2026 CVE Vulnerabilities

43,090 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-64897MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-63531MEDIUM5.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-63530MEDIUM5.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-63529MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-63528MEDIUM5.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-63524MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-63521MEDIUM5.5Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-63517MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-63516MEDIUM6.5Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over ...
CVE-2026-63512MEDIUM6.5Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network...
CVE-2026-62917MEDIUM4.6Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ...
CVE-2026-62915MEDIUM6.5Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net...
CVE-2026-62912MEDIUM6.5Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw...
CVE-2026-62902MEDIUM6.5Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information...
CVE-2026-62900MEDIUM5.9Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose...
CVE-2026-62899MEDIUM5.9Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker...
CVE-2026-62887MEDIUM5.5Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62883MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62882MEDIUM4.3Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove...
CVE-2026-62881MEDIUM6.7Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62842MEDIUM5.5Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-62839MEDIUM6.5Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov...
CVE-2026-62837MEDIUM6.5Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a netw...
CVE-2026-62829MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-62814MEDIUM6.5Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now