Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2026-45491
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
.net
8.0.28 / 9.0.17+
HIGH 7.0
CVE-2026-45487
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges loca…
Windows 10 21h2
10.0.19044.7417 / 10.0.19045.7417+
HIGH 7.8
CVE-2026-45486
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.8
CVE-2026-45484EPSS 35%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20384+
HIGH 8.4
CVE-2026-45482
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attack…
Visual Studio Code
1.123.2+
HIGH 8.2
CVE-2026-45476
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
Azure Network Adapter
Mitigation only
HIGH 7.8
CVE-2026-45475
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-45479
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-45481
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-45483
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker…
Sharepoint Server
16.0.19725.20384+
HIGH 8.4
CVE-2026-45472
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2026-45474
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-45469
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-45471
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-45467
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-45468
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20384+
HIGH 8.4
CVE-2026-45458
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19725.20384+
HIGH 8.4
CVE-2026-45461
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2026-45463
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
MEDIUM 5.4
CVE-2026-45464
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-45465
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20384+
MEDIUM 5.4
CVE-2026-45462
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20384+
HIGH 8.8
CVE-2026-45454
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execut…
Sharepoint Server
16.0.19725.20384+
HIGH 8.4
CVE-2026-45456
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19725.20384+
HIGH 7.8
CVE-2026-45457
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
MEDIUM 5.4
CVE-2026-45453
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20384+
HIGH 8.2
CVE-2026-44822
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-44820
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-44823
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-44819
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19725.20384+