cve
Veille des vulnérabilités Archive complète
identifiantvulnérabilitésévéritépublié
CVE-2026-55137Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-55140Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-55141Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-55144Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.Microsoft Windows 11 24h2 Élevée CVSS 7.1 CVE-2026-55145Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.Microsoft Copilot Élevée CVSS 7.1 CVE-2026-55651Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users.
Using these hashes, an attacker can modify or delete appointments of other providers, resulting in an Appointments Takeover. Version 1.6.0 fixes the issue. Élevée CVSS 7.1 CVE-2026-55898Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Microsoft 365 Apps Élevée CVSS 7.1 CVE-2026-55899Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-55944Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.Microsoft Dynamics Nav Critique CVSS 9.8 CVE-2026-55947Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-55948Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-55949Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-55954Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims.
The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback id_token against Apple's JWKS but does not validate any registered claims. The iss, aud, exp, and iat claims are read from the token and passed on to Ueberauth.Strategy.Apple.handle_callback!/1, which derives the logged-in user's uid and email directly from the unvalidated sub claim.
An attacker who obtains any Apple-signed ID token bearing the victim's sub (via a captured expired token, or via an ID token issued to a sibling client in the same Apple developer team) can replay it against the vulnerable callback and be authenticated as the victim. The absent exp check makes stolen tokens usable indefinitely, and the absent aud check enables cross-application account takeover across clients that share an Apple developer team.
This issue affects ueberauth_apple: from 0.1.0 before 0.6.2. Critique CVSS 9.1 CVE-2026-56155Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.Microsoft Active Directory Federation Services Critique CVSS 7.8 CVE-2026-56156Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-56159Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-56164Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.Microsoft SharePoint Server Critique CVSS 9.8 CVE-2026-56169Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.Microsoft Windows Admin Center Élevée CVSS 8.8 CVE-2026-56170Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.Microsoft .net Élevée CVSS 7.5 CVE-2026-56173Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7 CVE-2026-56175Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-56176Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-56178Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.Microsoft Defender For Endpoint Élevée CVSS 7 CVE-2026-56181Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.Microsoft Windows 11 24h2 Élevée CVSS 8.3 CVE-2026-56182Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-56183Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-56187Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-56188Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 CVE-2026-56189Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 8.4 CVE-2026-56190Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-56194Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 CVE-2026-56196Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.Microsoft Windows Admin Center Élevée CVSS 8.8 CVE-2026-56197Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.Microsoft Windows Admin Center Élevée CVSS 8.8 CVE-2026-56451A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application. Critique CVSS 10 CVE-2026-56642Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.Microsoft Fabric Data Warehouse Élevée CVSS 8.8 CVE-2026-56643Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-56644Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-56647Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 CVE-2026-56648Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-56649Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 CVE-2026-56650Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57087Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57088Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-57089Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-57090Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-57091Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57092Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Critique CVSS 9.9 CVE-2026-57093Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57094Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 CVE-2026-57095Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57096Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57102Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.Microsoft Visual Studio Code Élevée CVSS 8.8 CVE-2026-57107Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.Microsoft Windows Admin Center Élevée CVSS 7.8 CVE-2026-57108Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.Microsoft .net Élevée CVSS 7.5 CVE-2026-57898In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API.
The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied filename was treated as an opaque GridFS key and was not normalized or restricted as a filesystem path. A remote attacker could upload thumbnail content using an absolute or traversal-style filename, then trigger thumbnail retrieval so that the uploaded bytes were written to the attacker-chosen path on the server filesystem.
This could allow writing files anywhere the Java process has permission to write and may lead to remote code execution. The default InMemory backend is not affected by this specific path because it normalizes and restricts file paths to its temporary directory.
The issue is fixed in Eclipse BaSyx Java Server SDK 2.0.0-milestone-13.Analyse NVD en cours Critique CVSS 9 CVE-2026-57968Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.Microsoft Windows Subsystem For Linux Élevée CVSS 7.8 CVE-2026-57969Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.Microsoft Azure Cyclecloud Élevée CVSS 8.8 CVE-2026-57979Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58229Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service.
The Mint.HTTP1.decode_headers/5 and Mint.HTTP1.decode_trailer_headers/4 functions in lib/mint/http1.ex accumulate every parsed response header and chunked-trailer field into a per-request list that persists across incoming TCP segments as request.headers_buffer, and only clear it when the terminating blank line is received. The section has no cap on the number of headers or on total bytes, and the underlying :erlang.decode_packet(:httph_bin, binary, []) parser is invoked with an empty option list so its per-line and per-packet size limits also default to unlimited.
A malicious HTTP server (reachable directly, via an attacker-controlled redirect, via SSRF, or via a man-in-the-middle) can stream complete header lines (or, after a chunked body, complete trailer lines) indefinitely without ever emitting the terminating blank line. The connection state grows without bound until the BEAM node is killed by the operating system's out-of-memory handler, taking down the entire application that uses Mint as an HTTP client.
This issue affects mint: from 0.1.0 before 1.9.2. Élevée CVSS 8.2 CVE-2026-58233SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system.Analyse NVD en cours Élevée CVSS 7.6 CVE-2026-58277Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-58319Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service.
This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.Apache Doris Critique CVSS 9.1 CVE-2026-58476Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation or origin verification. Attackers can trigger actions such as disabling the passphrase, rebooting the device, deleting programs, or installing plugins, with the default configuration exposing these endpoints to unauthenticated users due to no required passphrase and a default credential of 'opendoor'.Dan-in-ca Sustainable Irrigation Platform Élevée CVSS 8.1 CVE-2026-58477Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation.Dan-in-ca Sustainable Irrigation Platform Élevée CVSS 7.5 CVE-2026-58479Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.Dan-in-ca Sustainable Irrigation Platform Critique CVSS 9.8 CVE-2026-58526Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58527Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-58529Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.Microsoft Windows 11 26h1 Élevée CVSS 7.1 CVE-2026-58530Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58531Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58532Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58533Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58534Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58535Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58536Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58537Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-58538Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58539Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58540Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58541Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58542Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-58544Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-58547Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58594Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-58595Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.Microsoft Bing Search Élevée CVSS 8.1 CVE-2026-58601Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58602Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-58608Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58609Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58610Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58613Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58617Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.Microsoft 365 Copilot Critique CVSS 9.8 CVE-2026-58618Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-58619Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-58626Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.Microsoft Windows 10 21h2 Élevée CVSS 8.8 CVE-2026-58627Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58628Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58629Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-58631Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.Microsoft Windows Admin Center Élevée CVSS 7.8 CVE-2026-58632Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 9201–9300 / 11286 CVE