CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2026-45606

    Last Modified: 11 Jun 2026

    Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-45640

    Last Modified: 11 Jun 2026

    Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.5
    High

    CVE-2026-45639

    Last Modified: 10 Jun 2026

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45605

    Last Modified: 11 Jun 2026

    Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.5
    High

    CVE-2026-45583

    Last Modified: 10 Jun 2026

    Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    8.8
    High

    CVE-2026-45504

    Last Modified: 15 Jun 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Published: 9 Jun 2026
    8.1
    High

    CVE-2026-45503

    Last Modified: 8 Jul 2026

    Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

    Published: 9 Jun 2026
    5
    Medium

    CVE-2026-45502

    Last Modified: 15 Jun 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

    Published: 9 Jun 2026
    6.5
    Medium

    CVE-2026-45501

    Last Modified: 8 Jul 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    6.1
    Medium

    CVE-2026-45500

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    6.2
    Medium

    CVE-2026-45491

    Last Modified: 10 Jun 2026

    Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45487

    Last Modified: 11 Jun 2026

    Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45490

    Last Modified: 10 Jun 2026

    Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    3.3
    Low

    CVE-2026-45466

    Last Modified: 10 Jun 2026

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45461

    Last Modified: 8 Jul 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    4.7
    Medium

    CVE-2026-45460

    Last Modified: 8 Jul 2026

    Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45458

    Last Modified: 8 Jul 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45456

    Last Modified: 11 Jun 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-45453

    Last Modified: 8 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44824

    Last Modified: 11 Jun 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44823

    Last Modified: 8 Jul 2026

    Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-44821

    Last Modified: 11 Jun 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44820

    Last Modified: 8 Jul 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44819

    Last Modified: 11 Jun 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-44818

    Last Modified: 8 Jul 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44817

    Last Modified: 8 Jul 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-42902

    Last Modified: 12 Jun 2026

    Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-34335

    Last Modified: 10 Jun 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-33828

    Last Modified: 10 Jun 2026

    Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-40404

    Last Modified: 10 Jun 2026

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-40409

    Last Modified: 11 Jun 2026

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-45483

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    3.3
    Low

    CVE-2026-45485

    Last Modified: 11 Jun 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45486

    Last Modified: 8 Jul 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-45479

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45474

    Last Modified: 8 Jul 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45471

    Last Modified: 24 Jun 2026

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    8.4
    High

    CVE-2026-45472

    Last Modified: 8 Jul 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45475

    Last Modified: 24 Jun 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-45469

    Last Modified: 11 Jun 2026

    Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-45468

    Last Modified: 10 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    4.6
    Medium

    CVE-2026-45467

    Last Modified: 12 Jun 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Jun 2026
    7
    High

    CVE-2026-41108

    Last Modified: 11 Jun 2026

    Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-47980

    Last Modified: 10 Jun 2026

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-47945

    Last Modified: 10 Jun 2026

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-48280

    Last Modified: 10 Jun 2026

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-47985

    Last Modified: 10 Jun 2026

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-47935

    Last Modified: 10 Jun 2026

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-47941

    Last Modified: 10 Jun 2026

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 9 Jun 2026
    5.4
    Medium

    CVE-2026-48251

    Last Modified: 10 Jun 2026

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 9 Jun 2026