CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 9d ago | 8.8 | is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. |
| Exploit 9d ago | 7.3 | is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. |
| 9d ago | 8.1 | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. |
| 9d ago | 7.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| 9d ago | 7.8 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| 9d ago | 7.8 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
| 9d ago | 7.8 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
| 9d ago | 7.8 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
| 9d ago | 7.8 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
| 9d ago | 8.1 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. |
| 9d ago | 7.8 | Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. |
| 9d ago | 8.8 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. |
| 9d ago | 8.8 | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. |
| 9d ago | 7.8 | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. |
| 9d ago | 8.8 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
| 9d ago | 8.8 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| 9d ago | 8.8 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |
| 9d ago | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| 9d ago | 7.8 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
| 9d ago | 7.8 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| 9d ago | 7 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
| 9d ago | 8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| 9d ago | 8.8 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. |
| 9d ago | 8.2 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
| 9d ago | 7.8 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |
| 9d ago | 7.3 | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. |
| KEV 9d ago | 7 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
| 9d ago | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| 9d ago | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| 9d ago | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |