Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-70323
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70325
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70316
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70318
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70319
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70320
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70322
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-70313
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70312
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70314
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
HIGH 8.8
CVE-2026-65811
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Power Bi Report Server
No fix yet
HIGH 8.1
CVE-2026-63520
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20522+
HIGH 8.1
CVE-2026-61363
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 8.1
CVE-2026-59134
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.4
CVE-2026-62828
Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.
Edge
No fix yet
HIGH 8.8
CVE-2026-54120
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Surface Management Services
No fix yet
MEDIUM 5.5
CVE-2026-55124
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
365 Apps
16.0.10417.20175 / 16.0.19725.20434+
HIGH 7.8
CVE-2026-50670
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 7.8
CVE-2026-50417
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-50370
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.5
CVE-2026-50328
Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-55899
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20175+
HIGH 7.5
CVE-2026-58292
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
150.0.4078.48+
HIGH 8.8
CVE-2026-57985
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
150.0.4078.48+
MEDIUM 5.5
CVE-2026-48569
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Visual Studio Code
1.123.2+
MEDIUM 5.4
CVE-2026-47641
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20384+
HIGH 7.8
CVE-2026-45636
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-44811
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Windows 11 26h1
10.0.28000.2269+
HIGH 8.1
CVE-2026-40376
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.123.2+
HIGH 8.8
CVE-2026-40411
Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
Azure Virtual Network Gateway
Mitigation only