CVE Database

Comprehensive vulnerability intelligence with advanced analytics

6.4

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating…

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.18%
View Details
7.8

Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft azure_connected_machine_agent
EPSS: 0.05%
View Details
7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.04%
View Details
7.0

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
EPSS: 0.05%
View Details
7.5

Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
EPSS: 0.04%
View Details
8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft sharepoint_server
EPSS: 0.56%
View Details
4.4

Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.11%
View Details
4.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft sharepoint_server
EPSS: 0.04%
View Details
5.4

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft sharepoint_server
EPSS: 0.05%
View Details
7.8

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.05%
View Details
7.8

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.04%
View Details
7.8

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.04%
View Details
8.4

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.03%
View Details
8.4

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.03%
View Details
7.8

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft sharepoint_server
EPSS: 0.10%
View Details
7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.04%
View Details
7.8

Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.03%
View Details
7.8

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.04%
View Details
8.8

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft sharepoint_server
EPSS: 0.08%
View Details
7.8

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.04%
View Details
8.4

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft office_long_term_servicing_channel
EPSS: 0.03%
View Details
7.0

Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft office
EPSS: 0.07%
View Details
7.8

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.05%
View Details
7.8

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_11_23h2
EPSS: 0.04%
View Details