Common Vulnerabilities and Exposures (CVE)

CVE-2026-62896

Sep 2, 2026 18:21:07 UTC

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

CVE-2026-63520

Sep 2, 2026 18:21:06 UTC

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVE-2026-63516

Sep 2, 2026 18:21:05 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-63512

Sep 2, 2026 18:21:04 UTC

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

CVE-2026-63514

Sep 2, 2026 18:21:04 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-62837

Sep 2, 2026 18:21:03 UTC

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

CVE-2026-62827

Sep 2, 2026 18:21:02 UTC

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVE-2026-62829

Sep 2, 2026 18:21:02 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-57105

Sep 2, 2026 18:21:01 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-65768

Sep 2, 2026 18:21:00 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

CVE-2026-58650

Sep 2, 2026 18:20:59 UTC

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-56174

Sep 2, 2026 18:20:58 UTC

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVE-2026-50472

Sep 2, 2026 18:20:57 UTC

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

CVE-2026-84379

Sep 2, 2026 18:20:46 UTC

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-elemen...

CVE-2026-51705

Sep 2, 2026 18:20:12 UTC

Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.