Vulnerability index

Browse CVEs

3,135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-66806 Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 365 Apps No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-65807 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a networ… 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-65811 Improper input validation in Power BI allows an authorized attacker to execute code over a network. Power Bi Report Server No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-65813 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Exchange Server No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65799 Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65810 Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. .net Framework No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-65806 Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. Azure Cyclecloud No fix yet Fix from $4,0002026-08-11 MEDIUM 6.7 CVE-2026-65795 No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,0002026-08-11 MEDIUM 6.7 CVE-2026-65797 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,0002026-08-11 MEDIUM 6.7 CVE-2026-65798 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,0002026-08-11 HIGH 8.1 CVE-2026-65789 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65774 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65673 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to… Entra Connect No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-65675 No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. Github Copilot Chat No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-65661 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65664 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64919 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64920 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65656 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute co… 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65657 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-64917 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 365 Apps No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-64910 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64911 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64912 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64914 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64915 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64903 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64904 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64905 Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64906 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11