Количество 396 015
Количество 396 015
CVE-2026-55132
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55131
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55130
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-5512
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and validation error messages included the full repository name for repositories the caller did not have access to. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program.
CVE-2026-55129
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55128
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55127
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55126
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55125
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55124
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-55123
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55122
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55121
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55120
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-5511
In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information. An authenticated attacker with administrative privileges could exploit this issue to confirm the presence of the diagnostic utility and view its valid command-line syntax and options. The exposed information is limited in scope and does not include sensitive system data.
CVE-2026-55119
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
CVE-2026-55118
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
CVE-2026-55117
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
CVE-2026-55116
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
CVE-2026-55115
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55132 Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55131 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55130 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-5512 An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and validation error messages included the full repository name for repositories the caller did not have access to. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program. | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-55129 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55128 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55127 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55126 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | CVSS3: 7.3 | 1% Низкий | 2 месяца назад | |
CVE-2026-55125 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55124 Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-55123 Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55122 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | CVSS3: 7.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-55121 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-55120 Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-5511 In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information. An authenticated attacker with administrative privileges could exploit this issue to confirm the presence of the diagnostic utility and view its valid command-line syntax and options. The exposed information is limited in scope and does not include sensitive system data. | CVSS3: 2.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-55119 A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-55118 A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. | CVSS3: 8.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-55117 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device. | CVSS3: 8.6 | 1% Низкий | 3 месяца назад | |
CVE-2026-55116 A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. | CVSS3: 9 | 0% Низкий | 3 месяца назад | |
CVE-2026-55115 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device. | CVSS3: 9.9 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу