VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30213 CVEsRSS

CVE-2026-78516Medium· 4.3
3w ago

Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.

Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.52%via NVD
CVE-2026-78515Medium· 6.5
3w ago

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · 365_appsEPSS 0.92%via NVD
CVE-2026-78514High· 8.8
3w ago

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-78513Medium· 5.5
3w ago

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

▾ Sunlitmicrosoft · 365_appsEPSS 0.54%via NVD
CVE-2026-78512High· 8.8
3w ago

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-78511High· 8.8
3w ago

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-78510High· 8.4
3w ago

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ Twilightmicrosoft · 365_appsEPSS 0.34%via NVD
CVE-2026-78509Critical· 9.8
3w ago

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · 365_appsEPSS 0.97%via NVD
CVE-2026-78508Medium· 4.6
3w ago

Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.47%via NVD
CVE-2026-78507High· 8.8
3w ago

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-78506Medium· 5.5
3w ago

Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ Sunlitmicrosoft · 365_appsEPSS 0.54%via NVD
CVE-2026-78505High· 8.8
3w ago

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-78504High· 8.8
3w ago

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-78503Medium· 6.5
3w ago

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · 365_appsEPSS 0.92%via NVD
CVE-2026-78502Medium· 6.5
3w ago

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · 365_appsEPSS 0.92%via NVD
CVE-2026-78464High· 7.0
3w ago

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.20%via NVD
CVE-2026-78463High· 8.8
3w ago

Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · remote_desktop_clientEPSS 0.86%via NVD
CVE-2026-78462High· 8.8
3w ago

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · visual_studio_codeEPSS 0.76%via NVD
CVE-2026-78461High· 7.4
3w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · visual_studio_codeEPSS 1.0%via NVD
CVE-2026-78457High· 7.0
3w ago

Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.26%via NVD
CVE-2026-78456High· 8.8
3w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2022EPSS 0.91%via NVD
CVE-2026-78455Medium· 4.3
3w ago

Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.52%via NVD
CVE-2026-78454Medium· 5.5
3w ago

Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.

Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.40%via NVD
CVE-2026-78453Medium· 6.5
3w ago

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.92%via NVD
CVE-2026-78452Medium· 4.6
3w ago

Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.47%via NVD
CVE-2026-78451Medium· 6.8
3w ago

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.44%via NVD
CVE-2026-78450High· 8.1
3w ago

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.71%via NVD
CVE-2026-78449High· 8.1
3w ago

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.71%via NVD
CVE-2026-78448High· 7.8
3w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-78447High· 7.8
3w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVEs tagged “nvd” — page 410 · VulnSea