Vulnerabilities (CVE)

Total 398723 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-58481 1 Network-ai 1 Network-ai 2026-08-13 N/A 6.5 MEDIUM
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox base such as `/tmp/network-ai-sandbox` also matches a sibling path such as `/tmp/network-ai-sandbox_evil/secret.txt`. An agent/user that can call `AgentRuntime.readFile()` or `AgentRuntime.listDir()` can read or list files outside the intended sandbox when the target path is in a sibling directory sharing the base path prefix. This breaks the documented sandbox boundary. The issue is fixed in v5.12.2. `SandboxPolicy.resolvePath()` and `isPathAllowed()` now use separator-anchored prefix checks (`resolved === base || resolved.startsWith(base + path.sep)`) for both the allow-list and block-list. A sibling directory that merely shares a name prefix (e.g. `/srv/app-evil` vs base `/srv/app`) is no longer treated as in-scope.
CVE-2026-70328 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 6.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70327 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 6.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-68817 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68816 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68815 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68814 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68812 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68811 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68810 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68808 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-68807 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68806 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68805 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68804 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68803 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68802 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-68801 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68800 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68799 1 Microsoft 6 365 Apps, Excel, Microsoft 365 and 3 more 2026-08-13 N/A 5.5 MEDIUM
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.