Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-45491 Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. .net 8.0.28 / 9.0.17+ Fix from $1,6002026-06-09 HIGH 7.0 CVE-2026-45487 Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges loca… Windows 10 21h2 10.0.19044.7417 / 10.0.19045.7417+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-45486 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 8.8 CVE-2026-45484EPSS 35% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,9502026-06-09 HIGH 8.4 CVE-2026-45482 Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attack… Visual Studio Code 1.123.2+ Fix from $1,9502026-06-09 HIGH 8.2 CVE-2026-45476 Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. Azure Network Adapter Mitigation only Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-45475 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19725.20384+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-45479 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-45481 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-45483 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 8.4 CVE-2026-45472 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 8.4 CVE-2026-45474 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-45469 Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-45471 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19725.20384+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-45467 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-45468 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 8.4 CVE-2026-45458 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19725.20384+ Fix from $1,9502026-06-09 HIGH 8.4 CVE-2026-45461 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 8.4 CVE-2026-45463 Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-45464 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-45465 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-45462 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 8.8 CVE-2026-45454 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execut… Sharepoint Server 16.0.19725.20384+ Fix from $1,9502026-06-09 HIGH 8.4 CVE-2026-45456 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19725.20384+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-45457 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-45453 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 8.2 CVE-2026-44822 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-44820 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-44823 Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-44819 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19725.20384+ Fix from $1,9502026-06-09