|
1581
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-40362
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1582
|
8.4 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-40363
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1583
|
8.4 |
HIGH
Local
|
-
|
-
|
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-122 CWE-843 CWE-908
Heap-based Buffer Overflow Type Confusion Use of Uninitialized Resource
|
CVE-2026-40364
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1584
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-40366
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1585
|
8.4 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-40367
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1586
|
8.8 |
HIGH
Network
|
-
|
-
|
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
|
CWE-73
External Control of File Name or Path
|
CVE-2026-40370
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1587
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
|
CWE-200
Information Exposure
|
CVE-2026-40374
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1588
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
|
CWE-200
Information Exposure
|
CVE-2026-40379
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1589
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
|
CWE-284
Improper Access Control
|
CVE-2026-40381
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1590
|
4.3 |
MEDIUM
Network
|
-
|
-
|
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-40416
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|