2026 CVE Vulnerabilities

46,942 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-45658MEDIUM6.8Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
CVE-2026-45655MEDIUM5.3Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph...
CVE-2026-45650MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perfo...
CVE-2026-45634MEDIUM5.5Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
CVE-2026-45608MEDIUM6.8Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
CVE-2026-45606MEDIUM5.5Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
CVE-2026-45604MEDIUM5.5Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informati...
CVE-2026-45595MEDIUM5.4Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feat...
CVE-2026-45594MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an a...
CVE-2026-45503MEDIUM6.5Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network...
CVE-2026-45502MEDIUM5Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information ov...
CVE-2026-45501MEDIUM6.1Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a...
CVE-2026-45500MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows...
CVE-2026-45491MEDIUM5.5Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tamper...
CVE-2026-45483MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server ...
CVE-2026-45481MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45479MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45468MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45467MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45465MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45464MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45462MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-45460MEDIUM4.7Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45455MEDIUM4.3Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-45453MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now