2026 CVE Vulnerabilities

43,188 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-61936MEDIUM5.5Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature lo...
CVE-2026-61933MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-61928MEDIUM5.5Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
CVE-2026-61924MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61921MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61920MEDIUM6.6Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut...
CVE-2026-61918MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61368MEDIUM5Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-61360MEDIUM5.5Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-61350MEDIUM4.6Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-61347MEDIUM5.5Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVE-2026-61345MEDIUM6.5Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo...
CVE-2026-59138MEDIUM6.5Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo...
CVE-2026-59137MEDIUM5.5Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc...
CVE-2026-59136MEDIUM5.5Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally...
CVE-2026-59135MEDIUM5.5Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CVE-2026-59131MEDIUM5.6No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
CVE-2026-59130MEDIUM5.6No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
CVE-2026-59128MEDIUM5.5Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally...
CVE-2026-58639MEDIUM6.5Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over...
CVE-2026-57105MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-54123MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attac...
CVE-2026-48483MEDIUM5.4TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp...
CVE-2026-48446MEDIUM5.5CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
CVE-2026-48445MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now