| | CVE-2026-45460 | Microsoft | medium | 4.7 | 0.4%
| | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45461 | Microsoft | high | 8.4 | 0.4%
| | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45462 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45463 | Microsoft | high | 8.4 | 0.3%
| | Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execut… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45464 | Microsoft | medium | 5.4 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 20, 2026 |
| | CVE-2026-45465 | Microsoft | medium | 5.4 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45466 | Microsoft | low | 3.3 | 0.4%
| | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose info… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45467 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45468 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45469 | Microsoft | high | 7.8 | 0.4%
| | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45471 | Microsoft | high | 7.8 | 0.5%
| | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45472 | Microsoft | high | 8.4 | 0.3%
| | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45474 | Microsoft | high | 8.4 | 0.4%
| | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45475 | Microsoft | high | 7.8 | 0.5%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45476 | Microsoft | high | 8.2 | 0.3%
| | Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45479 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45481 | Microsoft | high | 7.3 | 0.7%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45482 | Microsoft | high | 8.4 | 0.3%
| | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45483 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45484 | Microsoft | high | 8.8 | 2.0%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to el… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45485 | Microsoft | low | 3.3 | 0.4%
| | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45486 | Microsoft | high | 7.8 | 0.4%
| | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45490 | Microsoft | high | 7.8 | 0.4%
| | Improper authorization in .NET allows an authorized attacker to elevate privileges locally. | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45491 | Microsoft | medium | 6.2 | 0.4%
| | Improper link resolution before file access ('link following') in .NET allows an unauthorized attack… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45500 | Microsoft | medium | 6.1 | 0.4%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex… | Jun 9, 2026 | Jul 28, 2026 |
| | CVE-2026-45501 | Microsoft | medium | 6.5 | 0.3%
| | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to per… | Jun 9, 2026 | Jul 28, 2026 |
| | CVE-2026-45502 | Microsoft | medium | 5.0 | 20.3%
| | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to dis… | Jun 9, 2026 | Jul 28, 2026 |
| | CVE-2026-45503 | Microsoft | high | 8.1 | 0.4%
| | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose inform… | Jun 9, 2026 | Jul 28, 2026 |
| | CVE-2026-45504 | Microsoft | high | 8.8 | 0.8%
| | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to ele… | Jun 9, 2026 | Jul 28, 2026 |
| | CVE-2026-45583 | Microsoft | high | 7.5 | 0.5%
| | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an una… | Jun 9, 2026 | Jul 28, 2026 |
| | CVE-2026-45591 | Microsoft | high | 7.5 | 2.4%
| | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service ov… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45639 | Microsoft | high | 7.5 | 0.9%
| | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45643 | Microsoft | high | 7.8 | 0.4%
| | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45644 | Microsoft | high | 8.0 | 0.6%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Li… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45645 | Microsoft | high | 7.8 | 0.4%
| | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45647 | Microsoft | medium | 5.5 | 0.2%
| | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an autho… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45649 | Microsoft | high | 7.1 | 0.4%
| | Improper access control in Office for Android allows an unauthorized attacker to perform spoofing lo… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-45650 | Microsoft | medium | 4.3 | 0.6%
| | User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthoriz… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47281 | Microsoft | critical | 9.6 | 0.6%
| | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges ov… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47284 | Microsoft | medium | 6.5 | 0.8%
| | Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthori… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47287 | Microsoft | medium | 6.5 | 0.6%
| | Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering o… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47289 | Microsoft | high | 8.8 | 1.0%
| | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47292 | Microsoft | high | 7.8 | 0.4%
| | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorize… | Jun 9, 2026 | Aug 24, 2026 |
| | CVE-2026-47293 | Microsoft | high | 7.0 | 0.2%
| | Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47298 | Microsoft | high | 8.0 | 0.7%
| | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code … | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47631 | Microsoft | high | 8.1 | 0.4%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex… | Jun 9, 2026 | Jul 28, 2026 |
| | CVE-2026-47634 | Microsoft | high | 7.3 | 0.6%
| | Improper neutralization of special elements in output used by a downstream component ('injection') i… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47635 | Microsoft | high | 8.4 | 0.3%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47636 | Microsoft | medium | 5.4 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47637 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |