2026 CVE Vulnerabilities

61,503 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45503MEDIUM6.5Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network...
CVE-2026-45502MEDIUM5Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information ov...
CVE-2026-45501MEDIUM6.1Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a...
CVE-2026-45500MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows...
CVE-2026-45491MEDIUM5.5Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tamper...
CVE-2026-45490HIGH7.8Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-45487HIGH7Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attack...
CVE-2026-45486HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45485LOW3.3Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45484HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove...
CVE-2026-45483MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server ...
CVE-2026-45482HIGH8.4Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code ...
CVE-2026-45481MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45479MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45476HIGH8.2Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-45475HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45474HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45472HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45471HIGH7.8Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45469HIGH7.8Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally...
CVE-2026-45468MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45467MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45466LOW3.3Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-45465MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45464MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now