CVE Vulnerability Database

Search and browse 375,889 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65678HIGH7Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65675HIGH7.1No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security ...
CVE-2026-65673HIGH7.8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync all...
CVE-2026-65672HIGH7.8Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-65671HIGH7.8Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-65665HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-65664HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65663HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-65662MEDIUM5.5Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-65661HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65660MEDIUM6.5Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t...
CVE-2026-65658HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-65657HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65656HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauth...
CVE-2026-64922MEDIUM4.6Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-64921HIGH8.8Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate pri...
CVE-2026-64920HIGH7.8Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64919HIGH7.8Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64917MEDIUM5.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-64916MEDIUM4.6Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-64915HIGH7.8Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64914HIGH7.8Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64912HIGH7.8Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64911HIGH7.8Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64910HIGH7.8Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.