Filter public vulnerability entries by severity / channel / vendor / time.
CVE-2026-41940 · 2026-07-14 · pending_review
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control …
CVE-2026-34621 · 2026-07-14 · pending_review
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CVE-2026-21514 · 2026-07-14 · pending_review
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21509 · 2026-07-14 · pending_review
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally…
CVE-2026-20128 · 2026-07-14 · pending_review
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on…
CVE-2025-8088 · 2026-07-15 · pending_review
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CVE-2025-6218 · 2026-07-14 · pending_review
RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-0411 · 2026-07-15 · pending_review
7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2024-7262 · 2026-07-15 · pending_review
Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.
CVE-2024-21413 · 2026-07-15 · pending_review
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and o…
CVE-2023-7101 · 2026-07-15 · pending_review
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings wi…
CVE-2023-6448 · 2026-07-15 · pending_review
Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.
CVE-2023-45249 · 2026-07-15 · pending_review
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
CVE-2023-38831 · 2026-07-15 · pending_review
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
CVE-2023-36761 · 2026-07-15 · pending_review
Microsoft Word contains an unspecified vulnerability that allows for information disclosure.
CVE-2023-36563 · 2026-07-15 · pending_review
Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.
CVE-2023-35311 · 2026-07-15 · pending_review
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
CVE-2023-26369 · 2026-07-15 · pending_review
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
CVE-2023-23397 · 2026-07-15 · pending_review
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
CVE-2023-21715 · 2026-07-15 · pending_review
Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.
CVE-2023-21608 · 2026-07-15 · pending_review
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
CVE-2021-42292 · 2026-07-18 · pending_review
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
CVE-2021-38646 · 2026-07-15 · pending_review
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
CVE-2021-28550 · 2026-07-18 · pending_review
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
CVE-2021-27059 · 2026-07-18 · pending_review
Microsoft Office contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-21017 · 2026-07-18 · pending_review
Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
CVE-2020-9715 · 2026-07-14 · pending_review
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
CVE-2020-8599 · 2026-07-18 · pending_review
Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.
CVE-2020-8468 · 2026-07-18 · pending_review
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.
CVE-2020-8467 · 2026-07-18 · pending_review
Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
CVE-2020-6820 · 2026-07-18 · pending_review
Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.
CVE-2020-6819 · 2026-07-18 · pending_review
Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impac…
CVE-2020-25213 · 2026-07-18 · pending_review
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
CVE-2020-24557 · 2026-07-18 · pending_review
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the…
CVE-2020-11738 · 2026-07-18 · pending_review
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard.…
CVE-2019-9978 · 2026-07-18 · pending_review
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
CVE-2019-18187 · 2026-07-18 · pending_review
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
CVE-2019-17026 · 2026-07-18 · pending_review
Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.
CVE-2019-1297 · 2026-07-15 · pending_review
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
CVE-2019-11708 · 2026-07-15 · pending_review
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2019-11707 · 2026-07-15 · pending_review
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2018-4990 · 2026-07-15 · pending_review
Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
CVE-2018-20250 · 2026-07-18 · pending_review
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
CVE-2018-0802 · 2026-07-18 · pending_review
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is…
CVE-2018-0798 · 2026-07-18 · pending_review
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is…
CVE-2017-8570 · 2026-07-18 · pending_review
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
CVE-2017-11882 · 2026-07-18 · pending_review
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
CVE-2017-11826 · 2026-07-18 · pending_review
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in…
CVE-2017-11774 · 2026-07-18 · pending_review
Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.
CVE-2017-0262 · 2026-07-18 · pending_review
A remote code execution vulnerability exists in Microsoft Office.