2026 CVE Vulnerabilities
61,503 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45503 | MEDIUM | 6.5 | 0.4% | Jun 9, 2026 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network... |
| CVE-2026-45502 | MEDIUM | 5 | 20.3% | Jun 9, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information ov... |
| CVE-2026-45501 | MEDIUM | 6.1 | 0.3% | Jun 9, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a... |
| CVE-2026-45500 | MEDIUM | 6.1 | 0.4% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows... |
| CVE-2026-45491 | MEDIUM | 5.5 | 0.4% | Jun 9, 2026 | Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tamper... |
| CVE-2026-45490 | HIGH | 7.8 | 0.4% | Jun 9, 2026 | Improper authorization in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-45487 | HIGH | 7 | 0.2% | Jun 9, 2026 | Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attack... |
| CVE-2026-45486 | HIGH | 7.8 | 0.4% | Jun 9, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-45485 | LOW | 3.3 | 0.4% | Jun 9, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-45484 | HIGH | 8.8 | 2.0% | Jun 9, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove... |
| CVE-2026-45483 | MEDIUM | 5.4 | 0.5% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server ... |
| CVE-2026-45482 | HIGH | 8.4 | 0.3% | Jun 9, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code ... |
| CVE-2026-45481 | MEDIUM | 5.4 | 0.7% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-45479 | MEDIUM | 5.4 | 0.5% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-45476 | HIGH | 8.2 | 0.3% | Jun 9, 2026 | Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2026-45475 | HIGH | 7.8 | 0.5% | Jun 9, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-45474 | HIGH | 8.4 | 0.4% | Jun 9, 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-45472 | HIGH | 8.4 | 0.3% | Jun 9, 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-45471 | HIGH | 7.8 | 0.5% | Jun 9, 2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-45469 | HIGH | 7.8 | 0.4% | Jun 9, 2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally... |
| CVE-2026-45468 | MEDIUM | 5.4 | 0.5% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-45467 | MEDIUM | 5.4 | 0.5% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-45466 | LOW | 3.3 | 0.4% | Jun 9, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-45465 | MEDIUM | 5.4 | 0.5% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-45464 | MEDIUM | 5.4 | 0.5% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now