Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-26144

7.5

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Microsoft
Details

CVE-2026-26141

7.8

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-26134

7.8

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-26132

7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-26131

7.8

Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

Linux
Details

CVE-2026-26130

7.5

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Microsoft
Details

CVE-2026-26128

7.8

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Microsoft
Details

CVE-2026-26127

7.5

Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

Linux
Details

CVE-2026-26121

7.5

Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.

Microsoft
Details

CVE-2026-26118

8.8

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

Microsoft
Details
743/3864