Common Vulnerabilities and Exposures (CVE)

CVE-2026-45479

Aug 13, 2026 20:52:08 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-45474

Aug 13, 2026 20:52:07 UTC

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-45471

Aug 13, 2026 20:52:06 UTC

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-45472

Aug 13, 2026 20:52:06 UTC

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-45475

Aug 13, 2026 20:52:05 UTC

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-45469

Aug 13, 2026 20:52:04 UTC

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-45468

Aug 13, 2026 20:52:04 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-45467

Aug 13, 2026 20:52:03 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-41108

Aug 13, 2026 20:52:02 UTC

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-19483

Aug 13, 2026 20:47:01 UTC

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade f...

CVE-2026-19297

Aug 13, 2026 20:46:44 UTC

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.

CVE-2026-18715

Aug 13, 2026 20:46:29 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.

CVE-2026-18671

Aug 13, 2026 20:46:00 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to ca...

CVE-2026-19749

Aug 13, 2026 20:45:09 UTC

A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulatio...

CVE-2026-18741

Aug 13, 2026 20:45:09 UTC

Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management module that allows authenticated administrators to inject arbitrary JavaScript by entering malicious payloads into the Loca...