NVD Dashboard
CVEs Received and Processed
NVD Contains
| CVE Vulnerabilities | 377240 |
| Checklists | 913 |
| US-CERT Alerts | 249 |
| US-CERT Vuln Notes | 4486 |
| OVAL Queries | 0 |
| CPE Names | 1802557 |
CVSS V3 Score Distribution
| Severity | Number of Vulns |
|---|
CVSS V2 Score Distribution
| Severity | Number of Vulns |
|---|
For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
-
CVE-2026-70337 - Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 1:19:11 PM -0400 -
CVE-2026-70329 - Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 1:19:10 PM -0400 -
CVE-2026-65657 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:53 PM -0400 -
CVE-2026-64911 - Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:52 PM -0400 -
CVE-2026-63518 - Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:47 PM -0400 -
CVE-2026-63513 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:46 PM -0400 -
CVE-2026-13380 - VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the app... read CVE-2026-13380
Published: July 20, 2026; 5:16:46 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-13381 - VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files b... read CVE-2026-13381
Published: July 20, 2026; 5:16:46 PM -0400V3.1: 8.1 HIGH
-
CVE-2026-62910 - Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Published: August 11, 2026; 1:18:44 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-62890 - Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
Published: August 11, 2026; 1:18:40 PM -0400 -
CVE-2026-62823 - Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
Published: August 11, 2026; 1:18:36 PM -0400 -
CVE-2026-62915 - Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
Published: August 11, 2026; 1:18:45 PM -0400 -
CVE-2026-62898 - Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 1:18:43 PM -0400 -
CVE-2026-64920 - Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:53 PM -0400 -
CVE-2026-64905 - Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:51 PM -0400 -
CVE-2026-64914 - Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:52 PM -0400 -
CVE-2026-64919 - Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:53 PM -0400 -
CVE-2026-64907 - Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:51 PM -0400 -
CVE-2026-64912 - Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:52 PM -0400 -
CVE-2026-64904 - Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 1:18:51 PM -0400