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.Microsoft Visual Studio 2022 High CVSS 7.8 11/08 CVE-2026-62888Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7.8 11/08 CVE-2026-62889Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 11/08 CVE-2026-62890Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-62892Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 11/08 CVE-2026-62893Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 11/08 CVE-2026-62894Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-62897Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.Microsoft .net Framework High CVSS 7 11/08 CVE-2026-62898Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.Microsoft Visual Studio 2022 High CVSS 7.5 11/08 CVE-2026-62901Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.Microsoft Visual Studio 2022 High CVSS 7.5 11/08 CVE-2026-62908Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 11/08 CVE-2026-62909Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.Microsoft Visual Studio 2022 High CVSS 7.8 11/08 CVE-2026-62910Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.Microsoft Exchange Server High CVSS 8.8 11/08 CVE-2026-62911Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.Microsoft Exchange Server High CVSS 8 11/08 CVE-2026-62913Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.Microsoft Exchange Server High CVSS 8.8 11/08 CVE-2026-63177Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example `/x/../upload/...`) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue.NVD analysis in progress High CVSS 7.1 11/08 CVE-2026-63513Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-63514Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-63515Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-63518Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-63519Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-63520Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.1 11/08 CVE-2026-63522Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.Microsoft Azure Sql Database High CVSS 7.8 11/08 CVE-2026-63525Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-63526Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-63527Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-63532Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-63533Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64629A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-64898Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64901Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-64903Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64904Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64905Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64906Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64907Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64908Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64909Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64910Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64911Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64912Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64914Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64915Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64919Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64920Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-64921Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65656Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-65657Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-65658Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65660Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65661Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-65663Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65664Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-65665Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65671Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-65672Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 High CVSS 7.8 11/08 CVE-2026-65673Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.Microsoft Entra Connect High CVSS 7.8 11/08 CVE-2026-65675No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.NVD analysis in progress High CVSS 7.1 11/08 CVE-2026-65678Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 11/08 CVE-2026-65679Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 11/08 CVE-2026-65681Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 11/08 CVE-2026-65767Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.Microsoft Teams High CVSS 7.6 11/08 CVE-2026-65768Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.Microsoft Teams Critical CVSS 9.8 11/08 CVE-2026-65769Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.Microsoft Teams High CVSS 7.5 11/08 CVE-2026-65773Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 11/08 CVE-2026-65774Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-65775Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-65776Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 11/08 CVE-2026-65778Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 11/08 CVE-2026-65779Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 11/08 CVE-2026-65780Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 11/08 CVE-2026-65781Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 11/08 CVE-2026-65782Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 11/08 CVE-2026-65783Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 11/08 CVE-2026-65786Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-65787Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-65788Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 High CVSS 7 11/08 CVE-2026-65789Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 11/08 CVE-2026-65790Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-65791Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critical CVSS 9.8 11/08 CVE-2026-65796Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 11/08 CVE-2026-65799Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-65807Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.Microsoft 365 Apps High CVSS 8.8 11/08 CVE-2026-65810Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Microsoft .net Framework High CVSS 7.8 11/08 CVE-2026-65811Improper input validation in Power BI allows an authorized attacker to execute code over a network.Microsoft Power Bi Report Server High CVSS 8.8 11/08 CVE-2026-65813Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.Microsoft Exchange Server High CVSS 8.8 11/08 CVE-2026-65814Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-65815Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.Microsoft Dynamics 365 High CVSS 8.8 11/08 CVE-2026-66145An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.NVD analysis in progress Critical CVSS 9.1 11/08 CVE-2026-66147An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.NVD analysis in progress Critical CVSS 9.4 11/08 CVE-2026-66149Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-66150Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.NVD analysis in progress High CVSS 7.8 11/08 CVE-2026-66154An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.NVD analysis in progress High CVSS 8.3 11/08 CVE-2026-66763SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.NVD analysis in progress High CVSS 7.9 11/08 CVE-2026-66799Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 11/08 CVE-2026-66802Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1809 High CVSS 8.1 11/08 CVE-2026-66804Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 22h2 High CVSS 7.8 11/08 CVE-2026-66805Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-66807Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 11/08 CVE-2026-66808Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08
3501–3600 / 11286 CVE

Type at least two characters.

navigate open esc dismiss