<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Microsoft Office (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/office.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/office-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Microsoft Office (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-47294 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47294</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47294</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45659 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45659</guid>
    <pubDate>Fri, 22 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45659</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44212 – PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44212</guid>
    <pubDate>Thu, 14 May 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44212</strong></p>
  <p>PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42832 – Improper access control in Microsoft Office allows an unauthorized attacker to p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42832</guid>
    <pubDate>Tue, 12 May 2026 18:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42832</strong></p>
  <p>Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42831 – Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42831</guid>
    <pubDate>Tue, 12 May 2026 18:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42831</strong></p>
  <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41102 – Improper access control in Microsoft Office PowerPoint allows an authorized atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41102</guid>
    <pubDate>Tue, 12 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41102</strong></p>
  <p>Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41101 – Improper access control in Microsoft Office Word allows an authorized attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41101</guid>
    <pubDate>Tue, 12 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41101</strong></p>
  <p>Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40420 – Use after free in Microsoft Office allows an authorized attacker to elevate priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40420</guid>
    <pubDate>Tue, 12 May 2026 18:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40420</strong></p>
  <p>Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40419 – Use after free in Microsoft Office allows an authorized attacker to elevate priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40419</guid>
    <pubDate>Tue, 12 May 2026 18:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40419</strong></p>
  <p>Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40418 – Use after free in Microsoft Office allows an authorized attacker to elevate priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40418</guid>
    <pubDate>Tue, 12 May 2026 18:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40418</strong></p>
  <p>Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40368 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40368</guid>
    <pubDate>Tue, 12 May 2026 18:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40368</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40367 – Access of resource using incompatible type ('type confusion') in Microsoft Offic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40367</guid>
    <pubDate>Tue, 12 May 2026 18:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40367</strong></p>
  <p>Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40366 – Access of resource using incompatible type ('type confusion') in Microsoft Offic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40366</guid>
    <pubDate>Tue, 12 May 2026 18:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40366</strong></p>
  <p>Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40365 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40365</guid>
    <pubDate>Tue, 12 May 2026 18:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40365</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40364 – Access of resource using incompatible type ('type confusion') in Microsoft Offic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40364</guid>
    <pubDate>Tue, 12 May 2026 18:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40364</strong></p>
  <p>Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40363 – Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40363</guid>
    <pubDate>Tue, 12 May 2026 18:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40363</strong></p>
  <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40362 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40362</guid>
    <pubDate>Tue, 12 May 2026 18:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40362</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40361 – Use after free in Microsoft Office allows an unauthorized attacker to execute co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40361</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40361</strong></p>
  <p>Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40360 – Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40360</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40360</strong></p>
  <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40359 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40359</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40359</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40358 – Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40358</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40358</strong></p>
  <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40357 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40357</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40357</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35439 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35439</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35439</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35436 – Use after free in Microsoft Office allows an authorized attacker to elevate priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35436</guid>
    <pubDate>Tue, 12 May 2026 18:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35436</strong></p>
  <p>Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33112 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33112</guid>
    <pubDate>Tue, 12 May 2026 18:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33112</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33110 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33110</guid>
    <pubDate>Tue, 12 May 2026 18:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33110</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-50993 – Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50993</guid>
    <pubDate>Thu, 30 Apr 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-50993</strong></p>
  <p>Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5756 – Unauthenticated Configuration File Modification Vulnerability in DRC Central Off...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5756</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5756</strong></p>
  <p>Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfiltration, malicious traffic interception, or disruption of testing services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33115 – Use after free in Microsoft Office Word allows an unauthorized attacker to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33115</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33115</strong></p>
  <p>Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33114 – Untrusted pointer dereference in Microsoft Office Word allows an unauthorized at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33114</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33114</strong></p>
  <p>Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33095 – Use after free in Microsoft Office Word allows an unauthorized attacker to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33095</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33095</strong></p>
  <p>Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32200 – Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32200</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32200</strong></p>
  <p>Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32199 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32199</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32199</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32198 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32198</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32198</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32197 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32197</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32197</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32190 – Use after free in Microsoft Office allows an unauthorized attacker to execute co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32190</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32190</strong></p>
  <p>Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32189 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32189</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32189</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32188 – Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32188</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32188</strong></p>
  <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23657 – Use after free in Microsoft Office Word allows an unauthorized attacker to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23657</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23657</strong></p>
  <p>Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34838 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34838</guid>
    <pubDate>Thu, 02 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34838</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directl…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33755 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33755</guid>
    <pubDate>Fri, 27 Mar 2026 15:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33755</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `Contact/query` endpoint allows any authenticated user with basic addressbook access to extract arbitrary data from the database — including active session tokens of other users. This enables full account takeo…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33673 – PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33673</guid>
    <pubDate>Thu, 26 Mar 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33673</strong></p>
  <p>PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix.…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26144 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26144</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26144</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26134 – Integer overflow or wraparound in Microsoft Office allows an authorized attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26134</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26134</strong></p>
  <p>Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26114 – Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26114</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26114</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26113 – Untrusted pointer dereference in Microsoft Office allows an unauthorized attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26113</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26113</strong></p>
  <p>Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26112 – Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26112</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26112</strong></p>
  <p>Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26110 – Access of resource using incompatible type ('type confusion') in Microsoft Offic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26110</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26110</strong></p>
  <p>Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26109 – Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26109</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26109</strong></p>
  <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26108 – Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26108</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26108</strong></p>
  <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26107 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26107</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26107</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26106 – Improper input validation in Microsoft Office SharePoint allows an authorized at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26106</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26106</strong></p>
  <p>Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26105 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26105</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26105</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28046 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28046</guid>
    <pubDate>Thu, 05 Mar 2026 06:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28046</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Law Office law-office allows PHP Local File Inclusion.This issue affects Law Office: from n/a through <= 3.3.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3422 – U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3422</guid>
    <pubDate>Mon, 02 Mar 2026 07:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3422</strong></p>
  <p>U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27947 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27947</guid>
    <pubDate>Fri, 27 Feb 2026 20:21:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27947</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulnerability in the TNEF attachment processing flow. The vulnerable path extracts attacker-controlled files from `winmail.dat` and then invokes `zip` with a shell wildcard (`*`). Because extracted filenames are attacker-cont…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27832 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27832</guid>
    <pubDate>Fri, 27 Feb 2026 20:21:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27832</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, and 6.8.153 have a SQL Injection (SQLi) vulnerability, exploitable through the `advancedQueryData` parameter (`comparator` field) on an authenticated endpoint. The endpoint `index.php?r=email/template/emailSelection` processes `advancedQueryData` and forwards the SQL comparator wi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37203 – Office Product Key Finder 1.5.4 contains a denial of service vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37203</guid>
    <pubDate>Wed, 11 Feb 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37203</strong></p>
  <p>Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21514 – Reliance on untrusted inputs in a security decision in Microsoft Office Word all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21514</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21514</strong></p>
  <p>Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-807</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21511 – Deserialization of untrusted data in Microsoft Office Outlook allows an unauthor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21511</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21511</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21260 – Exposure of sensitive information to an unauthorized actor in Microsoft Office O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21260</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21260</strong></p>
  <p>Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21259 – Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21259</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21259</strong></p>
  <p>Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25512 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25512</guid>
    <pubDate>Wed, 04 Feb 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25512</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (RCE) vulnerability in Group-Office. The endpoint email/message/tnefAttachmentFromTempFile directly concatenates the user-controlled parameter tmp_file into an exec() call. By injecting shell metacharacters into tmp_file, an authentica…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29867 – Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29867</guid>
    <pubDate>Wed, 04 Feb 2026 05:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29867</strong></p>
  <p>Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Hancom Inc. Hancom Office 2018, Hancom Inc. Hancom Office 2020, Hancom Inc. Hancom Office 2022, Hancom Inc. Hancom Office 2024 allows File Content Injection.This issue affects Hancom Office 2018: before 10.0.0.12681; Hancom Office 2020: before 11.0.0.8916; Hancom Office 2022: before 12.0.0.4426; Hancom Office 2024: bef…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25134 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25134</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25134</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip file to achieve remote code execution. This vulnerability is fixed in 6.8.150, 25.0…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21509 – Reliance on untrusted inputs in a security decision in Microsoft Office allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21509</guid>
    <pubDate>Mon, 26 Jan 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21509</strong></p>
  <p>Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-807</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14237 – Buffer overflow in XPS font parse processing on Small Office Multifunction Print...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14237</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14237</strong></p>
  <p>Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14236 – Buffer overflow in Address Book attribute tag processing on Small Office Multifu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14236</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14236</strong></p>
  <p>Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14235 – Buffer overflow in XPS font fpgm data processing on Small Office Multifunction P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14235</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14235</strong></p>
  <p>Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LB…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14234 – Buffer overflow in CPCA list processing on Small Office Multifunction Printers a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14234</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14234</strong></p>
  <p>Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Seri…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14233 – Invalid free in CPCA file deletion processing on Small Office Multifunction Prin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14233</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14233</strong></p>
  <p>Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP23…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-763</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14232 – Buffer overflow in XML processing of XPS file in Small Office Multifunction Prin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14232</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14232</strong></p>
  <p>Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP23…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14231 – Buffer overflow in print job processing by WSD on Small Office Multifunction Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14231</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14231</strong></p>
  <p>Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP2…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-20963 – Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20963</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-20963</strong></p>
  <p>Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20957 – Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20957</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20957</strong></p>
  <p>Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20956 – Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20956</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20956</strong></p>
  <p>Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20955 – Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20955</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20955</strong></p>
  <p>Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20953 – Use after free in Microsoft Office allows an unauthorized attacker to execute co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20953</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20953</strong></p>
  <p>Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20952 – Use after free in Microsoft Office allows an unauthorized attacker to execute co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20952</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20952</strong></p>
  <p>Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20951 – Improper input validation in Microsoft Office SharePoint allows an unauthorized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20951</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20951</strong></p>
  <p>Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20950 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20950</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20950</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20949 – Improper access control in Microsoft Office Excel allows an unauthorized attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20949</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20949</strong></p>
  <p>Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20948 – Untrusted pointer dereference in Microsoft Office Word allows an unauthorized at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20948</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20948</strong></p>
  <p>Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20947 – Improper neutralization of special elements used in an sql command ('sql injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20947</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20947</strong></p>
  <p>Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20946 – Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20946</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20946</strong></p>
  <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20944 – Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20944</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20944</strong></p>
  <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20943 – Untrusted search path in Microsoft Office allows an unauthorized attacker to exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20943</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20943</strong></p>
  <p>Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59683 – Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59683</guid>
    <pubDate>Thu, 25 Dec 2025 05:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59683</strong></p>
  <p>Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14733 – An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14733</guid>
    <pubDate>Fri, 19 Dec 2025 01:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14733</strong></p>
  <p>An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64677 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64677</guid>
    <pubDate>Thu, 18 Dec 2025 22:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64677</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67719 – Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67719</guid>
    <pubDate>Thu, 11 Dec 2025 02:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67719</strong></p>
  <p>Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the validation of the previous password not to run as expected. This makes it possible for a logged in user to change their password in the back office without knowing t…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-620</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64672 – Improper neutralization of input during web page generation ('cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64672</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64672</strong></p>
  <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62564 – Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62564</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62564</strong></p>
  <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62563 – Use after free in Microsoft Office Excel allows an unauthorized attacker to exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62563</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62563</strong></p>
  <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62562 – Use after free in Microsoft Office Outlook allows an unauthorized attacker to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62562</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62562</strong></p>
  <p>Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62561 – Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62561</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62561</strong></p>
  <p>Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62560 – Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62560</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62560</strong></p>
  <p>Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62559 – Use after free in Microsoft Office Word allows an unauthorized attacker to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62559</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62559</strong></p>
  <p>Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62558 – Use after free in Microsoft Office Word allows an unauthorized attacker to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62558</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62558</strong></p>
  <p>Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62557 – Use after free in Microsoft Office allows an unauthorized attacker to execute co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62557</guid>
    <pubDate>Tue, 09 Dec 2025 18:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62557</strong></p>
  <p>Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62557">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
