vulnti.work

Vulnerability list

Filter public vulnerability entries by severity / channel / vendor / time.

Clear
Microsoft Office Security Feature Bypass Vulnerability
High KEV

CVE-2026-21509 · 2026-07-14 · pending_review

Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally…

RARLAB WinRAR Path Traversal Vulnerability
High KEV

CVE-2025-8088 · 2026-07-15 · pending_review

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.

RARLAB WinRAR Path Traversal Vulnerability
High KEV

CVE-2025-6218 · 2026-07-14 · pending_review

RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.

7-Zip Mark of the Web Bypass Vulnerability
High KEV

CVE-2025-0411 · 2026-07-15 · pending_review

7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.

Kingsoft WPS Office Path Traversal Vulnerability
High KEV

CVE-2024-7262 · 2026-07-15 · pending_review

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.

Microsoft Outlook Improper Input Validation Vulnerability
Critical KEV

CVE-2024-21413 · 2026-07-15 · pending_review

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and o…

Spreadsheet::ParseExcel Remote Code Execution Vulnerability
Critical KEV

CVE-2023-7101 · 2026-07-15 · pending_review

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings wi…

RARLAB WinRAR Code Execution Vulnerability
High KEV

CVE-2023-38831 · 2026-07-15 · pending_review

RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.

Microsoft Excel Security Feature Bypass
High KEV

CVE-2021-42292 · 2026-07-18 · pending_review

A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.

Adobe Acrobat and Reader Use-After-Free Vulnerability
High KEV

CVE-2021-28550 · 2026-07-18 · pending_review

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
High KEV

CVE-2020-6820 · 2026-07-18 · pending_review

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
High KEV

CVE-2020-6819 · 2026-07-18 · pending_review

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impac…

Trend Micro Multiple Products Improper Access Control Vulnerability
High KEV

CVE-2020-24557 · 2026-07-18 · pending_review

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the…

WordPress Snap Creek Duplicator Plugin File Download Vulnerability
High KEV

CVE-2020-11738 · 2026-07-18 · pending_review

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard.…

Trend Micro OfficeScan Directory Traversal Vulnerability
Critical KEV

CVE-2019-18187 · 2026-07-18 · pending_review

Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.

Mozilla Firefox and Thunderbird Type Confusion Vulnerability
High KEV

CVE-2019-11707 · 2026-07-15 · pending_review

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.

Microsoft Office Memory Corruption Vulnerability
Critical KEV

CVE-2018-0802 · 2026-07-18 · pending_review

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is…

Microsoft Office Memory Corruption Vulnerability
Critical KEV

CVE-2018-0798 · 2026-07-18 · pending_review

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is…

Microsoft Office Memory Corruption Vulnerability
Critical KEV

CVE-2017-11882 · 2026-07-18 · pending_review

Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

Microsoft Office Remote Code Execution Vulnerability
Critical KEV

CVE-2017-11826 · 2026-07-18 · pending_review

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in…

Next page →