Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 243/436
5.5
CVE-2026-50455

Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose informatio

5.5
CVE-2026-50456

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-50473

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-50475

Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.

5.5
CVE-2026-50483

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker

5.5
CVE-2026-50681

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack

5.5
CVE-2026-50690

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

5.5
CVE-2026-55023

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55027

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55028

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55035

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55042

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55046

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55047

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55050

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55057

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55121

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55124

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose info

5.5
CVE-2026-55138

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55139

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55142

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-56178

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el

5.5
CVE-2026-56184

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose i

5.5
CVE-2026-56192

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-56195

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-57083

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informatio

5.5
CVE-2026-57084

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-57085

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

5.5
CVE-2026-58545

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

5.5
CVE-2026-58547

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges loc

5.5
CVE-2026-47979

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An a

5.5
CVE-2026-48353

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst

5.5
CVE-2026-11580

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capab

5.5
CVE-2026-20146

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a

5.5
CVE-2026-49988

Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_

5.5
CVE-2026-62361

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib

5.5
CVE-2026-12979

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t

5.5
CVE-2026-9494

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The cli

5.5
CVE-2026-56453

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter

5.5
CVE-2026-45612

rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can

5.5
CVE-2026-50012

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli

5.5
CVE-2026-6511

During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart

5.5
CVE-2026-61378

A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to

5.5
CVE-2026-15943

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The is

5.5
CVE-2026-15415

AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure

5.5
CVE-2026-7771

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted stat

5.5
CVE-2026-57848

Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the devic

5.5
CVE-2026-53367

In the Linux kernel, the following vulnerability has been resolved: selinux: fix avdcache auditing The per-task avdcac

5.5
CVE-2026-53370

In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Improve validation and configuratio

5.5
CVE-2026-53371

In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: bound node_desc sysfs read with %.64s

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started