2026 CVE Vulnerabilities

46,854 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54981HIGH7.8Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized...
CVE-2026-54123MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attac...
CVE-2026-54113HIGH7.5Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o...
CVE-2026-50516CRITICAL9.4Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el...
CVE-2026-50472HIGH7Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CVE-2026-49179HIGH8.8Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows a...
CVE-2026-48483MEDIUM5.4TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp...
CVE-2026-48446MEDIUM5.5CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
CVE-2026-48445MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-48444MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-48443MEDIUM6.2CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application...
CVE-2026-48442HIGH7.1CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
CVE-2026-48440HIGH8.1ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in th...
CVE-2026-48439HIGH7.5CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application...
CVE-2026-48438HIGH7.5CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application deni...
CVE-2026-48437MEDIUM5.5CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security ...
CVE-2026-48436MEDIUM6.5CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur...
CVE-2026-48435MEDIUM6.2CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a...
CVE-2026-48434MEDIUM6.2CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application...
CVE-2026-48387MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-48386HIGH7.5ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure...
CVE-2026-48385HIGH7.7ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') ...
CVE-2026-48384MEDIUM4.9ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-servi...
CVE-2026-48376MEDIUM5.4is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. ...
CVE-2026-48375MEDIUM6.5ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now