Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26897
Total
1982
Critical
8080
High
8318
Medium
CVE ID Severity Score Description Published
CVE-2026-47639 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Jun 09, 2026
CVE-2026-47638 MEDIUM 4.6 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Jun 09, 2026
CVE-2026-47637 MEDIUM 4.6 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Jun 09, 2026
CVE-2026-47636 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Jun 09, 2026
CVE-2026-47635 HIGH 8.4 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. Jun 09, 2026
CVE-2026-47634 HIGH 7.3 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Jun 09, 2026
CVE-2026-47631 HIGH 8.1 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. Jun 09, 2026
CVE-2026-47298 HIGH 8.0 Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Jun 09, 2026
CVE-2026-47293 HIGH 7.0 Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. Jun 09, 2026
CVE-2026-47292 HIGH 7.8 Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. Jun 09, 2026
CVE-2026-47291 CRITICAL 9.8 Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. Jun 09, 2026
CVE-2026-47289 HIGH 8.8 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Jun 09, 2026
CVE-2026-47288 HIGH 7.1 Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. Jun 09, 2026
CVE-2026-47287 MEDIUM 6.5 Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. Jun 09, 2026
CVE-2026-47284 MEDIUM 6.5 Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. Jun 09, 2026
CVE-2026-47281 CRITICAL 9.6 Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Jun 09, 2026
CVE-2026-46492 HIGH 7.2 md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown … Jun 09, 2026
CVE-2026-45771 HIGH 7.5 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. … Jun 09, 2026
CVE-2026-45658 HIGH 7.8 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Jun 09, 2026
CVE-2026-45657 CRITICAL 9.8 Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. Jun 09, 2026
CVE-2026-45656 HIGH 7.8 Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. Jun 09, 2026
CVE-2026-45655 MEDIUM 5.3 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Jun 09, 2026
CVE-2026-45654 HIGH 7.9 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Jun 09, 2026
CVE-2026-45653 HIGH 7.0 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Jun 09, 2026
CVE-2026-45650 MEDIUM 4.3 User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. Jun 09, 2026