2026 CVE Vulnerabilities

59,273 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12252HIGH7.8In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, Stanford...
CVE-2026-54424HIGH8.4An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri...
CVE-2026-58523MEDIUM6.5Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over ...
CVE-2026-14617LOW3.1A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function Gatewa...
CVE-2026-58597MEDIUM4.3Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to pe...
CVE-2026-58524MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ...
CVE-2026-58522MEDIUM6.8Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-58426CRITICAL9.6Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state w...
CVE-2026-58424HIGH8.9Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-58423HIGH7.7LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-58422CRITICAL9.8Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58421HIGH7.5Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-58419HIGH7.5Notification API leaks private issue metadata after access revocation
CVE-2026-58418MEDIUM6.5SSRF via HTTP Redirect in Repository Migration
CVE-2026-58300MEDIUM6.2Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-58299HIGH7.5Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execu...
CVE-2026-58298MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ...
CVE-2026-58297HIGH7.1Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a...
CVE-2026-58296HIGH7.1Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a...
CVE-2026-58295HIGH8.3Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-58294HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-58293HIGH7.5External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code...
CVE-2026-58292HIGH7.5Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw...
CVE-2026-58291MEDIUM6.1Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t...
CVE-2026-58290HIGH7.5Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now