Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-23657

7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Microsoft
Details

CVE-2026-23653

5.7

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

GitHub
Details

CVE-2026-20945

4.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Microsoft
Details

CVE-2026-20930

7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Concurrent
Details

CVE-2026-20928

4.6

Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.

Details

CVE-2026-20806

5.5

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

Access
Details

CVE-2026-0390

6.7

Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

Reliance
Details

CVE-2026-0209

6.9

Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured.

Under
Details

CVE-2026-0207

8.5

A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.

FlashBlade
Details

CVE-2025-70023

9.8

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

An
Details
53/3864