2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-70130 — Heap: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70130

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. CVSSv3.1 8.4 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-69320 — Improper neutralization of special elements used in an os command ('os command injection') in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69320

Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-69306 — Not: failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69306

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 636VNDNotTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:19Z
CRIT

CVE-2026-69223 — Apache: Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 918VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-68820 — Use: after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68820in the wild

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. CVSSv3.1 7.0 (HIGH)

CWECWE 416TYPVulnerabilitySTAitw exploited
7.0
CVSS v3.1
85
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-66808 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66808

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-66805 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66805

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-66802 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66802

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-65815 — Deserialization: of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65815

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-65811 — Power: Improper input validation in Power BI allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65811

Improper input validation in Power BI allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 20VNDPowerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:19Z
HIGH

CVE-2026-65807 — Access: of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65807

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDAccessTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65796 — Microsoft Windows_10_1607: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65796

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH) · EPSS 41th percentile

CWECWE 122VNDMicrosoftVNDHeapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
CRIT

CVE-2026-65791 — Heap: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65791

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65789 — Use: after free in Windows DNS allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65789

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65768 — Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65768

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65767 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65767

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65679 — Heap: Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65679

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65665 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65665

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65663 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65663

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65660 — Microsoft Sharepoint_server: Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65660

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH) · EPSS 52th percentile

CWECWE 94VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-65658 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65658

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-64921 — Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64921

Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-64901 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64901

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-63520 — Microsoft: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63520

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 20VNDMicrosoftTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-63514 — Deserialization: of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63514

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score