cve
Veille des vulnérabilités Archive complète
identifiantvulnérabilitésévéritépublié
CVE-2026-62886Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.Microsoft Visual Studio 2022 Élevée CVSS 7.8 CVE-2026-62888Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 CVE-2026-62889Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 CVE-2026-62890Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-62892Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7 CVE-2026-62893Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-62894Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-62897Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.Microsoft .net Framework Élevée CVSS 7 CVE-2026-62898Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.Microsoft Visual Studio 2022 Élevée CVSS 7.5 CVE-2026-62901Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.Microsoft Visual Studio 2022 Élevée CVSS 7.5 CVE-2026-62908Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-62909Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.Microsoft Visual Studio 2022 Élevée CVSS 7.8 CVE-2026-62910Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.Microsoft Exchange Server Élevée CVSS 8.8 CVE-2026-62911Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.Microsoft Exchange Server Élevée CVSS 8 CVE-2026-62913Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.Microsoft Exchange Server Élevée CVSS 8.8 CVE-2026-63177Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example `/x/../upload/...`) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue.Analyse NVD en cours Élevée CVSS 7.1 CVE-2026-63513Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-63514Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-63515Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-63518Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-63519Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-63520Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.1 CVE-2026-63522Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.Microsoft Azure Sql Database Élevée CVSS 7.8 CVE-2026-63525Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-63526Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-63527Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-63532Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-63533Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64629A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.Analyse NVD en cours Élevée CVSS 7.8 CVE-2026-64898Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64901Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-64903Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64904Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64905Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64906Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64907Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64908Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64909Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64910Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64911Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64912Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64914Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64915Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64919Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64920Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-64921Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-65656Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-65657Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-65658Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-65660Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-65661Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-65663Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-65664Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-65665Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-65671Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-65672Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7.8 CVE-2026-65673Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.Microsoft Entra Connect Élevée CVSS 7.8 CVE-2026-65675No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.Analyse NVD en cours Élevée CVSS 7.1 CVE-2026-65678Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-65679Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 CVE-2026-65681Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-65767Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.Microsoft Teams Élevée CVSS 7.6 CVE-2026-65768Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.Microsoft Teams Critique CVSS 9.8 CVE-2026-65769Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.Microsoft Teams Élevée CVSS 7.5 CVE-2026-65773Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-65774Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-65775Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-65776Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-65778Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-65779Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-65780Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-65781Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-65782Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-65783Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-65786Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-65787Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-65788Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7 CVE-2026-65789Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 CVE-2026-65790Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-65791Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-65796Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 CVE-2026-65799Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-65807Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.Microsoft 365 Apps Élevée CVSS 8.8 CVE-2026-65810Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Microsoft .net Framework Élevée CVSS 7.8 CVE-2026-65811Improper input validation in Power BI allows an authorized attacker to execute code over a network.Microsoft Power Bi Report Server Élevée CVSS 8.8 CVE-2026-65813Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.Microsoft Exchange Server Élevée CVSS 8.8 CVE-2026-65814Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-65815Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.Microsoft Dynamics 365 Élevée CVSS 8.8 CVE-2026-66145An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.Analyse NVD en cours Critique CVSS 9.1 CVE-2026-66147An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.Analyse NVD en cours Critique CVSS 9.4 CVE-2026-66149Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.Analyse NVD en cours Élevée CVSS 7.8 CVE-2026-66150Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.Analyse NVD en cours Élevée CVSS 7.8 CVE-2026-66154An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.Analyse NVD en cours Élevée CVSS 8.3 CVE-2026-66763SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in a high impact on confidentiality and integrity. There is no impact on availability.Analyse NVD en cours Élevée CVSS 7.9 CVE-2026-66799Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-66802Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1809 Élevée CVSS 8.1 CVE-2026-66804Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 22h2 Élevée CVSS 7.8 CVE-2026-66805Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-66807Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-66808Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 3501–3600 / 11286 CVE