VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-78518High· 8.8
2w ago

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.86%via NVD
CVE-2026-73021High· 7.8
2w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-72996High· 7.8
2w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-72994High· 7.8
2w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-72977Medium· 6.5
2w ago

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · 365_appsEPSS 0.97%via NVD
CVE-2026-70581High· 7.8
2w ago

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-70573High· 7.0
2w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.28%via NVD
CVE-2026-69845Critical· 9.8
2w ago

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 1.0%via NVD
CVE-2026-69614High· 8.8
2w ago

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.

Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.86%via NVD
CVE-2026-69352High· 7.8
2w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-69295High· 7.8
2w ago

Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-69293High· 7.8
2w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-69286Medium· 5.5
2w ago

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.40%via NVD
CVE-2026-69270High· 7.8
2w ago

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-68839Critical· 9.8
2w ago

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 1.0%via NVD
CVE-2026-84282Medium· 6.5
2w ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server UR…

▾ SunlitAscensio System SIA / OnlyOffice · ONLYOFFICE ownCloud integration pluginEPSS 0.27%via NVD
CVE-2026-79376High· 8.8
2w ago

An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.

An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.

▾ TwilightEPSS 0.35%via NVD
CVE-2026-62647High· 7.4
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized wi…

▾ TwilightSiemens · Reyrolle 7SR5EPSS 0.56%via NVD
CVE-2022-51013Medium· 6.5
2w ago

PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients

PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-range damage values in itemstack NBT to trigger unhandled exceptions…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.51%via NVD
CVE-2022-51011Medium· 4.3
2w ago

PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large messages containing many newlines

PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large messages containing many newlines. Malicious clients can send meg…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.43%via NVD
CVE-2026-86440Medium· 5.4
2w ago

Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user

Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL safe if it appeared…

▾ Sunlitmisp-project · mispEPSS 0.24%via NVD
CVE-2026-86351Medium· 6.1
2w ago

Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /

Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolv…

▾ Sunlitmisp-project · mispEPSS 0.26%via NVD
CVE-2025-52651Low· 3.5
2w ago

HCL MyXalytics was affected by Improper Input validation Vulnerability

HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.

▾ SunlitHCL Software · MyXalyticsEPSS 0.15%via NVD
CVE-2022-51017High· 7.5
2w ago

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like…

▾ Twilightpmmp · PocketMine-MPEPSS 0.47%via NVD
CVE-2022-51015Medium· 6.5
2w ago

PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within InventoryTransactionPacket)

PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within InventoryTransactionPacket). A remote authenticated attacker can se…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.68%via NVD
CVE-2022-51012Medium· 6.5
2w ago

PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients

PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger serve…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.51%via NVD
CVE-2022-51010Medium· 6.5
2w ago

PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data

PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid range to trigger an uncaught exception that crashes the server.

▾ Sunlitpmmp · PocketMine-MPEPSS 0.51%via NVD
CVE-2021-48007Medium· 6.5
3w ago

PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields

PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unh…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.29%via NVD
CVE-2026-85528Medium· 5.3
3w ago

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker …

▾ SunlitSnowflake · net.snowflake:snowflake-jdbcEPSS 0.29%via NVD
CVE-2026-84947Low· 3.7⚖ disputed
3w ago

undici's dump interceptor reads and discards a response body up to a configurable maximum size

undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length…

▾ Sunlitnodejs · undiciEPSS 0.33%via NVD
CWE-20 vulnerabilities (CVEs) — page 7 · VulnSea