| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65660 | Hig | 0.69 | 8.8 | 0.02 | KEV | Aug 11, 2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| CVE-2026-65658 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65657 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-65656 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64922 | Med | 0.30 | 4.6 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-64921 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-64920 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64919 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64917 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-64916 | Med | 0.30 | 4.6 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-64915 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64914 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64912 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64911 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64910 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64909 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64908 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64907 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64906 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64905 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64904 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64903 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64902 | Med | 0.30 | 4.6 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-64901 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-64900 | Hig | 0.47 | 7.3 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-64899 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-64898 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-64897 | Med | 0.30 | 4.6 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-63533 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63532 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63531 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63530 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63529 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63528 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63527 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63526 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63525 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63524 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63522 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-63521 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63520 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-63519 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63518 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63517 | Med | 0.36 | 5.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-63516 | Med | 0.42 | 6.5 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-63515 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63514 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-63513 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63512 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | ||
| CVE-2026-62917 | Med | 0.30 | 4.6 | 0.01 | Aug 11, 2026 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
- risk 0.69cvss 8.8epss 0.02
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.30cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.01
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.30cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.30cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.47cvss 7.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.30cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.53cvss 8.1epss 0.01
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.42cvss 6.5epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.42cvss 6.5epss 0.01
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
- risk 0.30cvss 4.6epss 0.01
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.