CVE-2026-34621 · 2026-07-14 · pending_review
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。
CVE-2026-34621 · 2026-07-14 · pending_review
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CVE-2026-21514 · 2026-07-14 · pending_review
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21509 · 2026-07-14 · pending_review
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally…
CVE-2026-20128 · 2026-07-14 · pending_review
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on…
CVE-2025-8088 · 2026-07-15 · pending_review
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CVE-2025-6218 · 2026-07-14 · pending_review
RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-0411 · 2026-07-15 · pending_review
7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2024-7262 · 2026-07-15 · pending_review
Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.
CVE-2023-6448 · 2026-07-15 · pending_review
Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.
CVE-2023-38831 · 2026-07-15 · pending_review
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
CVE-2023-36761 · 2026-07-15 · pending_review
Microsoft Word contains an unspecified vulnerability that allows for information disclosure.
CVE-2023-36563 · 2026-07-15 · pending_review
Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.
CVE-2023-35311 · 2026-07-15 · pending_review
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
CVE-2023-26369 · 2026-07-15 · pending_review
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
CVE-2023-23397 · 2026-07-15 · pending_review
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
CVE-2023-21715 · 2026-07-15 · pending_review
Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.
CVE-2023-21608 · 2026-07-15 · pending_review
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
CVE-2021-42292 · 2026-07-18 · pending_review
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
CVE-2021-28550 · 2026-07-18 · pending_review
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
CVE-2021-21017 · 2026-07-18 · pending_review
Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
CVE-2020-9715 · 2026-07-14 · pending_review
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
CVE-2020-8599 · 2026-07-18 · pending_review
Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.
CVE-2020-8468 · 2026-07-18 · pending_review
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.
CVE-2020-6820 · 2026-07-18 · pending_review
Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.
CVE-2020-6819 · 2026-07-18 · pending_review
Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impac…
CVE-2020-24557 · 2026-07-18 · pending_review
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the…
CVE-2020-11738 · 2026-07-18 · pending_review
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard.…
CVE-2019-17026 · 2026-07-18 · pending_review
Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.
CVE-2019-11707 · 2026-07-15 · pending_review
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2017-11774 · 2026-07-18 · pending_review
Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.
CVE-2016-9079 · 2026-07-15 · pending_review
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
CVE-2016-7262 · 2026-07-18 · pending_review
A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.
CVE-2015-2545 · 2026-07-18 · pending_review
Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
CVE-2015-2424 · 2026-07-18 · pending_review
Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
CVE-2015-1770 · 2026-07-15 · pending_review
Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
CVE-2015-1642 · 2026-07-18 · pending_review
Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
CVE-2014-1812 · 2026-07-18 · pending_review
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully expl…
CVE-2014-0546 · 2026-07-15 · pending_review
Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.
CVE-2014-0496 · 2026-07-18 · pending_review
Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.
CVE-2013-3346 · 2026-07-18 · pending_review
Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.
CVE-2013-2729 · 2026-07-15 · pending_review
Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
CVE-2013-1690 · 2026-07-15 · pending_review
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via…
CVE-2013-1331 · 2026-07-15 · pending_review
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.
CVE-2011-4723 · 2026-07-15 · pending_review
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.
CVE-2011-2462 · 2026-07-15 · pending_review
The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).
CVE-2010-2883 · 2026-07-15 · pending_review
Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2009-4324 · 2026-07-15 · pending_review
Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.
CVE-2009-3459 · 2026-07-14 · pending_review
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
CVE-2009-3129 · 2026-07-18 · pending_review
Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.
CVE-2009-1862 · 2026-07-15 · pending_review
Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).