Export limit exceeded: 27557 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (27557 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69904 | 1 Microsoft | 1 Sharepoint Server | 2026-09-08 | 3.5 Low |
| Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-69562 | 1 Microsoft | 2 Sql Server 2017, Sql Server 2019 | 2026-09-08 | 6.5 Medium |
| Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-69559 | 1 Microsoft | 1 Teams | 2026-09-08 | 5.8 Medium |
| Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-69522 | 1 Microsoft | 4 .net, .net Framework, Visual Studio 2022 and 1 more | 2026-09-08 | 8.8 High |
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69325 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-08 | 8.1 High |
| Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69292 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 5 more | 2026-09-08 | 7 High |
| Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69282 | 1 Microsoft | 1 Sharepoint Server | 2026-09-08 | 8.8 High |
| Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69276 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-08 | 9.8 Critical |
| Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69271 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-08 | 8 High |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-68890 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-08 | 7.8 High |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-67379 | 1 Microsoft | 3 Sql Server 2019, Sql Server 2022, Sql Server 2025 | 2026-09-08 | 8.5 High |
| Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-65812 | 1 Microsoft | 1 Teams | 2026-09-08 | 6.8 Medium |
| Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-27222 | 3 Adobe, Apple, Microsoft | 3 Bridge, Macos, Windows | 2026-09-08 | 5.4 Medium |
| Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | ||||
| CVE-2026-81963 | 1 Microsoft | 10 Windows 11 23h2, Windows 11 23h2, Windows 11 24h2 and 7 more | 2026-09-08 | 7.8 High |
| Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-62804 | 1 Microsoft | 15 365 Apps, Microsoft 365, Microsoft 365 Apps For Enterprise and 12 more | 2026-09-08 | 7.8 High |
| External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-69855 | 1 Microsoft | 2 Azure Copilot, Microsoft Copilot In Azure | 2026-09-08 | 7.7 High |
| Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-70178 | 1 Microsoft | 2 Fabric, Microsoft Fabric | 2026-09-08 | 8.5 High |
| Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-80098 | 1 Microsoft | 1 Copilot Studio | 2026-09-08 | 9.3 Critical |
| Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-65818 | 1 Microsoft | 1 Power Platform | 2026-09-08 | 8.5 High |
| Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62886 | 1 Microsoft | 7 .net, .net Framework, Microsoft Visual Studio 2022 and 4 more | 2026-09-08 | 7.8 High |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | ||||