2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23820HIGH7.2A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authentic...
CVE-2026-23819HIGH8.8A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u...
CVE-2026-5146MEDIUM4.3Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacke...
CVE-2026-44343CRITICAL9.8WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard t...
CVE-2026-44279MEDIUM5.5An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, Forti...
CVE-2026-44278MEDIUM5.5A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindo...
CVE-2026-44277CRITICAL9.8A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticat...
CVE-2026-44204MEDIUM6.5Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortB...
CVE-2026-44196CRITICAL9.1Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication...
CVE-2026-44184HIGH8Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-44183CRITICAL9.8Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-44167HIGH7.5phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 fil...
CVE-2026-44166HIGH7.6Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker ...
CVE-2026-43929HIGH8.2ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails t...
CVE-2026-43892HIGH8.8AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli...
CVE-2026-43891HIGH7.5changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by...
CVE-2026-42899HIGH7.5Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service o...
CVE-2026-42898CRITICAL9.9Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a...
CVE-2026-42896HIGH7.8Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42893HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-42891MEDIUM6.5User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-42838MEDIUM5.4Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Ch...
CVE-2026-42833CRITICAL9.1Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a...
CVE-2026-42832MEDIUM5.5Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
CVE-2026-42831HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now