CVE Vulnerability Database

Search and browse 375,889 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-68794HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68793HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68792HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an author...
CVE-2026-66810MEDIUM5.5Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-66809MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-66808HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-66807HIGH7.8Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-66806MEDIUM5.5Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-66805HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-66804HIGH7.8Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
CVE-2026-66802HIGH8.1Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestati...
CVE-2026-66799HIGH7.8Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
CVE-2026-66301MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized ...
CVE-2026-65815HIGH8.8Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code ...
CVE-2026-65814HIGH7.8Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-65813MEDIUM6.5Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over...
CVE-2026-65811HIGH8.8Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-65810HIGH7.8Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-65807HIGH8.8Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ...
CVE-2026-65806MEDIUM6.5Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
CVE-2026-65799MEDIUM6.7Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65798MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65797MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65796MEDIUM5.9Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a networ...
CVE-2026-65795MEDIUM6.7No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally.