VYPR

CVEs

117,522 total · page 489 of 2,351

  • CVE-2026-21304HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-21283HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-21281HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-21280HigJan 13, 2026
    risk 0.56cvss 8.6epss 0.00

    Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker…

  • CVE-2026-21277HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-21276HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-21275HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-21274HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass security measures and execute…

  • CVE-2026-21272HigJan 13, 2026
    risk 0.56cvss 8.6epss 0.00

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could leverage this vulnerability to manipulate or inject malicious data into files on the system. Exploitation of…

  • CVE-2026-21271HigJan 13, 2026
    risk 0.56cvss 8.6epss 0.00

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2026-21268HigJan 13, 2026
    risk 0.56cvss 8.6epss 0.00

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2026-21267HigJan 13, 2026
    risk 0.56cvss 8.6epss 0.01

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue requires user…

  • CVE-2026-21226HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

  • CVE-2026-21224HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2026-21221HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-21219HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2026-20965HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20957HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-20956HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-20955HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.01

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-20953HigJan 13, 2026
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-20952HigJan 13, 2026
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-20951HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

  • CVE-2026-20950HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-20949HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-20948HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.01

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-20947HigJan 13, 2026
    risk 0.59cvss 8.8epss 0.19

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-20946HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-20944HigJan 13, 2026
    risk 0.55cvss 8.4epss 0.01

    Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-20943HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.01

    Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-20941HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20940HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20938HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20934HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20931HigJan 13, 2026
    risk 0.52cvss 8.0epss 0.01

    External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

  • CVE-2026-20929HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20926HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20924HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20923HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20922HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

  • CVE-2026-20921HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20920HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20919HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20918HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20877HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20875HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.02

    Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-20874HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20873HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20871HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.04

    Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20870HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.