2026 CVE Vulnerabilities

64,935 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-77491MEDIUM5.5Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVE-2026-77488MEDIUM5.5Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
CVE-2026-73029MEDIUM6.5Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-73019MEDIUM4.3Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feat...
CVE-2026-73008MEDIUM5.5Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized atta...
CVE-2026-73004MEDIUM5.5Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering loc...
CVE-2026-72999MEDIUM6.8Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attac...
CVE-2026-72985MEDIUM6.8Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a ph...
CVE-2026-72980MEDIUM5.5Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
CVE-2026-72977MEDIUM6.5Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network...
CVE-2026-72976MEDIUM5Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.
CVE-2026-72975MEDIUM6.5Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network...
CVE-2026-72974MEDIUM6.5Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-72966MEDIUM5.5Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering loc...
CVE-2026-72964MEDIUM5.5Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker ...
CVE-2026-72956MEDIUM6.5Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information ove...
CVE-2026-72945MEDIUM5.5Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
CVE-2026-72942MEDIUM6.5Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.
CVE-2026-72939MEDIUM6.5Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny servi...
CVE-2026-72938MEDIUM6.5Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized atta...
CVE-2026-72937MEDIUM5.5Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
CVE-2026-72935MEDIUM6.7Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-72931MEDIUM5.5Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an author...
CVE-2026-71350MEDIUM6.8Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical atta...
CVE-2026-71349MEDIUM6.8Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical atta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now