CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-58641

    Last Modified: 3 Sept 2026

    Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-54981

    Last Modified: 17 Aug 2026

    Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-42976

    Last Modified: 14 Aug 2026

    Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-72971

    Last Modified: 14 Aug 2026

    Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

    Published: 11 Aug 2026
    7.3
    High

    CVE-2026-70355

    Last Modified: 14 Aug 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70348

    Last Modified: 14 Aug 2026

    Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70347

    Last Modified: 14 Aug 2026

    Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7.5
    High

    CVE-2026-73089

    Last Modified: 14 Aug 2026

    Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `<year>-<month>-<day>` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70346

    Last Modified: 14 Aug 2026

    Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70345

    Last Modified: 14 Aug 2026

    Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70344

    Last Modified: 14 Aug 2026

    Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-66804

    Last Modified: 14 Aug 2026

    Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7
    High

    CVE-2026-65783

    Last Modified: 13 Aug 2026

    Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7.5
    High

    CVE-2026-61352

    Last Modified: 14 Aug 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-65806

    Last Modified: 12 Aug 2026

    Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    8.1
    High

    CVE-2026-70340

    Last Modified: 12 Aug 2026

    Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-57104

    Last Modified: 12 Aug 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-70336

    Last Modified: 12 Aug 2026

    Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70335

    Last Modified: 11 Aug 2026

    Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    6.7
    Medium

    CVE-2026-70330

    Last Modified: 18 Aug 2026

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    6.7
    Medium

    CVE-2026-70304

    Last Modified: 17 Aug 2026

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-70329

    Last Modified: 14 Aug 2026

    Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-70328

    Last Modified: 13 Aug 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-70327

    Last Modified: 13 Aug 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-70324

    Last Modified: 13 Aug 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70322

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70323

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70320

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70319

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70325

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70317

    Last Modified: 17 Aug 2026

    Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70314

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70318

    Last Modified: 17 Aug 2026

    Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-70321

    Last Modified: 13 Aug 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70315

    Last Modified: 14 Aug 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70316

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70310

    Last Modified: 14 Aug 2026

    Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70313

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70311

    Last Modified: 14 Aug 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-70312

    Last Modified: 14 Aug 2026

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-66301

    Last Modified: 11 Aug 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-65769

    Last Modified: 11 Aug 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    7
    High

    CVE-2026-70307

    Last Modified: 14 Aug 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    8.2
    High

    CVE-2026-69306

    Last Modified: 11 Aug 2026

    Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-69278

    Last Modified: 12 Aug 2026

    Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-69320

    Last Modified: 12 Aug 2026

    Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    7.3
    High

    CVE-2026-68821

    Last Modified: 12 Aug 2026

    Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7
    High

    CVE-2026-68820

    Last Modified: 14 Aug 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    5.9
    Medium

    CVE-2026-68819

    Last Modified: 14 Aug 2026

    Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-68816

    Last Modified: 13 Aug 2026

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 11 Aug 2026