Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,003
Quick preset (or use dates below)
Clear Filters
Showing 981 - 1,000 of 13,341 CVEs
CVE-2026-45454 MEDIUM - 6.5

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: sharepoint_server
Published: Jun 09, 2026
Source: NVD
CVE-2026-45453 MEDIUM - 5.4

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: sharepoint_server
Published: Jun 09, 2026
Source: NVD
CVE-2026-45446 MEDIUM - 4.8

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-44821 MEDIUM - 5.5

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Vendor: microsoft
Product: 365_apps
Published: Jun 09, 2026
Source: NVD
CVE-2026-44814 MEDIUM - 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_11_26h1
Published: Jun 09, 2026
Source: NVD
CVE-2026-44805 MEDIUM - 5.5

Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.

Vendor: microsoft
Product: windows_server_2019
Published: Jun 09, 2026
Source: NVD
CVE-2026-42973 MEDIUM - 5.5

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42972 MEDIUM - 5.5

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42971 MEDIUM - 5.5

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42970 MEDIUM - 5.5

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42969 MEDIUM - 5.5

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42968 MEDIUM - 5.5

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42915 MEDIUM - 5.7

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service over an adjacent network.

Vendor: microsoft
Product: windows_10_21h2
Published: Jun 09, 2026
Source: NVD
CVE-2026-42914 MEDIUM - 5.3

Windows Kerberos Denial of Service Vulnerability

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42907 MEDIUM - 6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1809
Published: Jun 09, 2026
Source: NVD
CVE-2026-42906 MEDIUM - 5.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_21h2
Published: Jun 09, 2026
Source: NVD
CVE-2026-42903 MEDIUM - 6.5

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42771 MEDIUM - 6.2

Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen. Impact summary: This out of bounds read will not directly exfiltrate the data read to the attacker so th...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-42769 MEDIUM - 5.3

Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to ...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-42767 MEDIUM - 5.9

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling a CMP server (or ac...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD