57,566 vulnerabilities published in 2026
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templit
MacroHub developed by GIGABYTE has a Local Privilege Escalation vulnerability. Due to the MacroHub application launching
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious bi
PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a cr
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512).
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper mo
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All version
A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP ser
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an una
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pri
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privilege
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
Audition versions 25.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary c
After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr
After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary co
After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resul
After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file,
After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary co
After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file,
After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file,
After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary co
After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr
After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr
After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary co
After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion')
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul
After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary co
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started