CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81948
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81947
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81824
4.7 MEDIUM

The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered …

Sep 8, 2026
CVE-2026-81823
5.3 MEDIUM

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are …

Sep 8, 2026
CVE-2026-81822
8.4 HIGH

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing …

Sep 8, 2026
CVE-2026-81821
8.4 HIGH

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.

Sep 8, 2026
CVE-2026-81401
5.5 MEDIUM

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81400
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81399
5.5 MEDIUM

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81398
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81397
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81396
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81395
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81394
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81393
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81392
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81391
5.5 MEDIUM

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81390
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81389
7.0 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81388
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81387
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81386
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81385
8.8 HIGH

Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-81383
7.4 HIGH

Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-81381
6.5 MEDIUM

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-81380
5.3 MEDIUM

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information …

Sep 8, 2026
CVE-2026-81379
8.2 HIGH

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-81378
8.2 HIGH

Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-81377
6.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

Sep 8, 2026
CVE-2026-81376
9.6 CRITICAL

Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-81357
8.2 HIGH

Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-81356
8.2 HIGH

Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026
CVE-2026-81355
7.5 HIGH

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81354
8.2 HIGH

Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-81353
7.8 HIGH

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-81352
8.8 HIGH

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-81349
7.2 HIGH

Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a …

Sep 8, 2026
CVE-2026-80097
8.6 HIGH

Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-80096
8.8 HIGH

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

Sep 8, 2026
CVE-2026-80093
7.0 HIGH

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-80091
6.5 MEDIUM

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80090
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80089
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80088
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80087
6.5 MEDIUM

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80086
6.5 MEDIUM

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80085
8.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-80084
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80083
8.8 HIGH

Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-80082
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.