57,566 vulnerabilities published in 2026
Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DP
Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC)
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vul
The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory.
Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the
Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The
Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privil
A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the I
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber P
The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution thro
The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is dir
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to o
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExe
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administr
In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() T
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally
Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinu
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an a
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locall
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.
Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privil
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate priv
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized att
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary c
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started