2026 CVE Vulnerabilities

64,922 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-66308MEDIUM6.5Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-66306MEDIUM6.5Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to di...
CVE-2026-66303MEDIUM6.5Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-63523MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an una...
CVE-2026-55256MEDIUM6.5In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation...
CVE-2026-45527MEDIUM4.3In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service d...
CVE-2026-28633MEDIUM5.5In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to ...
CVE-2026-28627MEDIUM4.3In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This cou...
CVE-2026-28617MEDIUM5.5In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could ...
CVE-2026-28596MEDIUM5.5In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource ...
CVE-2026-28584MEDIUM5.5In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a...
CVE-2026-9215MEDIUM6.7A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage socia...
CVE-2026-86672MEDIUM5.3A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. A...
CVE-2026-85875MEDIUM5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-83991MEDIUM5.5Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to ...
CVE-2026-83951MEDIUM5.5Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-83949MEDIUM5.5Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-83501MEDIUM5.5Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose info...
CVE-2026-81958MEDIUM5.5Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81824MEDIUM4.7The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMB...
CVE-2026-81823MEDIUM5.3The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for P...
CVE-2026-81401MEDIUM5.5Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ...
CVE-2026-81400MEDIUM5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81399MEDIUM5.5Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81395MEDIUM5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now