Tagged “nvd”
CVEs tagged nvd, newest first.
30213 CVEsRSS
CVE-2026-78516Medium· 4.3Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.
Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.
CVE-2026-78515Medium· 6.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-78514High· 8.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78513Medium· 5.5Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-78512High· 8.8Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78511High· 8.8Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78510High· 8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-78509Critical· 9.8Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-78508Medium· 4.6Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-78507High· 8.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78506Medium· 5.5Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-78505High· 8.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-78504High· 8.8Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78503Medium· 6.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-78502Medium· 6.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-78464High· 7.0Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-78463High· 8.8Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-78462High· 8.8Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-78461High· 7.4Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-78457High· 7.0Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.
CVE-2026-78456High· 8.8Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-78455Medium· 4.3Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-78454Medium· 5.5Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
CVE-2026-78453Medium· 6.5Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
CVE-2026-78452Medium· 4.6Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-78451Medium· 6.8Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-78450High· 8.1Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-78449High· 8.1Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-78448High· 7.8Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-78447High· 7.8Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.