2026 CVE Vulnerabilities

43,877 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-50401MEDIUM5.5Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information local...
CVE-2026-50394MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in...
CVE-2026-50389MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-50383MEDIUM5.5Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-50376MEDIUM6.5Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50374MEDIUM6.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a phys...
CVE-2026-50366MEDIUM6.5Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ...
CVE-2026-50352MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack...
CVE-2026-50341MEDIUM5.5Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-50339MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t...
CVE-2026-50334MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disc...
CVE-2026-50324MEDIUM5.9Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho...
CVE-2026-50310MEDIUM4.7Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information ...
CVE-2026-50302MEDIUM6.5Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security f...
CVE-2026-4018MEDIUM6.4TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local acce...
CVE-2026-49177MEDIUM5.5Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
CVE-2026-48580MEDIUM5.5Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-47969MEDIUM5.5Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attack...
CVE-2026-45067MEDIUM6.3### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply...
CVE-2026-45066MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until...
CVE-2026-45065MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-15757MEDIUM6.3A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send...
CVE-2026-15715MEDIUM4.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i...
CVE-2026-0515MEDIUM6.2Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a cra...
CVE-2026-59888MEDIUM6.5jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now