Microsoft
300 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-62316
HIGH 8.8
Ufo — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, u…
2026-08-21
CVE-2026-69502
CRITICAL 10
Azure Sql Database — Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges…
2026-08-21
CVE-2026-55013
HIGH 7.1
Windows Remote Help — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoof…
2026-08-20
CVE-2026-55015
MEDIUM 5.5
Windows Remote Help — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
2026-08-20
CVE-2026-62834
CRITICAL 9.3
Azure Data Factory — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elev…
2026-08-20
CVE-2026-63509
CRITICAL 9.9
Microsoft Fabric — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network…
2026-08-20
CVE-2026-65770
CRITICAL 10
Azure Managed Instance For Apache Cassandra — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance f…
2026-08-20
CVE-2026-65801
CRITICAL 10
Microsoft Exchange Online — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate pri…
2026-08-20
CVE-2026-65816
CRITICAL 10
Azure Web Apps — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileg…
2026-08-20
CVE-2026-66309
CRITICAL 9.1
Azure Sql Database — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a netwo…
2026-08-20
CVE-2026-66800
HIGH 8.6
Azure Data Factory — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose informati…
2026-08-20
CVE-2026-68782
CRITICAL 9.9
Azure Sql Database — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database all…
2026-08-20
CVE-2026-68789
CRITICAL 9.9
Azure Sql Database — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database all…
2026-08-20
CVE-2026-69400
CRITICAL 9.6
Azure Logic Apps — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an u…
2026-08-20
CVE-2026-69419
HIGH 8.5
Azure Data Manager For Energy — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code …
2026-08-20
CVE-2026-69519
HIGH 8.6
Azure Stack Hci — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information ove…
2026-08-20
CVE-2026-69543
HIGH 8.5
Azure Virtual Machines — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileg…
2026-08-20
CVE-2026-69555
CRITICAL 10
Azure Arc — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
2026-08-20
CVE-2026-69558
HIGH 8.6
Microsoft Partner Center — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker t…
2026-08-20
CVE-2026-69836
CRITICAL 10
Microsoft Entra — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a…
2026-08-20
CVE-2026-69851
CRITICAL 9.9
Microsoft Entra — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg…
2026-08-20
CVE-2026-69855
HIGH 7.7
Microsoft Copilot In Azure — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose inf…
2026-08-20
CVE-2026-70105
MEDIUM 6.5
Microsoft 365 Apps For Enterprise — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information ove…
2026-08-20
CVE-2026-62727
HIGH 7
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho…
2026-08-19
CVE-2026-69550
MEDIUM 6.5
Windows App For Mac — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a net…
2026-08-19
CVE-2026-76259
HIGH 8.8
Splunk Enterprise — In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with …
2026-08-19
CVE-2026-24301
HIGH 8.8
Copilot Web — Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allow…
2026-08-18
CVE-2026-76037
HIGH 8.4
Chrome — Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local at…
2026-08-18
CVE-2026-73851
MEDIUM 6.1
Kiota — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or …
2026-08-17
CVE-2026-50523
HIGH 7.8
Powershell 7.4 — Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell al…
2026-08-14
CVE-2026-69414
HIGH 7.8
Microsoft Malware Protection Engine — Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defend…● PoC
2026-08-14
CVE-2026-72970
HIGH 8.3
Microsoft Edge (Chromium Based) — Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code …
2026-08-14
CVE-2026-10571
MEDIUM 5.7
Websphere Application Server Liberty — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused…
2026-08-13
CVE-2026-14525
CRITICAL 9.4
Websphere Application Server Liberty — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty …
2026-08-13
CVE-2026-73296
CRITICAL 9.4
Ufo — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, c…● PoC
2026-08-12
CVE-2026-73297
MEDIUM 6.9
Ufo — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _…● PoC
2026-08-12
CVE-2026-73298
HIGH 8.7
Container Migration Solution Accelerator — The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-ag…
2026-08-12
CVE-2026-73299
CRITICAL 10
Prompty — Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript …
2026-08-12
CVE-2026-40375
MEDIUM 6.5
Microsoft Dynamics 365 Business Central 2024 Release Wave 2 — Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over …
2026-08-11
CVE-2026-42976
HIGH 7.8
Windows 10 Version 1607 — Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privi…
2026-08-11
CVE-2026-47285
MEDIUM 6.5
Visual Studio Code — Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allo…
2026-08-11
CVE-2026-47299
HIGH 7.2
Azure Monitor Agent Linux Extension — Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent all…
2026-08-11
CVE-2026-47940
HIGH 7.8
Lightroom Classic — Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrar…
2026-08-11
CVE-2026-48397
HIGH 8.6
Lightroom Classic — Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitr…
2026-08-11
CVE-2026-48404
HIGH 7.8
Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec…
2026-08-11
CVE-2026-48405
HIGH 7.8
Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec…
2026-08-11
CVE-2026-48406
HIGH 7.8
Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec…
2026-08-11
CVE-2026-48407
HIGH 7.8
Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec…
2026-08-11
CVE-2026-48408
HIGH 7.8
Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec…
2026-08-11
CVE-2026-48409
HIGH 7.8
Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec…
2026-08-11
CVE-2026-48410
HIGH 7.8
Lightroom Classic — Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec…
2026-08-11
CVE-2026-48441
HIGH 8.6
Lightroom Classic — Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Travers…
2026-08-11
CVE-2026-48447
HIGH 7.7
Lightroom Classic — Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code …
2026-08-11
CVE-2026-49179
HIGH 8.8
Windows 10 Version 1607 — Improper neutralization of special elements used in a command ('command injection') in Windows Active Director…
2026-08-11
CVE-2026-50472
HIGH 7
Windows 10 Version 1607 — Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-50516
CRITICAL 9.4
Azure Kubernetes Service — Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized atta…
2026-08-11
CVE-2026-54113
HIGH 7.5
Windows 10 Version 1607 — Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny…
2026-08-11
CVE-2026-54123
MEDIUM 5.5
Microsoft Defender For Endpoint For Mac — Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an author…
2026-08-11
CVE-2026-54981
HIGH 7.8
Python Extension For Visual Studio Code — Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an un…
2026-08-11
CVE-2026-54984
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locall…
2026-08-11
CVE-2026-56174
HIGH 7.8
Windows 10 Version 1809 — Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-56179
HIGH 8.3
Windows 11 Version 24h2 — Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perfor…
2026-08-11
CVE-2026-57104
HIGH 8.8
Azure Storage Explorer — Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer…
2026-08-11
CVE-2026-57105
HIGH 8
Microsoft Sharepoint Server 2019 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share…
2026-08-11
CVE-2026-58612
HIGH 7.4
Powershell 7.4 — Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose in…
2026-08-11
CVE-2026-58639
MEDIUM 6.5
Microsoft Sharepoint Enterprise Server 2016 — Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spo…
2026-08-11
CVE-2026-58641
HIGH 7.8
.Net 10.0 — Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-58650
HIGH 7.8
Visual Studio Code — Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypa…
2026-08-11
CVE-2026-58651
HIGH 7.8
Microsoft 365 Apps For Enterprise — Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-59113
HIGH 8.8
Visual Studio Code — Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
2026-08-11
CVE-2026-59119
HIGH 7.3
Powershell 7.4 — Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges loca…
2026-08-11
CVE-2026-59122
HIGH 7
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho…
2026-08-11
CVE-2026-59124
CRITICAL 9.8
Microsoft Hpc Pack 2019 — Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized at…
2026-08-11
CVE-2026-59125
HIGH 7
Windows 10 Version 1607 — Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges …
2026-08-11
CVE-2026-59126
HIGH 7
Windows 10 Version 21h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event L…
2026-08-11
CVE-2026-59127
HIGH 7.8
Windows 10 Version 1607 — Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locall…
2026-08-11
CVE-2026-59128
MEDIUM 5.5
Windows 10 Version 1607 — Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose informati…
2026-08-11
CVE-2026-59130
MEDIUM 5.6
Windows 10 Version 1607 — No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-59131
MEDIUM 5.6
Windows 10 Version 1607 — No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-59132
HIGH 7.5
Windows 10 Version 1607 — Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
2026-08-11
CVE-2026-59133
HIGH 8.8
Windows App Client For Windows Desktop — Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized …
2026-08-11
CVE-2026-59134
HIGH 7.5
Windows 10 Version 1607 — Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a net…
2026-08-11
CVE-2026-59135
MEDIUM 5.5
Windows 10 Version 1607 — Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose informatio…
2026-08-11
CVE-2026-59136
MEDIUM 5.5
Windows 10 Version 1607 — Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose informati…
2026-08-11
CVE-2026-59137
MEDIUM 5.5
Windows 10 Version 1607 — Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose infor…
2026-08-11
CVE-2026-59138
MEDIUM 6.5
Windows 10 Version 1607 — Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service ov…
2026-08-11
CVE-2026-61345
MEDIUM 6.5
Windows 10 Version 1607 — Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service ov…
2026-08-11
CVE-2026-61346
HIGH 7
Windows 10 Version 1809 — Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61347
MEDIUM 5.5
Windows 10 Version 1607 — Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locall…
2026-08-11
CVE-2026-61348
HIGH 7
Windows 10 Version 1607 — Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi…
2026-08-11
CVE-2026-61349
HIGH 7.8
Windows 10 Version 1607 — Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61350
MEDIUM 4.6
Windows 10 Version 1607 — Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attac…
2026-08-11
CVE-2026-61352
HIGH 7.5
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop …
2026-08-11
CVE-2026-61353
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges lo…
2026-08-11
CVE-2026-61355
HIGH 7.8
Windows 10 Version 21h2 — Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges …
2026-08-11
CVE-2026-61356
HIGH 7.8
Windows 10 Version 1809 — Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker …
2026-08-11
CVE-2026-61357
HIGH 7.8
Windows 11 Version 24h2 — Use after free in Application Information Services allows an authorized attacker to elevate privileges locally…
2026-08-11
CVE-2026-61358
HIGH 7.8
Windows 10 Version 1809 — Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBrok…
2026-08-11
CVE-2026-61359
HIGH 7.8
Windows 11 Version 23h2 — Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61360
MEDIUM 5.5
Windows 10 Version 1607 — Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-61361
HIGH 7
Windows 11 Version 24h2 — Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
2026-08-11
CVE-2026-61363
HIGH 7.5
Windows 10 Version 1607 — Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a net…
2026-08-11
CVE-2026-61364
HIGH 7.8
Windows 10 Version 1607 — Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker …
2026-08-11
CVE-2026-61365
HIGH 7.8
Windows 10 Version 1607 — Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker …
2026-08-11
CVE-2026-61366
HIGH 7
Windows 10 Version 1607 — Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61367
HIGH 7.8
Windows 10 Version 1607 — Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker …
2026-08-11
CVE-2026-61368
MEDIUM 5
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-61918
MEDIUM 6.5
Windows 10 Version 1607 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a net…
2026-08-11
CVE-2026-61920
MEDIUM 6.6
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS all…
2026-08-11
CVE-2026-61921
MEDIUM 6.5
Windows 10 Version 1607 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a net…
2026-08-11
CVE-2026-61923
HIGH 7.8
Windows 10 Version 1809 — Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate pri…
2026-08-11
CVE-2026-61924
MEDIUM 6.5
Windows 10 Version 1607 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a net…
2026-08-11
CVE-2026-61925
HIGH 7.8
Windows 10 Version 1607 — Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61926
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61927
HIGH 7
Windows 11 Version 24h2 — Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61928
MEDIUM 5.5
Windows 10 Version 1607 — Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering…
2026-08-11
CVE-2026-61929
HIGH 7
Windows 11 Version 23h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61930
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61932
HIGH 7.8
Windows 10 Version 1607 — Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized…
2026-08-11
CVE-2026-61933
MEDIUM 5.5
Windows 11 Version 24h2 — Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-61934
HIGH 7.8
Windows 11 Version 23h2 — Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61936
MEDIUM 5.5
Windows 10 Version 1809 — Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security …
2026-08-11
CVE-2026-61937
HIGH 7.8
Windows 10 Version 1607 — Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally…
2026-08-11
CVE-2026-61938
HIGH 7
Windows 11 Version 24h2 — Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-61939
HIGH 7
Windows 10 Version 1607 — Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62688
HIGH 7.8
Windows 11 Version 24h2 — Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges …
2026-08-11
CVE-2026-62690
HIGH 7
Windows 10 Version 1809 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push No…
2026-08-11
CVE-2026-62692
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privile…
2026-08-11
CVE-2026-62693
HIGH 7
Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Se…
2026-08-11
CVE-2026-62695
HIGH 7.8
Windows 11 Version 23h2 — Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62696
HIGH 7.8
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized…
2026-08-11
CVE-2026-62698
HIGH 7.8
Windows 10 Version 1607 — Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privilege…
2026-08-11
CVE-2026-62699
MEDIUM 6.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized a…
2026-08-11
CVE-2026-62700
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62701
HIGH 7.8
Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62702
MEDIUM 6.8
Windows 10 Version 21h2 — Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a net…
2026-08-11
CVE-2026-62703
MEDIUM 5.5
Windows 10 Version 1809 — Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62705
HIGH 7
Windows 11 Version 24h2 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Fi…
2026-08-11
CVE-2026-62707
HIGH 7.8
Windows 10 Version 1607 — Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges l…
2026-08-11
CVE-2026-62708
MEDIUM 6.4
Windows 11 Version 24h2 — Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
2026-08-11
CVE-2026-62709
MEDIUM 5.5
Windows 10 Version 1607 — Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62710
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate priv…
2026-08-11
CVE-2026-62711
HIGH 7.8
Windows 10 Version 1607 — Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62712
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62713
HIGH 7.8
Windows 10 Version 1809 — Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate …
2026-08-11
CVE-2026-62714
MEDIUM 6.5
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info…
2026-08-11
CVE-2026-62715
MEDIUM 6.5
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info…
2026-08-11
CVE-2026-62716
MEDIUM 6.5
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info…
2026-08-11
CVE-2026-62717
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges loca…
2026-08-11
CVE-2026-62718
MEDIUM 6.5
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info…
2026-08-11
CVE-2026-62719
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges loca…
2026-08-11
CVE-2026-62720
MEDIUM 6.5
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info…
2026-08-11
CVE-2026-62721
HIGH 7.8
Windows 10 Version 1607 — Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to …
2026-08-11
CVE-2026-62722
HIGH 7.8
Windows 11 Version 24h2 — Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privilege…
2026-08-11
CVE-2026-62723
HIGH 7
Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62724
HIGH 7
Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62725
HIGH 7
Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62726
HIGH 7
Windows 10 Version 1607 — Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62728
HIGH 7
Windows 10 Version 1607 — Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorize…
2026-08-11
CVE-2026-62729
HIGH 7
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho…
2026-08-11
CVE-2026-62730
MEDIUM 5.5
Windows 10 Version 1607 — Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information loc…
2026-08-11
CVE-2026-62732
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges lo…
2026-08-11
CVE-2026-62733
HIGH 7.8
Windows 10 Version 1607 — Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62734
HIGH 7
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho…
2026-08-11
CVE-2026-62735
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62736
HIGH 7.8
Windows 11 Version 23h2 — Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62737
HIGH 7.8
Windows 11 Version 24h2 — Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62738
MEDIUM 5.5
Windows 10 Version 1607 — Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information…
2026-08-11
CVE-2026-62739
HIGH 7.8
Windows 10 Version 1809 — Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62740
MEDIUM 5.5
Windows 10 Version 1607 — Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose informati…
2026-08-11
CVE-2026-62741
HIGH 7.8
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges…
2026-08-11
CVE-2026-62742
MEDIUM 6.5
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info…
2026-08-11
CVE-2026-62743
MEDIUM 5.5
Windows 10 Version 1607 — Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62745
MEDIUM 6.5
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info…
2026-08-11
CVE-2026-62746
MEDIUM 5.5
Windows 10 Version 1607 — Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62747
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate priv…
2026-08-11
CVE-2026-62748
HIGH 7
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telepho…
2026-08-11
CVE-2026-62749
HIGH 7
Windows 11 Version 24h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62750
MEDIUM 6.5
Windows 10 Version 1607 — Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering …
2026-08-11
CVE-2026-62751
HIGH 7.8
Windows 10 Version 21h2 — Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privi…
2026-08-11
CVE-2026-62752
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62753
HIGH 7
Windows 10 Version 1607 — Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62754
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62755
HIGH 7.8
Windows 10 Version 1607 — Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally…
2026-08-11
CVE-2026-62757
MEDIUM 5.3
Windows 10 Version 1607 — Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass…
2026-08-11
CVE-2026-62758
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevat…
2026-08-11
CVE-2026-62761
HIGH 7.8
Windows 10 Version 1607 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att…
2026-08-11
CVE-2026-62766
HIGH 7
Windows 11 Version 24h2 — Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62768
HIGH 7.8
Windows 10 Version 1607 — Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62769
MEDIUM 6.7
Windows 10 Version 1607 — Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62770
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62771
HIGH 7.8
Windows 10 Version 1809 — Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate …
2026-08-11
CVE-2026-62772
HIGH 7.8
Windows 11 Version 26h1 — Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized …
2026-08-11
CVE-2026-62773
HIGH 7
Windows 10 Version 1607 — Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62774
HIGH 7
Windows 10 Version 1607 — Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62775
MEDIUM 5.5
Windows 11 Version 26h1 — Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att…
2026-08-11
CVE-2026-62776
HIGH 7.8
Windows 10 Version 1607 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att…
2026-08-11
CVE-2026-62777
HIGH 7.8
Windows 10 Version 1607 — Missing authentication for critical function in Windows License Manager allows an authorized attacker to eleva…
2026-08-11
CVE-2026-62778
HIGH 8.1
Windows 10 Version 1607 — Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-08-11
CVE-2026-62779
HIGH 7.8
Windows 11 Version 24h2 — Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62780
HIGH 7
Windows 11 Version 23h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62781
HIGH 8.1
Windows 10 Version 1607 — Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
2026-08-11
CVE-2026-62782
MEDIUM 6.5
Windows 10 Version 1607 — Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a networ…
2026-08-11
CVE-2026-62783
HIGH 7.8
Windows 10 Version 1809 — Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevat…
2026-08-11
CVE-2026-62784
HIGH 8.8
Windows 10 Version 1607 — Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker…
2026-08-11
CVE-2026-62785
HIGH 8.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized atta…
2026-08-11
CVE-2026-62786
MEDIUM 5.5
Windows 10 Version 1607 — Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62787
HIGH 7.5
Windows 10 Version 1607 — Use after free in Windows DNS allows an authorized attacker to execute code over a network.
2026-08-11
CVE-2026-62788
HIGH 7
Windows 11 Version 23h2 — Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62790
HIGH 8.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
2026-08-11
CVE-2026-62792
HIGH 8.1
Windows 10 Version 1607 — Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
2026-08-11
CVE-2026-62793
MEDIUM 5.5
Windows 10 Version 1607 — Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62795
HIGH 8.8
Windows 10 Version 1607 — Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to exec…
2026-08-11
CVE-2026-62796
MEDIUM 5.5
Windows 10 Version 1607 — Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62797
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62798
MEDIUM 5.5
Windows 11 Version 23h2 — Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62799
HIGH 7.8
Windows 11 Version 26h1 — Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62800
HIGH 8.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
2026-08-11
CVE-2026-62803
HIGH 7.8
Windows 10 Version 1607 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att…
2026-08-11
CVE-2026-62807
HIGH 7.8
Windows 10 Version 1607 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att…
2026-08-11
CVE-2026-62811
HIGH 7.8
Windows 11 Version 23h2 — Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62812
HIGH 7.8
Windows 10 Version 1607 — Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized att…
2026-08-11
CVE-2026-62814
MEDIUM 6.5
Windows 10 Version 1607 — Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose info…
2026-08-11
CVE-2026-62815
CRITICAL 9.8
Windows 11 Version 23h2 — Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
2026-08-11
CVE-2026-62816
HIGH 8.8
Windows 10 Version 1607 — Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to …
2026-08-11
CVE-2026-62817
HIGH 8.8
Windows 10 Version 1809 — Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
2026-08-11
CVE-2026-62818
HIGH 8.8
Windows 10 Version 1607 — Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code …
2026-08-11
CVE-2026-62819
HIGH 8.1
Windows 10 Version 1607 — Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthori…
2026-08-11
CVE-2026-62820
HIGH 8.1
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS all…
2026-08-11
CVE-2026-62822
HIGH 8.8
Windows 10 Version 1607 — Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
2026-08-11
CVE-2026-62823
HIGH 8.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adja…
2026-08-11
CVE-2026-62824
HIGH 8.8
Windows 10 Version 1607 — Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a ne…
2026-08-11
CVE-2026-62827
HIGH 8.8
Microsoft Sharepoint Enterprise Server 2016 — Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove…
2026-08-11
CVE-2026-62829
MEDIUM 4.6
Microsoft Sharepoint Server 2019 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share…
2026-08-11
CVE-2026-62832
HIGH 7.8
Windows 10 Version 21h2 — Improper link resolution before file access ('link following') in Windows User Profile Service allows an autho…
2026-08-11
CVE-2026-62837
MEDIUM 6.5
Microsoft Sharepoint Enterprise Server 2016 — Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information o…
2026-08-11
CVE-2026-62839
MEDIUM 6.5
Microsoft Sharepoint Enterprise Server 2016 — Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform s…
2026-08-11
CVE-2026-62842
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-62869
HIGH 8.8
Microsoft Entra — Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoo…
2026-08-11
CVE-2026-62871
HIGH 7.8
.Net 8.0 — Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-62872
HIGH 8.8
Microsoft .Net Framework 3.5 — Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
2026-08-11
CVE-2026-62876
HIGH 7.8
Windows 10 Version 1607 — Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62877
HIGH 7.8
Windows 10 Version 1607 — Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62878
CRITICAL 9.8
Windows 10 Version 1607 — Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
2026-08-11
CVE-2026-62880
HIGH 7.8
Windows 10 Version 1607 — Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62881
MEDIUM 6.7
Windows 10 Version 1607 — Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62882
MEDIUM 4.3
Microsoft 365 Apps For Enterprise — Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform sp…
2026-08-11
CVE-2026-62883
MEDIUM 6.7
Windows 10 Version 1607 — Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62885
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62886
HIGH 7.8
.Net 10.0 — Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62887
MEDIUM 5.5
Windows 10 Version 1607 — Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
2026-08-11
CVE-2026-62888
HIGH 7.8
Windows 10 Version 21h2 — Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62889
HIGH 8.1
Windows 10 Version 1607 — Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code…
2026-08-11
CVE-2026-62890
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
2026-08-11
CVE-2026-62892
HIGH 7
Windows 10 Version 1809 — Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privi…
2026-08-11
CVE-2026-62893
CRITICAL 9.8
Windows 10 Version 1607 — Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
2026-08-11
CVE-2026-62894
HIGH 7.8
Windows 10 Version 1607 — Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges loc…
2026-08-11
CVE-2026-62897
HIGH 7
.Net 10.0 — Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-62898
HIGH 7.5
.Net 10.0 — Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
2026-08-11
CVE-2026-62899
MEDIUM 5.9
.Net 10.0 — Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorize…
2026-08-11
CVE-2026-62900
MEDIUM 5.9
.Net 10.0 — Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker t…
2026-08-11
CVE-2026-62901
HIGH 7.5
.Net 10.0 — Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
2026-08-11
CVE-2026-62902
MEDIUM 6.5
.Net 8.0 — Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose i…
2026-08-11
CVE-2026-62908
HIGH 7
Windows 10 Version 1607 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup …
2026-08-11
CVE-2026-62909
HIGH 7.8
.Net 10.0 — Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
2026-08-11
CVE-2026-62910
HIGH 7.2
Microsoft Exchange Server 2016 Cumulative Update 23 — Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authori…
2026-08-11
CVE-2026-62911
HIGH 8
Microsoft Exchange Server 2016 Cumulative Update 23 — Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate …
2026-08-11
CVE-2026-62912
MEDIUM 6.5
Microsoft Exchange Server 2016 Cumulative Update 23 — Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service o…
2026-08-11
CVE-2026-62913
HIGH 8.8
Microsoft Exchange Server 2016 Cumulative Update 23 — Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a n…
2026-08-11
CVE-2026-62914
HIGH 7.3
Microsoft Exchange Server 2016 Cumulative Update 23 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Ser…
2026-08-11
CVE-2026-62915
MEDIUM 6.5
Microsoft Exchange Server 2016 Cumulative Update 23 — Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature …
2026-08-11
CVE-2026-62917
MEDIUM 4.6
Microsoft Sharepoint Enterprise Server 2016 — Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ove…
2026-08-11
CVE-2026-63512
MEDIUM 6.5
Microsoft Sharepoint Enterprise Server 2016 — Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over…
2026-08-11
CVE-2026-63513
HIGH 7.8
Microsoft 365 Apps For Enterprise — Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-63514
HIGH 8.8
Microsoft Sharepoint Enterprise Server 2016 — Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code…
2026-08-11
CVE-2026-63515
HIGH 7.8
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-63516
MEDIUM 6.5
Microsoft Sharepoint Enterprise Server 2016 — Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoo…
2026-08-11
CVE-2026-63517
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-63518
HIGH 7.8
Microsoft 365 Apps For Enterprise — Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-63519
HIGH 7.8
Microsoft 365 Apps For Enterprise — Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-63520
HIGH 8.1
Microsoft Sharepoint Enterprise Server 2016 — Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over …
2026-08-11
CVE-2026-63521
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-63522
HIGH 7.8
Azure Sql Database — Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to e…
2026-08-11
CVE-2026-63524
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-63525
HIGH 7.8
Microsoft 365 Apps For Enterprise — Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-63526
HIGH 7.8
Microsoft 365 Apps For Enterprise — Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-63527
HIGH 7.8
Microsoft 365 Apps For Enterprise — Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-63528
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-63529
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-63530
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-63531
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-63532
HIGH 7.8
Microsoft 365 Apps For Enterprise — Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-63533
HIGH 7.8
Microsoft 365 Apps For Enterprise — Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-64897
MEDIUM 4.6
Microsoft Sharepoint Enterprise Server 2016 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share…
2026-08-11
CVE-2026-64898
HIGH 7.8
Microsoft 365 Apps For Enterprise — Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-08-11
CVE-2026-64899
MEDIUM 5.5
Microsoft 365 Apps For Enterprise — Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
2026-08-11
CVE-2026-64900
HIGH 7.3
Microsoft Sharepoint Enterprise Server 2016 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share…
2026-08-11
CVE-2026-64901
HIGH 8.8
Microsoft Sharepoint Enterprise Server 2016 — Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code…
2026-08-11
CVE-2026-64902
MEDIUM 4.6
Microsoft Sharepoint Enterprise Server 2016 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share…
2026-08-11
CVE-2026-64903
HIGH 7.8
Microsoft 365 Apps For Enterprise — Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
2026-08-11