CVE-2026-45454
CVE-2026-45454 is a path traversal vulnerability in Microsoft Office SharePoint. An authorized attacker can exploit this vulnerability to execute code over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM.
These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-45454 is a path traversal vulnerability in Microsoft Office SharePoint. An authorized attacker can exploit this vulnerability to execute code over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM.
CVE-2026-44824 is a high-severity vulnerability in Microsoft Office that allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS v3.1 score of 7.8 and is classified as HIGH. It was published on June 9, 2026, and last modified on June 11, 2026.
CVE-2026-44823 is a high-severity vulnerability in Microsoft Office Excel that allows unauthorized attackers to execute code locally via an integer underflow. The vulnerability has a CVSS score of 7.8 and was published on June 9, 2026. It affects various versions of Microsoft Office, including Office 2016, Office 2019, Office 2021, and Office 2024, as well as Microsoft 365 Apps. The vulnerability can be e [truncated]
CVE-2026-44822 is a high-severity vulnerability in Microsoft Office Excel that can be exploited by an unauthorized attacker to disclose sensitive information over a network. The vulnerability has a CVSS score of 8.2 and is classified as CWE-125.
CVE-2026-44821 is an out-of-bounds read vulnerability in Microsoft Office that allows an unauthorized attacker to disclose information locally. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. It was published on 2026-06-09T17:17:18.443Z and modified on 2026-06-11T18:40:00.750Z.
CVE-2026-44820 is a HIGH-severity vulnerability in Microsoft Office Excel, with a CVSS score of 7.8. The vulnerability is caused by an integer underflow (wrap or wraparound) and allows an unauthorized attacker to execute code locally. The vulnerability was published on 2026-06-09T17:17:18.313Z and last modified on 2026-06-11T18:38:16.130Z.
CVE-2026-44819 is a high-severity vulnerability in Microsoft Office that allows an unauthorized attacker to execute code locally. The vulnerability has a CVSS v3.1 score of 7.8 and is classified as HIGH. It was published on June 9, 2026, and last modified on June 11, 2026.
CVE-2026-44818 is a HIGH-severity vulnerability in Microsoft Office Excel, with a CVSS score of 7. The vulnerability is caused by an integer underflow (wrap or wraparound) and allows an unauthorized attacker to execute code locally. The vulnerability was published on 2026-06-09T17:17:18.040Z and modified on 2026-06-11T18:38:18.510Z.
CVE-2026-44817 is a HIGH severity vulnerability in Microsoft Office Excel. An integer underflow (or, wrap/wraparound) vulnerability exists, which could allow an unauthorized attacker to execute code locally. The vulnerability has a CVSS score of 7.8 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-44817).
CVE-2026-44815 is a critical vulnerability in the Windows DHCP Client that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. It was published on 2026-06-09T17:17:17.717Z and modified on 2026-06-11T17:35:59.970Z.
CVE-2026-44812 is a high-severity vulnerability in Windows Win32K - GRFX that allows local code execution. Published on June 9, 2026, and modified on June 17, 2026, this vulnerability has a CVSS score of 7.8. It is caused by an integer overflow or wraparound in the Windows Win32K - GRFX component. An unauthorized attacker can exploit this vulnerability to execute code locally. Multiple Windows versions an [truncated]
CVE-2026-44810 is a HIGH-severity vulnerability in Windows Cryptographic Services, with a CVSS score of 8.4. The vulnerability allows an unauthorized attacker to elevate privileges locally due to improper authentication. The CVE was published on 2026-06-09T17:17:17.013Z and last modified on 2026-06-11T17:13:17.257Z.
CVE-2026-44809 is a HIGH severity vulnerability in the Windows Common Log File System Driver. The vulnerability is caused by a use-after-free issue, which allows an authorized attacker to elevate privileges locally. The CVSS score for this vulnerability is 7.8.
CVE-2026-44805 is a use-after-free vulnerability in the Windows Network Controller (NC) Host Agent. An authorized attacker can exploit this vulnerability locally to deny service. The vulnerability has a CVSS score of 5.5 and a severity rating of MEDIUM. It was published on 2026-06-09T17:17:16.480Z and modified on 2026-06-11T18:55:54.507Z.
CVE-2026-44802 is a use-after-free vulnerability in the Windows DWM Core Library. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability was published on [cvePublishedAt]2026-06-09T17:17:16.010Z[/cvePublishedAt] and last modified on [cveModifiedAt]2026-06-12T17:05:08.167Z[/cveModifiedAt].
CVE-2026-44801 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. It was published on 2026-06-09T17:17:15.827Z and modified on 2026-06-12T17:20:04.780Z.
CVE-2026-44799 is a heap-based buffer overflow vulnerability in Microsoft Remote Desktop Client. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. An unauthorized attacker can exploit this vulnerability to execute code over a network.
CVE-2026-42993 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability is caused by a heap-based buffer overflow and has a CVSS score of 7.5.
CVE-2026-42992 is a high-severity vulnerability in the Remote Desktop Client, allowing unauthorized attackers to execute code over a network. The vulnerability is caused by a heap-based buffer overflow and has a CVSS score of 7.5.
CVE-2026-42991 is a HIGH-severity vulnerability (CVSS Score: 7.8) in Windows Push Notifications, allowing an authorized attacker to elevate privileges locally due to a race condition. The vulnerability was published on 2026-06-09 and last modified on 2026-06-11.
CVE-2026-42989 is a HIGH-severity vulnerability in Microsoft Windows, with a CVSS score of 7.8. The vulnerability is caused by improper link resolution before file access, also known as 'link following,' in the Winlogon component. This allows an authorized attacker to elevate privileges locally. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.
CVE-2026-42987 is a HIGH severity vulnerability in Windows Deployment Services that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.1 and was published on 2026-06-09T17:17:14.853Z. The vulnerability was modified on 2026-06-11T15:46:16.010Z. The affected products include Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windo [truncated]
CVE-2026-42986 is a HIGH severity vulnerability in Microsoft Graphics Component. An authorized attacker can exploit this vulnerability locally to elevate their privileges. The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:14.683Z. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server.
CVE-2026-42985 is a high-severity vulnerability in the Remote Desktop Client that allows an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. It was published on 2026-06-09T17:17:14.500Z and modified on 2026-06-15T20:15:51.050Z.
CVE-2026-42984 is a high-severity vulnerability in the Windows Kernel that allows an authorized attacker to elevate privileges locally. This use-after-free vulnerability has a CVSS score of 7 and a CVSS severity of HIGH. The vulnerability was published on 2026-06-09T17:17:14.347Z and modified on 2026-06-10T19:37:03.870Z.
CVE-2026-42983 is a use-after-free vulnerability in the Windows DWM Core Library. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. An authorized attacker can exploit this vulnerability locally to elevate privileges.
CVE-2026-42981 is a HIGH severity vulnerability in Windows Performance Monitor that allows an unauthorized attacker to execute code over a network. The vulnerability is caused by an integer underflow (wrap or wraparound) and has a CVSS score of 8.1.
CVE-2026-42980 is a HIGH-severity vulnerability in the Windows NT OS Kernel. An authorized attacker can exploit this integer underflow (wrap or wraparound) vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8.
CVE-2026-42979 is a HIGH-severity vulnerability in Windows Push Notifications that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and was published on 2026-06-09T17:17:13.697Z. The vulnerability was modified on 2026-06-11T17:00:05.750Z.
CVE-2026-42978 is a high-severity elevation of privilege vulnerability in Windows Push Notifications. An authorized attacker could exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as CWE-362 and CWE-416.