5d ago
2026-09-08 18:20Z
CRIT

CVE-2026-78445 — Use: after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78445

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-78444 — Untrusted: pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78444

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 822VNDUntrustedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-78442 — Heap: Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78442

Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-78439 — Stack: Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78439

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77908 — Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77908

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77907 — Heap: Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77907

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77906 — Heap: Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77906

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77901 — Null: pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77901

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 476VNDNullTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77505 — Use: after free in DNS Server allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77505

Use after free in DNS Server allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77504 — Double: free in Microsoft Office Word allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77504

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 415VNDDoubleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77503 — Out: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77503

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. CVSSv3.1 8.4 (HIGH)

CWECWE 125TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77495 — Heap: Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77495

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
CRIT

CVE-2026-77493 — Double: free in Microsoft Graphics Component allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77493

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 415VNDDoubleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77487 — SQL: Improper access control in SQL Server allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77487

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77486 — Integer: overflow or wraparound in SQL Server allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77486

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77484 — Deserialization: of untrusted data in SQL Server allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77484

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77483 — Weak: authentication in SQL Server allows an authorized attacker to elevate privileges over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77483

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 1390VNDWeakTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77482 — Heap: Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77482

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77481 — Heap: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77481

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-77480 — Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77480

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 1220TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-76191 — Animate: is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76191

Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 94VNDAnimateTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-73028 — SQL: Improper access control in SQL Server allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73028

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
CRIT

CVE-2026-73025 — Weak: authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73025

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1390VNDWeakTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-73023 — Heap: Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73023

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH

CVE-2026-73018 — Heap: Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73018

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score