VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-62733High· 7.8
1mo ago

Windows Win32k Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62728High· 7.0
1mo ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-62720Medium· 6.5
1mo ago

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ SunlitMicrosoft · Windows Server 2012EPSS 0.54%via CVEORG
CVE-2026-62814Medium· 6.5
1mo ago

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ SunlitMicrosoft · Windows Server 2012EPSS 0.54%via CVEORG
CVE-2026-62786Medium· 5.5
1mo ago

Win32k Information Disclosure Vulnerability

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-62782Medium· 6.5
1mo ago

Windows SMB Client Information Disclosure Vulnerability

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-62743Medium· 5.5
1mo ago

Win32k Information Disclosure Vulnerability

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-63531Medium· 5.5
1mo ago

Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-63530Medium· 5.5
1mo ago

Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-63529Medium· 5.5
1mo ago

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-63528Medium· 5.5
1mo ago

Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-63524Medium· 5.5
1mo ago

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-62887Medium· 5.5
1mo ago

Windows NTFS Information Disclosure Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-62880High· 7.8
1mo ago

Windows NTFS Elevation of Privilege Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62842Medium· 5.5
1mo ago

Microsoft Office Graphics Component Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-64917Medium· 5.5
1mo ago

Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-64909High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-64899Medium· 5.5
1mo ago

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-68797Medium· 5.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-66809Medium· 5.5
1mo ago

Microsoft Office Graphics Component Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.43%via CVEORG
CVE-2026-66806Medium· 5.5
1mo ago

Microsoft Office Word Information Disclosure Vulnerability

Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.43%via CVEORG
CVE-2026-68814High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-62738Medium· 5.5
1mo ago

Windows Management Instrumentation Information Disclosure Vulnerability

Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-18694High· 7.1
1mo ago

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation

An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries agai…

▾ Twilightmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18688High· 7.1
1mo ago

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in …

▾ Twilightmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-17535Medium· 6.2
1mo ago

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting th…

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting th…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-62718Medium· 6.5
1mo ago

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-62716Medium· 6.5
1mo ago

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-62715Medium· 6.5
1mo ago

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-62714Medium· 6.5
1mo ago

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CWE-125 vulnerabilities (CVEs) — page 18 · VulnSea