57,566 vulnerabilities published in 2026
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code ov
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker t
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges ove
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Com
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate priv
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netwo
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate p
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a ne
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privile
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a net
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an au
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a netw
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges lo
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a ne
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over
Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitra
Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute synta
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started