Common Vulnerabilities and Exposures (CVE)

CVE-2026-47655

Aug 13, 2026 20:52:11 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

CVE-2026-47644

Aug 13, 2026 20:52:10 UTC

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

CVE-2026-45483

Aug 13, 2026 20:52:09 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

CVE-2026-45485

Aug 13, 2026 20:52:09 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-45486

Aug 13, 2026 20:52:08 UTC

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-45479

Aug 13, 2026 20:52:08 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-45474

Aug 13, 2026 20:52:07 UTC

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-45471

Aug 13, 2026 20:52:06 UTC

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-45472

Aug 13, 2026 20:52:06 UTC

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-45475

Aug 13, 2026 20:52:05 UTC

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-45469

Aug 13, 2026 20:52:04 UTC

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-45468

Aug 13, 2026 20:52:04 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-45467

Aug 13, 2026 20:52:03 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-41108

Aug 13, 2026 20:52:02 UTC

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-19483

Aug 13, 2026 20:47:01 UTC

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade f...