|
1521
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Update
|
CWE-416
Use After Free
|
CVE-2026-40358
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1522
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Update
|
CWE-416
Use After Free
|
CVE-2026-40359
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1523
|
7.8 |
HIGH
Local
|
-
|
-
|
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-40360
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1524
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Update
|
CWE-416
Use After Free
|
CVE-2026-40361
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1525
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-40362
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1526
|
8.4 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-40363
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1527
|
8.4 |
HIGH
Local
|
-
|
-
|
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Update
|
CWE-122 CWE-843 CWE-908
Heap-based Buffer Overflow Type Confusion Use of Uninitialized Resource
|
CVE-2026-40364
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1528
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Update
|
CWE-416
Use After Free
|
CVE-2026-40366
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1529
|
8.4 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Update
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-40367
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1530
|
8.8 |
HIGH
Network
|
-
|
-
|
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
Update
|
CWE-73
External Control of File Name or Path
|
CVE-2026-40370
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|