Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

365 Apps HIGH 7.8
CVE-2026-55038

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55039

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55041

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55043

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Patch available
Fix from $1,950 2026-07-14
365 Apps MEDIUM 5.5
CVE-2026-55042

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

Patch available
Fix from $1,600 2026-07-14
Sharepoint Server HIGH 8.7
CVE-2026-55034

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55031

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55032

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55033

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55036

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55037

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55024

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55025

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55029

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
365 Apps MEDIUM 5.5
CVE-2026-55026

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
365 Apps MEDIUM 5.5
CVE-2026-55027

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
365 Apps MEDIUM 5.5
CVE-2026-55028

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55030

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server HIGH 8.7
CVE-2026-55021

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55017

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Patch available
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55018

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Patch available
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55022

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Patch available
Fix from $1,950 2026-07-14
365 Apps MEDIUM 5.5
CVE-2026-55023

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55016

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55019

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-55020

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Minecraft Bedrock Dedicated Server CRITICAL 9.8
CVE-2026-55010

Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-14
365 Apps HIGH 7.8
CVE-2026-54131

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.4
CVE-2026-54128

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14