CVE Vulnerability Database

Search and browse 396,244 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45490HIGH7.8Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-45487HIGH7Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attack...
CVE-2026-45486HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45485LOW3.3Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45484HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove...
CVE-2026-45483MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server ...
CVE-2026-45482HIGH8.4Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code ...
CVE-2026-45481MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45479MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45476HIGH8.2Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-45475HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45474HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45472HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45471HIGH7.8Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45469HIGH7.8Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally...
CVE-2026-45468MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45467MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45466LOW3.3Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-45465MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45464MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45463HIGH8.4Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45462MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45461HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45460MEDIUM4.7Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45459LOW3.3Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature loca...