Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26990
Total
2034
Critical
8144
High
8390
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45468 | MEDIUM | 4.6 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Jun 09, 2026 |
| CVE-2026-45467 | MEDIUM | 4.6 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Jun 09, 2026 |
| CVE-2026-45466 | LOW | 3.3 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-45465 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Jun 09, 2026 |
| CVE-2026-45464 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Jun 09, 2026 |
| CVE-2026-45463 | HIGH | 8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-45462 | MEDIUM | 4.6 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Jun 09, 2026 |
| CVE-2026-45461 | HIGH | 8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-45460 | MEDIUM | 4.7 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-45459 | LOW | 3.3 | Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | Jun 09, 2026 |
| CVE-2026-45458 | HIGH | 8.4 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-45457 | HIGH | 7.8 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-45456 | HIGH | 8.4 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-45455 | LOW | 3.3 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | Jun 09, 2026 |
| CVE-2026-45454 | MEDIUM | 6.5 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Jun 09, 2026 |
| CVE-2026-45453 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Jun 09, 2026 |
| CVE-2026-45447 | HIGH | 8.8 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in … | Jun 09, 2026 |
| CVE-2026-45446 | MEDIUM | 4.8 | Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing … | Jun 09, 2026 |
| CVE-2026-45445 | HIGH | 7.5 | Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: … | Jun 09, 2026 |
| CVE-2026-44824 | HIGH | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-44823 | HIGH | 7.8 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-44822 | HIGH | 8.2 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | Jun 09, 2026 |
| CVE-2026-44821 | MEDIUM | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | Jun 09, 2026 |
| CVE-2026-44820 | HIGH | 7.8 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |
| CVE-2026-44819 | HIGH | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 09, 2026 |