2026 CVE Vulnerabilities

43,880 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-58647MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized at...
CVE-2026-58614MEDIUM5.5Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
CVE-2026-58279MEDIUM6.5Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-57976MEDIUM6.5Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ...
CVE-2026-57097MEDIUM6.8Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical atta...
CVE-2026-56185MEDIUM6.5Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
CVE-2026-55003MEDIUM6.5Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-55000MEDIUM6.4Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-54997MEDIUM5.5Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
CVE-2026-54988MEDIUM6.1Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-54432MEDIUM4.7Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus...
CVE-2026-54132MEDIUM6.8Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attac...
CVE-2026-54108MEDIUM6.5External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing o...
CVE-2026-50381MEDIUM5.5Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized...
CVE-2026-50350MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authori...
CVE-2026-50316MEDIUM5.5Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information...
CVE-2026-50303MEDIUM5.5Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypas...
CVE-2026-50300MEDIUM5.5Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50299MEDIUM6.8Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a p...
CVE-2026-50298MEDIUM6.8Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a phy...
CVE-2026-50295MEDIUM5.5Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locall...
CVE-2026-50294MEDIUM6.2Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized atta...
CVE-2026-49807MEDIUM6.2Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclos...
CVE-2026-49804MEDIUM6.6Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a phys...
CVE-2026-49801MEDIUM5.5Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now