2026 CVE Vulnerabilities

61,397 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34695HIGH7.8InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that coul...
CVE-2026-34694MEDIUM4.8Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting ...
CVE-2026-34693HIGH8Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripti...
CVE-2026-34691CRITICAL9.3Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting ...
CVE-2026-28237MEDIUM5.5Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially lead...
CVE-2026-0466MEDIUM5.5Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memor...
CVE-2026-9213HIGH8.1A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with tr...
CVE-2026-9212HIGH8Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network...
CVE-2026-9211HIGH8.8An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operati...
CVE-2026-9210MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-9076HIGH7.5Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an ...
CVE-2026-7383HIGH8.1Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() ...
CVE-2026-50508HIGH7.5Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp...
CVE-2026-50507MEDIUM6.8Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security f...
CVE-2026-49959HIGH8.8Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers ...
CVE-2026-49958MEDIUM5Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the g...
CVE-2026-49957HIGH7.7Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attack...
CVE-2026-49956HIGH7.1Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users t...
CVE-2026-49955MEDIUM6.9Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote att...
CVE-2026-49848MEDIUM4.3FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49847HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49843MEDIUM5.3FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49842HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49841CRITICAL9.8FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49840CRITICAL9.1FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now