Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-55075

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chained into account takeover. Email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the `email_verified` claim was only enforced when present as a boolean `false` so an absent or non-boolean claim was treated as verified. The fix in versions 2.29.7, 2.32.

PUBLISHED
Vendor
coder
Product
coder
Provider severity
HIGH
Conflicts
1

CVE-2026-5507

When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55069

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the PostgreSQL database can exploit SHA-512's high computation speed to recover the administrator password offline. In Kubernetes deployments, a successful crack further enables reading of the cluster ServiceAccount Token and all K8s Secrets, achieving vertical pr

PUBLISHED
Vendor
kestra-io
Product
kestra
Provider severity
HIGH
Conflicts
0

CVE-2026-5506

The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all versions up to, and including, 0.2.6. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
lucascaro
Product
Wavr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55058

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Office Online Server, Microsoft Office 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-55057

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55056

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office 2016, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2026-55055

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft SharePoint Server 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Word 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-55054

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft Office 365 for Mac, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Excel 2016, Microsoft Office 2019, Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55053

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Office Online Server
Provider severity
HIGH
Conflicts
1

CVE-2026-55052

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-55051

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55050

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Word 2016, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2021
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5505

The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
bitacre
Product
WP-Clippy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55049

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-55048

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Office Online Server
Provider severity
HIGH
Conflicts
2

CVE-2026-55047

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55046

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Office Online Server, Microsoft Office LTSC 2024
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55045

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2019, Microsoft Office 2016, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Server 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC for Mac 2021, Microsoft SharePoint Enterprise Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-55044

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Office Online Server, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Excel 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-55043

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft PowerPoint 2016, Microsoft Office 2019
Provider severity
HIGH
Conflicts
2

CVE-2026-55042

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55041

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Excel 2016, Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-55040

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5504

A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previous versions of wolfSSL the interior padding bytes are not validated.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55039

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021, Microsoft Excel 2016, Microsoft Office LTSC for Mac 2024, Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
2

CVE-2026-55038

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Server 2019, Microsoft Word 2016, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC 2021, Microsoft Office 365 for Mac, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-55037

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Office Online Server, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-55036

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Office Online Server, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-55035

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft Office 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC for Mac 2021, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft Office LTSC 2024, Microsoft Office 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2024
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55034

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-55033

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Word 2016, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Server 2019, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft SharePoint Server Subscription Edition, Microsoft Office 2019, Microsoft Office 365 for Mac
Provider severity
HIGH
Conflicts
2

CVE-2026-55032

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft SharePoint Server 2019, Microsoft Office LTSC 2021, Microsoft Word 2016, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-55031

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Office Online Server, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-55030

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5503

In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This caused TLSX_UseSNI to attach the attacker-controlled publicName to the shared WOLFSSL_CTX when no inner SNI was configured. TLSX_EchRestoreSNI then failed to clean it up because its removal was gated on serverNameX != NULL. The inner ClientHello was sized before the pollution but written after it, causing TLSX_SNI_Write to memcpy 255 bytes past the allocation boundary.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55029

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Office Online Server, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-55028

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft SharePoint Server 2019, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft Office 2019, Microsoft SharePoint Server Subscription Edition
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55027

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft SharePoint Server 2019, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft Office 2016, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55026

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft Office 2019, Microsoft Office 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55025

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office LTSC 2021, Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-55024

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Office Online Server, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-55023

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft SharePoint Server 2019, Microsoft Office 365 for Mac, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office 2016, Microsoft SharePoint Server Subscription Edition
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55022

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office 2016, Microsoft Office LTSC 2021, Microsoft Office 365 for Mac, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2026-55021

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition
Provider severity
HIGH
Conflicts
1

CVE-2026-55020

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5502

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_course_content_order() function. The function only validates the nonce (CSRF protection) but does not verify whether the user has permission to manage course content. The can_user_manage() authorization check only executes when the 'content_parent' parameter is pr

PUBLISHED
Vendor
themeum
Product
Tutor LMS – eLearning and online course solution
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55019

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55018

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft Office 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-55017

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2016
Provider severity
HIGH
Conflicts
1