Vulnerabilities (CVE)

Total 398710 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-64914 1 Microsoft 5 365 Apps, Access, Office 2019 and 2 more 2026-08-14 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64919 1 Microsoft 5 365 Apps, Access, Office 2019 and 2 more 2026-08-14 N/A 7.8 HIGH
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64907 1 Microsoft 6 365 Apps, Microsoft 365, Office 2019 and 3 more 2026-08-14 N/A 7.8 HIGH
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64912 1 Microsoft 5 365 Apps, Access, Office 2019 and 2 more 2026-08-14 N/A 7.8 HIGH
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64904 1 Microsoft 5 365 Apps, Microsoft 365, Office 2019 and 2 more 2026-08-14 N/A 7.8 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63533 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-08-14 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63526 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-08-14 N/A 7.8 HIGH
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63530 1 Microsoft 6 365 Apps, Microsoft 365, Office 2019 and 3 more 2026-08-14 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-63093 2 Anysphere, Microsoft 2 Cursor, Windows 2026-08-14 N/A 8.8 HIGH
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.
CVE-2026-64899 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-08-14 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-60121 1 Vitec 1 Flamingo 2026-08-14 N/A 9.8 CRITICAL
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without escaping, allowing injected commands to execute with root privileges via passwordless sudo.
CVE-2026-61498 1 Vitec 1 Flamingo 2026-08-14 N/A 9.8 CRITICAL
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.
CVE-2026-63528 1 Microsoft 6 365 Apps, Microsoft 365, Office 2019 and 3 more 2026-08-14 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-62872 1 Microsoft 14 .net Framework, Windows 10 1607, Windows 10 1809 and 11 more 2026-08-14 N/A 8.8 HIGH
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
CVE-2026-62897 1 Microsoft 7 .net, .net Framework, Visual Studio 2022 and 4 more 2026-08-14 N/A 7.0 HIGH
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62899 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 5.9 MEDIUM
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62900 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 5.9 MEDIUM
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62901 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 7.5 HIGH
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62902 1 Microsoft 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more 2026-08-14 N/A 6.5 MEDIUM
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-64917 1 Microsoft 6 365 Apps, Microsoft 365, Office 2019 and 3 more 2026-08-14 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.