CVE-2026-35439
- EPSS 2.03%
- Veröffentlicht 12.05.2026 16:58:35
- Zuletzt bearbeitet 13.05.2026 20:53:04
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-32201
- EPSS 22.77%
- Veröffentlicht 14.04.2026 16:58:36
- Zuletzt bearbeitet 28.05.2026 14:27:53
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20945
- EPSS 25.08%
- Veröffentlicht 14.04.2026 16:56:55
- Zuletzt bearbeitet 06.05.2026 18:04:39
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-26106
- EPSS 1.37%
- Veröffentlicht 10.03.2026 17:05:17
- Zuletzt bearbeitet 13.03.2026 16:00:14
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-26113
- EPSS 0.54%
- Veröffentlicht 10.03.2026 17:05:04
- Zuletzt bearbeitet 13.03.2026 17:08:02
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-26114
- EPSS 3.03%
- Veröffentlicht 10.03.2026 17:05:04
- Zuletzt bearbeitet 13.03.2026 17:07:21
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-26105
- EPSS 1.16%
- Veröffentlicht 10.03.2026 17:05:01
- Zuletzt bearbeitet 13.03.2026 20:44:57
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21511
- EPSS 3.64%
- Veröffentlicht 10.02.2026 18:16:33
- Zuletzt bearbeitet 11.02.2026 18:56:56
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21260
- EPSS 1.43%
- Veröffentlicht 10.02.2026 18:16:27
- Zuletzt bearbeitet 11.02.2026 19:10:20
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20958
- EPSS 0.3%
- Veröffentlicht 13.01.2026 17:57:09
- Zuletzt bearbeitet 14.01.2026 19:21:51
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.