Export limit exceeded: 390764 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (390764 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-69442 1 Microsoft 5 365 Apps, Office 2016, Office 2019 and 2 more 2026-09-09 8.8 High
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-85124 1 Fastify 2 Fastify-http-proxy, Fastify\/http-proxy 2026-09-09 7.5 High
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options. An unauthenticated network attacker can use this to reach upstream paths that were meant to stay hidden behind the proxy, resulting in disclosure of internal endpoints. This is a path traversal issue (CWE-22). Users should upgrade to @fastify/http-proxy 11.6.2 or later.
CVE-2026-69626 1 Microsoft 9 365 Apps, Microsoft 365, Office 2016 and 6 more 2026-09-09 6.5 Medium
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
CVE-2026-69629 1 Microsoft 6 365 Apps, Office 2019, Office 2021 and 3 more 2026-09-09 8.8 High
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-69632 1 Microsoft 8 365 Apps, Microsoft 365, Office 2019 and 5 more 2026-09-09 8.8 High
Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-69739 1 Microsoft 5 365 Apps, Office 2016, Office 2019 and 2 more 2026-09-09 6.5 Medium
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
CVE-2026-87566 1 Google 1 Chrome 2026-09-09 5.3 Medium
Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-85788 1 Aws 1 Aws Labs Mysql Mcp Server 2026-09-09 5.5 Medium
Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To remediate this issue, users should upgrade to version 1.0.23.
CVE-2026-77908 1 Microsoft 1 Dynamics 365 2026-09-09 8.8 High
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVE-2026-70351 1 Microsoft 1 Webp Image Extension 2026-09-09 8.8 High
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-69858 1 Microsoft 3 Windows Server 2022, Windows Server 2025, Windows Server 2025 (server Core Installation) 2026-09-09 8.1 High
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-69690 1 Microsoft 2 Sharepoint Server, Sharepoint Server Subscription Edition 2026-09-09 4.6 Medium
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69310 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-09-09 7 High
Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-58611 1 Microsoft 1 Xbox Gaming Services 2026-09-09 7.8 High
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
CVE-2026-58600 1 Microsoft 3 Hevc Video Extensions, Hevc Video Extensions For Licensed Appplications, Hevc Video Extensions From Device Manufacturer 2026-09-09 7.8 High
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
CVE-2026-56198 1 Microsoft 8 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 5 more 2026-09-09 7.8 High
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
CVE-2026-47297 1 Microsoft 3 Sql Server 2019, Sql Server 2022, Sql Server 2025 2026-09-09 8.1 High
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-87498 1 Google 1 Chrome 2026-09-09 3.1 Low
Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CVE-2026-87467 2 Google, Microsoft 2 Chrome, Windows 2026-09-09 8.1 High
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CVE-2026-87514 1 Google 1 Chrome 2026-09-09 8.1 High
Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)