Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-26107

7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Microsoft
Details

CVE-2026-26106

8.8

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Microsoft
Details

CVE-2026-26105

9.3

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Microsoft
Details

CVE-2026-25972

4.3

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data …

Fortinet
Details

CVE-2026-25836

7.2

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI …

Fortinet
Details

CVE-2026-25689

6.5

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeceptor 6.0 all versions, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 …

Fortinet
Details

CVE-2026-25605

5.9

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could …

SICAM
Details

CVE-2026-25573

8.6

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the …

SICAM
Details

CVE-2026-25572

5.9

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. …

SICAM
Details

CVE-2026-25571

5.9

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. …

SICAM
Details
745/3864