CVE Vulnerability Database

Search and browse 375,862 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-70323MEDIUM5.5Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70322MEDIUM5.5Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally...
CVE-2026-70321HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-70320MEDIUM5.5Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally...
CVE-2026-70319MEDIUM5.5Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-70318MEDIUM5.5Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-70317MEDIUM5.5Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70316MEDIUM5.5Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally...
CVE-2026-70315MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70314MEDIUM5.5Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70313HIGH7.8Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally...
CVE-2026-70312MEDIUM5.5Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally...
CVE-2026-70311HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-70310MEDIUM5.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-70307HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-70306CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-70304MEDIUM6.7Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-70130HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-69320HIGH8.8Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows ...
CVE-2026-69306HIGH8.2Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature...
CVE-2026-69278HIGH7.8Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-69223CRITICAL9.1Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before...
CVE-2026-68821HIGH7.3Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-68820HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-68819MEDIUM5.9Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.