2026 CVE Vulnerabilities

64,705 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39047HIGH7.5Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Prin...
CVE-2026-8485HIGH7.5Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i...
CVE-2026-8469HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthentic...
CVE-2026-8467CRITICAL9.5Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanit...
CVE-2026-47068LOW2.3Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session P...
CVE-2026-24425CRITICAL9.9Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface ...
CVE-2026-22554HIGH7.8A heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26...
CVE-2026-21836MEDIUM6.5The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, documen...
CVE-2026-5950MEDIUM5.3An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling ...
CVE-2026-5947MEDIUM5.9Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incomi...
CVE-2026-5946HIGH7.5Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`...
CVE-2026-45584HIGH8.1Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
CVE-2026-45498HIGH7.5Microsoft Defender Denial of Service Vulnerability
CVE-2026-45443MEDIUM5Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Explo...
CVE-2026-42834HIGH7.8Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-42383HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooComme...
CVE-2026-41091HIGH7.8Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to el...
CVE-2026-3593CRITICAL9.8A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20....
CVE-2026-3592MEDIUM5.3BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a quer...
CVE-2026-3039HIGH7.5BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory ...
CVE-2026-29518HIGH7Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that ...
CVE-2026-27424MEDIUM4.3Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Confi...
CVE-2026-27405MEDIUM6.5Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-24573MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualiz...
CVE-2026-25602LOW2.3Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server)...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now