|
941
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-47287
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
New
|
CWE-200
Information Exposure
|
CVE-2026-47284
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-306 CWE-798 CWE-862
Missing Authentication for Critical Function Use of Hard-coded Credentials Missing Authorization
|
CVE-2026-47281
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
7.2 |
HIGH
Network
|
-
|
-
|
md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When u…
New
|
CWE-80 CWE-87
Basic XSS Improper Neutralization of Alternate XSS Syntax
|
CVE-2026-46492
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
4.3 |
MEDIUM
Network
|
-
|
-
|
User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-45650
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
7.1 |
HIGH
Local
|
-
|
-
|
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-45649
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-45647
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-45645
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
8.0 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45644
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
7.5 |
HIGH
Network
|
-
|
-
|
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45639
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|