SEPTEMBER 27, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

380,885 records on file
Page 751 of 12,697
CVE ID Score Description
16d ago
7.8

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

16d ago
6.7

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

16d ago
8.8

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

16d ago
6.5

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

16d ago
6.5

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

16d ago
8.8

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

16d ago
5.5

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

16d ago
8.8

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

16d ago
5.5

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

16d ago
5.5

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

16d ago
8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

16d ago
5.5

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

16d ago
5.5

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

16d ago
5.5

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

16d ago
5.5

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

16d ago
5.5

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

16d ago
5.5

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

16d ago
5.5

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

16d ago
7.8

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

16d ago
5.5

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

16d ago
7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

16d ago
5.5

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

16d ago
7

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

16d ago
9.3

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

16d ago
6.7

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

16d ago
8.4

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

16d ago
8.8

Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

16d ago
8.2

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

16d ago
7.8

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

16d ago
9.1

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.