CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55140
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55137
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55136
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55134
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55133
7.8 HIGH

Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55132
7.8 HIGH

Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55131
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55130
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55129
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55128
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55127
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55126
7.3 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-55125
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55123
7.8 HIGH

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55122
7.1 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-55120
7.8 HIGH

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55058
7.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55056
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55055
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55053
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55052
8.8 HIGH

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-55049
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55048
7.8 HIGH

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55045
8.4 HIGH

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55044
7.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55043
7.8 HIGH

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55041
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55039
7.8 HIGH

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55038
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55037
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55036
7.8 HIGH

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55034
7.3 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-55033
7.8 HIGH

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55032
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55031
7.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55029
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55025
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55024
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55022
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55021
7.3 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-55018
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-55017
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-54131
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-54128
8.4 HIGH

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-54125
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-54124
7.8 HIGH

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

Jul 14, 2026
CVE-2026-54121
8.8 HIGH

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-54115
7.8 HIGH

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-50692
8.8 HIGH

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-50689
7.8 HIGH

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.