Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2026-47636
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-47639
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-47631
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …
Exchange Server
15.02.2562.043+
MEDIUM 5.4
CVE-2026-47637
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-47638
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20384+
CRITICAL 9.8
CVE-2026-47291EPSS 23%
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 8.8
CVE-2026-47289
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows App
2.0.1193.0 / 10.0.14393.9234+
HIGH 7.8
CVE-2026-47292
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Visual Studio Code
1.123.1+
HIGH 7.1
CVE-2026-47288
Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.
Windows Server 2012
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.0
CVE-2026-47293
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
MEDIUM 6.5
CVE-2026-47284
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a netwo…
Visual Studio Code
1.123.1+
MEDIUM 6.5
CVE-2026-47287
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Visual Studio Code
1.123.1+
CRITICAL 9.8
CVE-2026-45657EPSS 15%
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Windows 11 23h2
10.0.20348.5256 / 10.0.22631.7219+
CRITICAL 9.6
CVE-2026-47281
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.123.1+
MEDIUM 6.8
CVE-2026-45658
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.9
CVE-2026-45654
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Windows 11 24h2
10.0.26100.8655 / 10.0.26100.32995+
HIGH 7.8
CVE-2026-45656
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.1
CVE-2026-45649
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
Excel
No fix yet
HIGH 7.0
CVE-2026-45653
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
MEDIUM 5.3
CVE-2026-45655
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 8.8
CVE-2026-45648
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
Windows Server 2022
10.0.20348.5256 / 10.0.26100.32995+
HIGH 8.0
CVE-2026-45644
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker…
Live Share Canvas
1.4.2+
HIGH 7.8
CVE-2026-45641
Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Windows 10 21h2
10.0.19044.7417 / 10.0.19045.7417+
HIGH 7.8
CVE-2026-45645
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-45643
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.0
CVE-2026-45647
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Defender For Endpoint
101.26042.0011+
HIGH 8.1
CVE-2026-45635
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code o…
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-45636
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-45637
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8880 / 10.0.19044.7417+
HIGH 7.8
CVE-2026-45638
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+