2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-64918MEDIUM6.5Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a netw...
CVE-2026-62801MEDIUM6.5Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthori...
CVE-2026-62762MEDIUM6.5Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ...
CVE-2026-58649MEDIUM6.5Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-54611MEDIUM5.5InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (R...
CVE-2026-86668MEDIUM4.3A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function u...
CVE-2026-86667MEDIUM4.7A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list o...
CVE-2026-84391MEDIUM6.5A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial...
CVE-2026-84386MEDIUM5.1A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all vers...
CVE-2026-84385MEDIUM5.4A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5...
CVE-2026-82076MEDIUM6.5An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary data...
CVE-2026-82074MEDIUM6.5MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user wit...
CVE-2026-82073MEDIUM6.5A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges t...
CVE-2026-82070MEDIUM6.5A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privile...
CVE-2026-82069MEDIUM6.5A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privilege...
CVE-2026-82068MEDIUM6.5A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal asse...
CVE-2026-82065MEDIUM6.5A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection c...
CVE-2026-82063MEDIUM5.3A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cau...
CVE-2026-82062MEDIUM5.5A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled f...
CVE-2026-82060MEDIUM5.4In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store d...
CVE-2026-82059MEDIUM6.5An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user ...
CVE-2026-82058MEDIUM6.5A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges ...
CVE-2026-82057MEDIUM6.5A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod ...
CVE-2026-82056MEDIUM5.3A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert ...
CVE-2026-82055MEDIUM6.5A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer d...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now