2026 CVE Vulnerabilities

43,882 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-49799MEDIUM6.5Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized att...
CVE-2026-49794MEDIUM4.6Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat...
CVE-2026-49180MEDIUM5.5Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize...
CVE-2026-49174MEDIUM6.1Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering...
CVE-2026-49168MEDIUM6.8Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges wi...
CVE-2026-47282MEDIUM6.5Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos...
CVE-2026-45496MEDIUM5.5Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthori...
CVE-2026-41087MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-40422MEDIUM5.5Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-36214MEDIUM6.4osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable...
CVE-2026-34349MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in...
CVE-2026-34348MEDIUM6.5Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over...
CVE-2026-34346MEDIUM5.5Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized at...
CVE-2026-34328MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to dis...
CVE-2026-33842MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-15702MEDIUM6.3A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file co...
CVE-2026-15700MEDIUM4.7A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th...
CVE-2026-14646MEDIUM4.9Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets re...
CVE-2026-14645MEDIUM5.1Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making ...
CVE-2026-9108MEDIUM5.4A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths withi...
CVE-2026-7494MEDIUM5.3Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A use...
CVE-2026-62642MEDIUM6.5In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma...
CVE-2026-62641MEDIUM6.5In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft...
CVE-2026-60119MEDIUM5.4Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event cre...
CVE-2026-60118MEDIUM6.9Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now