Total CVEs

131,648

Critical Severity

2,801

High Severity

10,044

Last 7 Days

1,241
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,801 - 2,820 of 28,053 CVEs
CVE-2026-41613 HIGH - 8.8

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: visual_studio_code
Published: May 12, 2026
Source: NVD
CVE-2026-41612 MEDIUM - 5.5

Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.

Vendor: microsoft
Product: live_preview
Published: May 12, 2026
Source: NVD
CVE-2026-41611 HIGH - 7.8

Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.

Vendor: microsoft
Product: visual_studio_code
Published: May 12, 2026
Source: NVD
CVE-2026-41610 MEDIUM - 6.3

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: visual_studio_code
Published: May 12, 2026
Source: NVD

Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-engineering redirects.

Vendor: horilla
Product: horilla-hr
Published: May 12, 2026
Source: NVD
CVE-2026-41109 HIGH - 8.8

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.

Vendor: microsoft
Product: visual_studio_code
Published: May 12, 2026
Source: NVD
CVE-2026-41107 HIGH - 7.4

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 12, 2026
Source: NVD
CVE-2026-41103 CRITICAL - 9.1

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: confluence_saml_sso
Published: May 12, 2026
Source: NVD
CVE-2026-41102 HIGH - 7.1

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

Vendor: microsoft
Product: powerpoint
Published: May 12, 2026
Source: NVD
CVE-2026-41101 HIGH - 7.1

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

Vendor: microsoft
Product: word
Published: May 12, 2026
Source: NVD
CVE-2026-41100 MEDIUM - 4.4

Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

Vendor: microsoft
Product: 365_copilot
Published: May 12, 2026
Source: NVD
CVE-2026-41097 MEDIUM - 6.7

Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1809
Published: May 12, 2026
Source: NVD
CVE-2026-41096 CRITICAL - 9.8

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_11_23h2
Published: May 12, 2026
Source: NVD
CVE-2026-41095 HIGH - 7.8

Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_server_2012
Published: May 12, 2026
Source: NVD
CVE-2026-41094 HIGH - 8.8

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: data_formulator
Published: May 12, 2026
Source: NVD
CVE-2026-41089 CRITICAL - 9.8

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_server_2012
Published: May 12, 2026
Source: NVD
CVE-2026-41088 HIGH - 7.8

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_21h2
Published: May 12, 2026
Source: NVD
CVE-2026-41086 HIGH - 8.8

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: windows_admin_center
Published: May 12, 2026
Source: NVD
CVE-2026-40421 MEDIUM - 4.3

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: 365_apps
Published: May 12, 2026
Source: NVD
CVE-2026-40420 HIGH - 8.8

Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: 365_apps
Published: May 12, 2026
Source: NVD