Vulnerabilities (CVE)

Total 398697 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-65777 1 Microsoft 6 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 3 more 2026-08-14 N/A 5.3 MEDIUM
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.
CVE-2026-65672 1 Microsoft 6 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 3 more 2026-08-14 N/A 7.8 HIGH
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-63521 1 Microsoft 5 365 Apps, Office 2019, Office 2021 and 2 more 2026-08-14 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-70323 1 Microsoft 5 365 Apps, Microsoft 365, Office 2019 and 2 more 2026-08-14 N/A 5.5 MEDIUM
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-73107 2026-08-14 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-68792 1 Microsoft 4 365 Apps, Office 2019, Office 2021 and 1 more 2026-08-14 N/A 7.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-62241 1 Mohibshaikh 1 Clawvet 2026-08-14 N/A 9.1 CRITICAL
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest a victim's userId, forge a valid HS256 cg_session cookie offline using the known secret, and call GET /api/v1/auth/me to obtain the victim's email address, subscription plan, and secret apiKey. The published clawvet npm package (CLI only) is not affected.
CVE-2026-58643 1 Microsoft 1 Windows Admin Center 2026-08-14 N/A 6.1 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-48566 1 Microsoft 4 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 1 more 2026-08-14 N/A 5.5 MEDIUM
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-32202 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-08-14 N/A 4.3 MEDIUM
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32153 1 Microsoft 7 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 4 more 2026-08-14 N/A 7.8 HIGH
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
CVE-2023-7347 2026-08-14 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-64910 1 Microsoft 5 365 Apps, Microsoft 365, Office 2019 and 2 more 2026-08-14 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-70338 1 Microsoft 1 Powershell 2026-08-14 N/A 7.8 HIGH
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-70130 1 Microsoft 4 365 Apps, Office 2019, Office 2021 and 1 more 2026-08-14 N/A 8.4 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-66807 1 Microsoft 5 365 Apps, Microsoft 365, Office 2019 and 2 more 2026-08-14 N/A 7.8 HIGH
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63515 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-08-14 N/A 7.8 HIGH
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-62913 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-08-14 N/A 8.8 HIGH
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-46600 2026-08-14 N/A 7.5 HIGH
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
CVE-2026-44962 2026-08-14 N/A 9.9 CRITICAL
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.