2026 CVE Vulnerabilities
43,882 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49799 | MEDIUM | 6.5 | 0.8% | Jul 14, 2026 | Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized att... |
| CVE-2026-49794 | MEDIUM | 4.6 | 0.3% | Jul 14, 2026 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat... |
| CVE-2026-49180 | MEDIUM | 5.5 | 0.3% | Jul 14, 2026 | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize... |
| CVE-2026-49174 | MEDIUM | 6.1 | 0.2% | Jul 14, 2026 | Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering... |
| CVE-2026-49168 | MEDIUM | 6.8 | 0.3% | Jul 14, 2026 | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges wi... |
| CVE-2026-47282 | MEDIUM | 6.5 | 0.6% | Jul 14, 2026 | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos... |
| CVE-2026-45496 | MEDIUM | 5.5 | 0.5% | Jul 14, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthori... |
| CVE-2026-41087 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis... |
| CVE-2026-40422 | MEDIUM | 5.5 | 0.3% | Jul 14, 2026 | Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
| CVE-2026-36214 | MEDIUM | 6.4 | 0.3% | Jul 14, 2026 | osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable... |
| CVE-2026-34349 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in... |
| CVE-2026-34348 | MEDIUM | 6.5 | 0.7% | Jul 14, 2026 | Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over... |
| CVE-2026-34346 | MEDIUM | 5.5 | 0.2% | Jul 14, 2026 | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized at... |
| CVE-2026-34328 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to dis... |
| CVE-2026-33842 | MEDIUM | 5.5 | 0.4% | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis... |
| CVE-2026-15702 | MEDIUM | 6.3 | 0.3% | Jul 14, 2026 | A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file co... |
| CVE-2026-15700 | MEDIUM | 4.7 | 0.4% | Jul 14, 2026 | A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th... |
| CVE-2026-14646 | MEDIUM | 4.9 | 0.3% | Jul 14, 2026 | Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets re... |
| CVE-2026-14645 | MEDIUM | 5.1 | 0.4% | Jul 14, 2026 | Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making ... |
| CVE-2026-9108 | MEDIUM | 5.4 | — | Jul 14, 2026 | A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths withi... |
| CVE-2026-7494 | MEDIUM | 5.3 | 0.1% | Jul 14, 2026 | Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A use... |
| CVE-2026-62642 | MEDIUM | 6.5 | 0.3% | Jul 14, 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma... |
| CVE-2026-62641 | MEDIUM | 6.5 | 0.2% | Jul 14, 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft... |
| CVE-2026-60119 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event cre... |
| CVE-2026-60118 | MEDIUM | 6.9 | 0.2% | Jul 14, 2026 | Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now