CVE-2026-20948
- EPSS 0.55%
- Veröffentlicht 13.01.2026 17:57:06
- Zuletzt bearbeitet 16.01.2026 16:19:15
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20947
- EPSS 18.6%
- Veröffentlicht 13.01.2026 17:56:52
- Zuletzt bearbeitet 16.01.2026 16:17:12
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-20959
- EPSS 7.25%
- Veröffentlicht 13.01.2026 17:56:49
- Zuletzt bearbeitet 14.01.2026 19:19:39
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-20963
- EPSS 31.55%
- Veröffentlicht 13.01.2026 17:56:49
- Zuletzt bearbeitet 01.04.2026 16:01:22
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-20951
- EPSS 0.8%
- Veröffentlicht 13.01.2026 17:56:47
- Zuletzt bearbeitet 14.01.2026 19:22:17
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- EPSS 0.65%
- Veröffentlicht 13.01.2026 17:56:45
- Zuletzt bearbeitet 16.01.2026 16:14:34
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62558
- EPSS 0.62%
- Veröffentlicht 09.12.2025 17:55:59
- Zuletzt bearbeitet 10.12.2025 15:39:36
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62559
- EPSS 0.62%
- Veröffentlicht 09.12.2025 17:55:59
- Zuletzt bearbeitet 10.12.2025 15:38:54
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- EPSS 0.51%
- Veröffentlicht 09.12.2025 17:55:57
- Zuletzt bearbeitet 10.12.2025 18:32:58
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62562
- EPSS 0.8%
- Veröffentlicht 09.12.2025 17:55:40
- Zuletzt bearbeitet 09.12.2025 21:30:44
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.