Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2026-70318
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
365 Apps
Patch available
MEDIUM 5.5
CVE-2026-70317
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70316
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70315
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70314
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-70313
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70312
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-70311
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-70310
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
HIGH 7.0
CVE-2026-70307
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
CRITICAL 9.3
CVE-2026-70306
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20434+
HIGH 7.8
CVE-2026-70304
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9121+
HIGH 7.8
CVE-2026-70130
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 8.8
CVE-2026-69320
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to e…
Visual Studio Code
1.132.1+
HIGH 8.2
CVE-2026-69306
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Visual Studio Code
1.132.1+
CRITICAL 9.1
CVE-2026-69223
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommend…
Allura
1.19.1+
HIGH 7.8
CVE-2026-69278
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Visual Studio Code
1.132.1+
HIGH 7.8
CVE-2026-68821
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
App Installer
1.30.80+
HIGH 7.0
CVE-2026-68820 KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.5
CVE-2026-68819
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.8
CVE-2026-68817
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Patch available
HIGH 7.8
CVE-2026-68816
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Patch available
HIGH 7.8
CVE-2026-68815
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Patch available
HIGH 7.8
CVE-2026-68814
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Patch available
MEDIUM 5.5
CVE-2026-68813
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
365 Apps
Patch available
HIGH 7.8
CVE-2026-68812
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Patch available
HIGH 7.8
CVE-2026-68811
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Patch available
HIGH 7.8
CVE-2026-68810
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Patch available
MEDIUM 5.5
CVE-2026-68809
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-68808
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
365 Apps
Patch available