Количество 396 541
Количество 396 541
CVE-2026-55136
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55135
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55134
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55133
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
CVE-2026-55132
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55131
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55130
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-5512
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and validation error messages included the full repository name for repositories the caller did not have access to. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program.
CVE-2026-55129
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55128
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55127
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55126
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55125
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55124
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-55123
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55122
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55121
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55120
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-5511
In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information. An authenticated attacker with administrative privileges could exploit this issue to confirm the presence of the diagnostic utility and view its valid command-line syntax and options. The exposed information is limited in scope and does not include sensitive system data.
CVE-2026-55119
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55136 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55135 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | CVSS3: 4.6 | 1% Низкий | 2 месяца назад | |
CVE-2026-55134 Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55133 Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55132 Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55131 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55130 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-5512 An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and validation error messages included the full repository name for repositories the caller did not have access to. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program. | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-55129 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55128 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55127 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55126 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | CVSS3: 7.3 | 1% Низкий | 2 месяца назад | |
CVE-2026-55125 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-55124 Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-55123 Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-55122 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | CVSS3: 7.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-55121 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-55120 Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-5511 In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information. An authenticated attacker with administrative privileges could exploit this issue to confirm the presence of the diagnostic utility and view its valid command-line syntax and options. The exposed information is limited in scope and does not include sensitive system data. | CVSS3: 2.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-55119 A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу