Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 452/454
7.0
CVE-2026-50672

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50674

Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-56173

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-56183

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-56187

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-57093

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2026-58544

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-58619

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-58629

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-58637

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50526

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tamperin

7.0
CVE-2026-54684

jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlle

7.0
CVE-2026-9046

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications

7.0
CVE-2026-60063

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt

7.0
CVE-2026-61389

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt

7.0
CVE-2026-53410

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl

7.0
CVE-2026-58598

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all

7.0
CVE-2026-46999

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery

7.0
CVE-2026-60494

Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation).

7.0
CVE-2026-60705

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

7.0
CVE-2026-60833

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affe

7.0
CVE-2026-61061

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported v

7.0
CVE-2026-61120

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

7.0
CVE-2026-16584

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to

7.0
CVE-2026-64219

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_i

7.0
CVE-2026-64222

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on A

7.0
CVE-2026-64283

In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Treat memslot binding offset+size

7.0
CVE-2026-64315

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - use print_hex_dump_devel to guard ke

7.0
CVE-2026-64413

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko

7.0
CVE-2026-64420

In the Linux kernel, the following vulnerability has been resolved: mfd: cros_ec: Delay dev_set_drvdata() until probe s

7.0
CVE-2026-64460

In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Skip VF Resizable BAR restore on read erro

7.0
CVE-2026-64510

In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix acpi_nfit_init() error cleanu

7.0
CVE-2026-28926

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1

7.0
CVE-2026-43693

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1

7.0
CVE-2026-43755

A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 2

7.0
CVE-2026-16184

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafte

7.0
CVE-2026-40272

Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted k

7.0
CVE-2026-17993

Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalat

7.0
CVE-2026-67326

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attac

7.0
CVE-2026-10848

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j

7.0
CVE-2026-69097

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitra

7.0
CVE-2026-18605

A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library A

7.0
CVE-2026-18718

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exe

7.0
CVE-2026-64587

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before

7.0
CVE-2026-70640

llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrap

7.0
CVE-2026-58230

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att

7.0
CVE-2026-50472

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-59122

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.0
CVE-2026-59125

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-59126

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Ser

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started