|
1031
|
8.3 |
HIGH
Network
|
-
|
-
|
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
New
|
CWE-862
Missing Authorization
|
CVE-2026-35438
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1032
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
New
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2026-35440
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1033
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-416
Use After Free
|
CVE-2026-40358
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1034
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
New
|
CWE-416
Use After Free
|
CVE-2026-40359
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1035
|
7.8 |
HIGH
Local
|
-
|
-
|
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-40360
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1036
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
New
|
CWE-416
Use After Free
|
CVE-2026-40361
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1037
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-40362
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1038
|
8.4 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-40363
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1039
|
8.4 |
HIGH
Local
|
-
|
-
|
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
New
|
CWE-122 CWE-843 CWE-908
Heap-based Buffer Overflow Type Confusion Use of Uninitialized Resource
|
CVE-2026-40364
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1040
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
New
|
CWE-416
Use After Free
|
CVE-2026-40366
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|