57,566 vulnerabilities published in 2026
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a net
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netwo
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a networ
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate pri
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allo
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a networ
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execu
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context o
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code insi
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code ins
libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shel
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range
In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns fo
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using
Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository,
RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started