CVE-2026-73029 Microsoft SQL Server Information Disclosure Vulnerability
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-73029 Microsoft US
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-73029 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-68786 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67643 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67636 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78518 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67389 Microsoft US
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78509 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78517 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78504 Microsoft US
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
EPSS 0.01 CVE-2026-78513 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78510 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78505 Microsoft US
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78515 Microsoft US
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-78502 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78511 Microsoft US
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67384 Microsoft US
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67383 Microsoft US
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67379 Microsoft US
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-67376 Microsoft US
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67378 Microsoft US
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-78439 Microsoft US
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77908 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-77898 Microsoft US
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69282 Microsoft US
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69273 Microsoft US
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69285 Microsoft US
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69268 Microsoft US
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77504 Microsoft US
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77493 Microsoft US
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69804 Microsoft US
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69797 Microsoft US
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69767 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69778 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69764 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69759 Microsoft US
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69529 Microsoft US
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69683 Microsoft US
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69739 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-69690 Microsoft US
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69719 Microsoft US
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69724 Microsoft US
Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69742 Microsoft US
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69734 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69716 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69722 Microsoft US
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69686 Microsoft US
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69678 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69671 Microsoft US
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69641 Microsoft US
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69556 Microsoft US
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-69382 Microsoft US
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69380 Microsoft US
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-69378 Microsoft US
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
EPSS 0.01 CVE-2026-69375 Microsoft US
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-69361 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-69356 Microsoft US
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69355 Microsoft US
Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-72946 Microsoft US
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-70351 Microsoft US
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58600 Microsoft US