Export limit exceeded: 404003 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 20939 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404003 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404003 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 103068 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (103068 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-19546 | 1 Redhat | 1 Enterprise Linux | 2026-09-09 | 8.8 High |
| A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546. | ||||
| CVE-2026-78518 | 1 Microsoft | 11 365 Apps, Excel, Excel 2016 and 8 more | 2026-09-09 | 8.8 High |
| Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-78439 | 1 Microsoft | 4 Office, Office 365, Office Macos 2021 and 1 more | 2026-09-09 | 8.8 High |
| Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69273 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 8.8 High |
| Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69285 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69268 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 8.8 High |
| Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69804 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 7.5 High |
| Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69797 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 8.8 High |
| Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69767 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 8.8 High |
| Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69759 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 8.8 High |
| Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69724 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 8.8 High |
| Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69742 | 1 Microsoft | 6 365 Apps, Office 2019, Office 2021 and 3 more | 2026-09-09 | 8.8 High |
| Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69716 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 8.8 High |
| Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69722 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 8.8 High |
| Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69678 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 8.8 High |
| Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69556 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-67373 | 1 Microsoft | 1 Sql Server 2025 | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-84942 | 2 Aws, Opensearch | 2 Amazon Opensearch Service, Opensearch Dashboards | 2026-09-09 | 8.7 High |
| Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation. | ||||
| CVE-2026-77354 | 1 Getkin | 1 Kin-openapi | 2026-09-09 | 7.5 High |
| kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter into a dense slice by allocating entries from zero through the largest supplied index, after which buildResObj creates another slice of the same length. This allocation occurs before schema validation, so maxItems does not prevent it. An unauthenticated client can send a small query such as param[items][50000000]=x to an endpoint whose deepObject schema contains an array, forcing multi-gigabyte heap allocation and causing an OOM kill or restart loop. Other request-body encodings and styled parameters that do not produce bracketed integer indexes are not affected. This issue is fixed in version 0.142.0. | ||||
| CVE-2026-87553 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||