CVE-2026-21511
- EPSS 3.64%
- Veröffentlicht 10.02.2026 18:16:33
- Zuletzt bearbeitet 11.02.2026 18:56:56
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21260
- EPSS 1.43%
- Veröffentlicht 10.02.2026 18:16:27
- Zuletzt bearbeitet 11.02.2026 19:10:20
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20958
- EPSS 0.3%
- Veröffentlicht 13.01.2026 17:57:09
- Zuletzt bearbeitet 14.01.2026 19:21:51
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-20948
- EPSS 0.55%
- Veröffentlicht 13.01.2026 17:57:06
- Zuletzt bearbeitet 16.01.2026 16:19:15
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20947
- EPSS 18.6%
- Veröffentlicht 13.01.2026 17:56:52
- Zuletzt bearbeitet 16.01.2026 16:17:12
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-20959
- EPSS 7.25%
- Veröffentlicht 13.01.2026 17:56:49
- Zuletzt bearbeitet 14.01.2026 19:19:39
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-20963
- EPSS 31.55%
- Veröffentlicht 13.01.2026 17:56:49
- Zuletzt bearbeitet 01.04.2026 16:01:22
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-20951
- EPSS 0.8%
- Veröffentlicht 13.01.2026 17:56:47
- Zuletzt bearbeitet 14.01.2026 19:22:17
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- EPSS 0.65%
- Veröffentlicht 13.01.2026 17:56:45
- Zuletzt bearbeitet 16.01.2026 16:14:34
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
- EPSS 1.04%
- Veröffentlicht 09.12.2025 17:56:06
- Zuletzt bearbeitet 12.12.2025 13:47:01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.