57,566 vulnerabilities published in 2026
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose informatio
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose info
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose i
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informatio
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges loc
Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An a
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capab
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a
Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib
The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The cli
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter
rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli
During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart
A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to
A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The is
AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted stat
Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the devic
In the Linux kernel, the following vulnerability has been resolved: selinux: fix avdcache auditing The per-task avdcac
In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Improve validation and configuratio
In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: bound node_desc sysfs read with %.64s
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started