Search Results (49757 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-78510 1 Microsoft 9 365 Apps, Microsoft 365, Office 2016 and 6 more 2026-09-08 9.8 Critical
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78506 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 5.5 Medium
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-78504 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 8.8 High
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78503 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-78502 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-18796 1 Nordic Semiconductor Asa 1 Nrf5340 2026-09-08 N/A
Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.
CVE-2026-85201 1 Eclipse 1 Ankaios 2026-09-08 N/A
In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation that may abort the Ankaios agent process. This results in loss of orchestration services for workloads managed by the affected agent.
CVE-2026-77911 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
CVE-2026-72976 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 5 Medium
Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
CVE-2026-44756 1 Sap Se 1 Sap Extended Passport (epp) Processing 2026-09-08 10 Critical
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
CVE-2026-72973 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 8.8 High
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-76977 1 Sap Se 1 Sapui5(frame Options Allowlist) 2026-09-08 4.3 Medium
SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.
CVE-2026-72972 1 Microsoft 10 365 Apps, Microsoft 365, Office 2019 and 7 more 2026-09-08 8.8 High
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-75021 1 Fastify-cli 1 Fastify-cli 2026-09-08 8.1 High
fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the local machine, and because the Inspector protocol allows arbitrary code evaluation, a remote party that reaches it can achieve remote code execution on the developer's machine. This affects fastify-cli from 1.5.0 up to 8.0.1. Users should upgrade to fastify-cli 8.0.1, which honors the configured Inspector bind address.
CVE-2026-16025 1 Paytr 1 Paytr Virtual Pos Iframe Api (v9x) Whmcs Module 2026-09-08 7.5 High
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
CVE-2026-67384 1 Microsoft 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more 2026-09-08 8.8 High
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-66814 1 Microsoft 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more 2026-09-08 8.8 High
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67381 1 Microsoft 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more 2026-09-08 8.8 High
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67369 1 Microsoft 3 Microsoft Sql Server 2025 (cu8), Microsoft Sql Server 2025 For X64-based Systems (gdr), Sql Server 2025 2026-09-08 6.5 Medium
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-81991 2026-09-08 5.5 Medium
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.