Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-44866

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44865

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44864

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44863

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44862

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44861

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44860

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-4486

A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the argument curTime results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-513
Provider severity
HIGH
Conflicts
2

CVE-2026-44859

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44858

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44857

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44856

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44855

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44854

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44853

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44852

An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input validation in the file path parameter. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system as a privileged user.

PUBLISHED
Vendor
Hewlett Packard Enterprise (HPE)
Product
HPE Aruba Networking Wireless Operating System (AOS)
Provider severity
HIGH
Conflicts
0

CVE-2026-44850

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an environment-level Disable bind mounts for non-administrators security setting that blocks regular users from binding host paths into containers they create through the Portainer-mediated Docker API. The check that enforces this setting only inspected th

PUBLISHED
Vendor
portainer
Product
portainer
Provider severity
HIGH
Conflicts
0

CVE-2026-4485

A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/search_student.php. The manipulation of the argument Search leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
College Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-44849

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings restrictions that administrators configure to restrict the container configurations non-admin users can launch: privileged mode, host PID namespace, device mapping, capabilities, sysctls, security-opt (Seccomp / AppArmor),

PUBLISHED
Vendor
portainer
Product
portainer
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44848

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*) were not registered with a handler, so standard users with endpoint access could call privileged plugin operations — including installing and enabling plugins — directly against the underlying Docker daemon. The vulnerabi

PUBLISHED
Vendor
portainer
Product
portainer
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44847

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns (None, {}), which Django REST Framework interprets as successful authentication. Combined with optional per-trigger token verification and no backend enforcement of token requirements, any unauthenticated attacker who knows a valid trigger ID can invoke webhook triggers to e

PUBLISHED
Vendor
1Panel-dev
Product
MaxKB
Provider severity
HIGH
Conflicts
1

CVE-2026-44844

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.1, EmlParser.get_raw_body_text() recurses unconditionally for every nested message/rfc822 attachment without any depth limit. An attacker who can supply a badly crafted EML file with approximately 120 nested message/rfc822 parts triggers an unhandled RecursionError and aborts parsing of the message. A 12 KB EML file is enough to crash a wo

PUBLISHED
Vendor
GOVCERT-LU
Product
eml_parser
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44843

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="all". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime path

PUBLISHED
Vendor
langchain-ai
Product
langchain
Provider severity
HIGH
Conflicts
0

CVE-2026-44840

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is vulnerable to DQL (Dgraph Query Language) injection. User-supplied password values are interpolated directly into a DQL `checkpwd()` query via `fmt.Sprintf` without any escaping or parameterization. An attacker can inject a password containing a double-quote character to break out of the DQL string literal and append arbitrary DQL query blocks. Version 25.3.4 patches

PUBLISHED
Vendor
dgraph-io
Product
dgraph
Provider severity
HIGH
Conflicts
0

CVE-2026-4484

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with Student-level access and above, to elevate their privileges to that of an administrator.

PUBLISHED
Vendor
masteriyo
Product
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education
Provider severity
HIGH
Conflicts
0

CVE-2026-44839

RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44838

RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that include their client ID. However, the client_id is provided by the user in the MQTT CONNECT packet and is inserted into the regex pattern without escaping special regex characters. This flaw enables an authen

PUBLISHED
Vendor
rabbitmq
Product
rabbitmq-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44837

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

PUBLISHED
Vendor
ViewComponent
Product
view_component
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44836

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name from the URL and calls it with public_send. The code does not verify that the requested method is one of the preview examples explicitly defined by the preview class. As a result, inherited public methods on ViewComponent::Preview are route-reachable. The most important one is render_with_template, which accepts template:

PUBLISHED
Vendor
ViewComponent
Product
view_component
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44833

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.

PUBLISHED
Vendor
grokability
Product
snipe-it
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44832

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the superuser key from the permissions array, allowing admin and all other permission keys to be set by any user who can update users. This vulnerability is fixed in 8.4.1.

PUBLISHED
Vendor
grokability
Product
snipe-it
Provider severity
HIGH
Conflicts
1

CVE-2026-44831

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.

PUBLISHED
Vendor
grokability
Product
snipe-it
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44830

Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, the BearerTokenAuthMiddleware bypasses authentication for all HTTP requests. Combined with the default 0.0.0.0 host binding and CORS allow_origins=["*"], operators following the Docker setup without explicitly setting API_TOKEN expose the full Knowledge-Graph read/write API to any LAN-reachable client. An attacker on the same network can read, write

PUBLISHED
Vendor
Dataojitori
Product
nocturne_memory
Provider severity
HIGH
Conflicts
0

CVE-2026-4483

An exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxGeneralIo, exposes IOCTL methods that permit direct read and write access to MSR and system memory. A local attacker with high privileges could abuse these interfaces to perform unauthorized operations. Successful exploitation may result in privilege escalation on Windows 7 systems or cause a system crash (BSoD) on Windo

PUBLISHED
Vendor
Moxa, Moxa, Moxa
Product
MxGeneralIo, MxGeneralIo, MxGeneralIo
Provider severity
HIGH
Conflicts
1

CVE-2026-44827

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils.py performs string interpolation on the custom_pipeline parameter using f"{custom_pipeline}.py". When custom_pipeline is not supplied by the user, it defaults to None, which Python interpolates as the

PUBLISHED
Vendor
huggingface
Product
diffusers
Provider severity
HIGH
Conflicts
0

CVE-2026-44826

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-add endpoint. Submitting a negative integer is accepted by the server and treated as a normal positive line-item, but with the sign carried through into every downstream computation: line total, sub-total, taxes, and grand total all become negative numbers. The customer-facing cart UI then displays a n

PUBLISHED
Vendor
givanz
Product
Vvveb
Provider severity
HIGH
Conflicts
0

CVE-2026-44825

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, not yet released, vers

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Solr
Provider severity
HIGH
Conflicts
1

CVE-2026-44824

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft Office 365 for Mac, Microsoft Office 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-44823

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Office Online Server, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
2

CVE-2026-44822

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Office Online Server, Microsoft Office LTSC for Mac 2024, Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-44821

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2016, Microsoft Office 365 for Mac, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft SharePoint Server 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44820

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel 2016, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Office Online Server, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2026-4482

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.

PUBLISHED
Vendor
Rapid7
Product
Insight Agent
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44819

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office 2019, Microsoft Office 365 for Mac
Provider severity
HIGH
Conflicts
1

CVE-2026-44818

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Office Online Server
Provider severity
HIGH
Conflicts
1

CVE-2026-44817

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2019, Microsoft Excel 2016, Microsoft Office 365 for Mac, Office Online Server, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-44815

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 23H2, Windows 11 version 23H2, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows Server 2025, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2016, Windows 10 Version 1809
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44814

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44813

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
HIGH
Conflicts
0

CVE-2026-44812

Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Microsoft Excel for Android, Windows 10 Version 21H2, Windows Server 2016, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019, Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Microsoft Word for Android, Microsoft PowerPoint for Android, Windows Server 2012, Windows 11 version 23H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1