2026 CVE Vulnerabilities

61,548 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34180HIGH7.5Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes ...
CVE-2026-33828HIGH7.8Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
CVE-2026-33113MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-32193HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all...
CVE-2026-28301MEDIUM4.8A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit...
CVE-2026-26142CRITICAL9.8Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
CVE-2026-24181HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes...
CVE-2026-24180HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes...
CVE-2026-22926HIGH7.8Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
CVE-2026-0420MEDIUM5.9An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co...
CVE-2026-0419HIGH8Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u...
CVE-2026-0418MEDIUM4.5Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n...
CVE-2026-0417MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected ...
CVE-2026-0416MEDIUM4.5An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini...
CVE-2026-0415MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-0414MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-0413MEDIUM4.5A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated a...
CVE-2026-0412MEDIUM4.5Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in ...
CVE-2026-0411HIGH8An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected...
CVE-2026-0410MEDIUM4.5Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorize...
CVE-2026-0409MEDIUM6.4A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the rout...
CVE-2026-8045MEDIUM6.5CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu...
CVE-2026-8025CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information T...
CVE-2026-49948HIGH8.6Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted s...
CVE-2026-49938MEDIUM6.5A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, Fo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now