| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-70315 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70314 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70313 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70312 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70311 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-70310 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70307 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70306 | Cri | 0.60 | 9.3 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-70304 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70130 | Hig | 0.55 | 8.4 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-69320 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69306 | Hig | 0.53 | 8.2 | 0.01 | Aug 11, 2026 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-69278 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-69223 | Cri | 0.59 | 9.1 | 0.01 | Aug 11, 2026 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. | ||
| CVE-2026-68821 | Hig | 0.47 | 7.3 | 0.00 | Aug 11, 2026 | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68820 | Hig | 0.58 | 7.0 | 0.00 | KEV | Aug 11, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-68819 | Med | 0.38 | 5.9 | 0.01 | Aug 11, 2026 | Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-68817 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68816 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68815 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68814 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68813 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68812 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68811 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68810 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68809 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68808 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68807 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68806 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68805 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68804 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68803 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68802 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68801 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68800 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68799 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68798 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68797 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-68796 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68795 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68794 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68793 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68792 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-66810 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-66809 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-66808 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-66807 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-66806 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-66805 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-66804 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. |
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.55cvss 8.4epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.2epss 0.01
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.51cvss 7.8epss 0.00
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- risk 0.59cvss 9.1epss 0.01
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
- risk 0.47cvss 7.3epss 0.00
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
- risk 0.58cvss 7.0epss 0.00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.38cvss 5.9epss 0.01
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.00
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.01
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.
- risk 0.36cvss 5.5epss 0.00
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.00
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.